cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82

Vulnerabilities

Page 26 of 292
CVE-2026-9886P3CRITICALCVSS 9.6fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9886 [CRITICAL] CWE-416 CVE-2026-9886: Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-15899P3CRITICALCVSS 9.6fixed in 150.0.7871.128≥ 150.0.7871.128, < 150.0.7871.1282026-07-20
CVE-2026-15899 [CRITICAL] CWE-416 CVE-2026-15899: Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote att Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-14390P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14390 [CRITICAL] CWE-416 CVE-2026-14390: Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potenti Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11094P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11094 [CRITICAL] CWE-416 CVE-2026-11094: Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacke Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11114P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11114 [CRITICAL] CWE-416 CVE-2026-11114: Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attac Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9874P3CRITICALCVSS 9.6fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9874 [CRITICAL] CWE-416 CVE-2026-9874: Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-8511P3CRITICALCVSS 9.6fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8511 [CRITICAL] CWE-416 CVE-2026-8511: Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potential Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-17758P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17758 [CRITICAL] CWE-122 CVE-2026-17758: Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to po Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-12027P3CRITICALCVSS 9.6fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12027 [CRITICAL] CWE-250 CVE-2026-12027: Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote a Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14425P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14425 [CRITICAL] CWE-416 CVE-2026-14425: Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potenti Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14424P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14424 [CRITICAL] CWE-416 CVE-2026-14424: Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to p Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14398P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14398 [CRITICAL] CWE-416 CVE-2026-14398: Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potenti Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-14419P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14419 [CRITICAL] CWE-416 CVE-2026-14419: Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentia Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-8580P3CRITICALCVSS 9.6fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8580 [CRITICAL] CWE-416 CVE-2026-8580: Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potenti Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17675P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17675 [CRITICAL] CWE-787 CVE-2026-17675: Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who h Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14417P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14417 [CRITICAL] CWE-416 CVE-2026-14417: Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentia Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-17991P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17991 [CRITICAL] CWE-20 CVE-2026-17991: Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a r Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17987P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17987 [CRITICAL] CWE-20 CVE-2026-17987: Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)
nvd
CVE-2026-17990P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17990 [CRITICAL] CWE-20 CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allow Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)
nvd
CVE-2024-3159P3HIGHCVSS 8.8fixed in 123.0.6312.105≥ 123.0.6312.105, < 123.0.6312.1052024-04-06
CVE-2024-3159 [HIGH] CWE-119 CVE-2024-3159: Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase