cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 261 of 292
CVE-2022-4195P4MEDIUMCVSS 4.3fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4195 [MEDIUM] CVE-2022-4195: Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0.5359.71 allowed a r Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass Safe Browsing warnings via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2024-7003P4MEDIUMCVSS 4.3fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-7003 [MEDIUM] CWE-358 CVE-2024-7003: Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attac Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2019-5864P4MEDIUMCVSS 4.3fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5864 [MEDIUM] CWE-20 CVE-2019-5864: Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
nvd
CVE-2022-3318P4MEDIUMCVSS 4.3fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3318 [MEDIUM] CWE-404 CVE-2022-3318: Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to reboot Chrome OS to potentially exploit heap corruption via UI interaction. (Chromium security severity: Low)
nvd
CVE-2024-7976P4MEDIUMCVSS 4.3fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-7976 [MEDIUM] CWE-79 CVE-2024-7976: Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attac Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1224P4MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1224 [MEDIUM] CVE-2023-1224: Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-7001P4MEDIUMCVSS 4.3fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-7001 [MEDIUM] CWE-474 CVE-2024-7001: Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attack Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-6999P4MEDIUMCVSS 4.3fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-6999 [MEDIUM] CWE-451 CVE-2024-6999: Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attac Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-8906P4MEDIUMCVSS 4.3fixed in 129.0.6668.58≥ 129.0.6668.58, < 129.0.6668.582024-09-17
CVE-2024-8906 [MEDIUM] CVE-2024-8906: Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-8034P4MEDIUMCVSS 4.3fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-8034 [MEDIUM] CVE-2024-8034: Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allow Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-0809P4MEDIUMCVSS 4.3fixed in 121.0.6167.85≥ 121.0.6167.85, < 121.0.6167.852024-01-24
CVE-2024-0809 [MEDIUM] CWE-693 CVE-2024-0809: Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-7022P4MEDIUMCVSS 4.3fixed in 123.0.6312.58≥ 123.0.6312.58, < 123.0.6312.582024-09-23
CVE-2024-7022 [MEDIUM] CWE-457 CVE-2024-7022: Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-11111P4MEDIUMCVSS 4.3fixed in 131.0.6778.69≥ 131.0.6778.69, < 131.0.6778.692024-11-12
CVE-2024-11111 [MEDIUM] CWE-79 CVE-2024-11111: Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-8035P4MEDIUMCVSS 4.3fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-8035 [MEDIUM] CWE-79 CVE-2024-8035: Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowe Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-11116P4MEDIUMCVSS 4.3fixed in 131.0.6778.69≥ 131.0.6778.69, < 131.0.6778.692024-11-12
CVE-2024-11116 [MEDIUM] CWE-79 CVE-2024-11116: Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attac Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-0446P4MEDIUMCVSS 4.3fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0446 [MEDIUM] CWE-451 CVE-2025-0446: Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2024-9962P4MEDIUMCVSS 4.3fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9962 [MEDIUM] CVE-2024-9962: Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-9958P4MEDIUMCVSS 4.3fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9958 [MEDIUM] CVE-2024-9958: Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a r Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-1922P4MEDIUMCVSS 4.3fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-03-05
CVE-2025-1922 [MEDIUM] CWE-451 CVE-2025-1922: Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-7019P4MEDIUMCVSS 4.3fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-09-23
CVE-2024-7019 [MEDIUM] CWE-451 CVE-2024-7019: Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase