Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 262 of 292
CVE-2024-9963P4MEDIUMCVSS 4.3fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9963 [MEDIUM] CVE-2024-9963: Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote a
Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-9964P4MEDIUMCVSS 4.3fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9964 [MEDIUM] CVE-2024-9964: Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote at
Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2025-11215P4MEDIUMCVSS 4.3fixed in 141.0.7390.54≥ 141.0.7390.54, < 141.0.7390.542025-11-06
CVE-2025-11215 [MEDIUM] CWE-193 CVE-2025-11215: Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform
Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5869P4MEDIUMCVSS 4.3fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5869 [MEDIUM] CWE-122 CVE-2026-5869: Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to o
Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5864P4MEDIUMCVSS 4.3fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5864 [MEDIUM] CWE-122 CVE-2026-5864: Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker t
Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7972P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7972 [MEDIUM] CWE-457 CVE-2026-7972: Uninitialized Use in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had c
Uninitialized Use in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13902P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13902 [MEDIUM] CWE-451 CVE-2026-13902: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowe
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13916P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13916 [MEDIUM] CWE-451 CVE-2026-13916: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowe
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17785P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17785 [MEDIUM] CWE-457 CVE-2026-17785: Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17771P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17771 [MEDIUM] CWE-457 CVE-2026-17771: Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-8579P4MEDIUMCVSS 4.3fixed in 139.0.7258.66≥ 139.0.7258.66, < 139.0.7258.662025-08-07
CVE-2025-8579 [MEDIUM] CWE-79 CVE-2025-8579: Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-8577P4MEDIUMCVSS 4.3fixed in 139.0.7258.66≥ 139.0.7258.66, < 139.0.7258.662025-08-07
CVE-2025-8577 [MEDIUM] CWE-79 CVE-2025-8577: Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17889P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17889 [MEDIUM] CWE-457 CVE-2026-17889: Uninitialized Use in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak
Uninitialized Use in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14034P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14034 [MEDIUM] CWE-284 CVE-2026-14034: Inappropriate implementation in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a r
Inappropriate implementation in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-8582P4MEDIUMCVSS 4.3fixed in 139.0.7258.66≥ 139.0.7258.66, < 139.0.7258.662025-08-07
CVE-2025-8582 [MEDIUM] CWE-20 CVE-2025-8582: Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a
Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-13981P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13981 [MEDIUM] CWE-451 CVE-2026-13981: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowe
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13980P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13980 [MEDIUM] CWE-451 CVE-2026-13980: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowe
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11107P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11107 [MEDIUM] CWE-451 CVE-2026-11107: Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote a
Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13952P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13952 [MEDIUM] CWE-352 CVE-2026-13952: Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150.0.7871.47 allowed a re
Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13946P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13946 [MEDIUM] CWE-352 CVE-2026-13946: Inappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allo
Inappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd