Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 263 of 292
CVE-2026-9115P4MEDIUMCVSS 4.3fixed in 148.0.7778.179≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9115 [MEDIUM] CWE-693 CVE-2026-9115: Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowe
Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-7282P4MEDIUMCVSS 4.3fixed in 113.0.5672.63≥ 113.0.5672.63, < 113.0.5672.632024-09-23
CVE-2023-7282 [MEDIUM] CWE-451 CVE-2023-7282: Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote
Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-2323P4MEDIUMCVSS 4.3fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2323 [MEDIUM] CWE-451 CVE-2026-2323: Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote a
Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-9919P4MEDIUMCVSS 4.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9919 [MEDIUM] CWE-125 CVE-2026-9919: Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote att
Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9116P4MEDIUMCVSS 4.3fixed in 148.0.7778.179≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9116 [MEDIUM] CWE-693 CVE-2026-9116: Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed
Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9113P4MEDIUMCVSS 4.3fixed in 148.0.7778.179≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9113 [MEDIUM] CWE-125 CVE-2026-9113: Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker
Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11665P4MEDIUMCVSS 4.3fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11665 [MEDIUM] CWE-125 CVE-2026-11665: Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote atta
Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-12443P4MEDIUMCVSS 4.3fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12443 [MEDIUM] CWE-125 CVE-2025-12443: Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to per
Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17769P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17769 [MEDIUM] CWE-20 CVE-2026-17769: Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a
Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17773P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17773 [MEDIUM] CWE-20 CVE-2026-17773: Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a
Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9929P4MEDIUMCVSS 4.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9929 [MEDIUM] CWE-200 CVE-2026-9929: Inappropriate implementation in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a
Inappropriate implementation in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9943P4MEDIUMCVSS 4.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9943 [MEDIUM] CWE-125 CVE-2026-9943: Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote att
Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7340P4MEDIUMCVSS 4.3fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7340 [MEDIUM] CWE-472 CVE-2026-7340: Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attac
Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14116P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14116 [MEDIUM] CWE-20 CVE-2026-14116: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allow
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-5891P4MEDIUMCVSS 4.3fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5891 [MEDIUM] CWE-451 CVE-2026-5891: Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remo
Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11159P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11159 [MEDIUM] CWE-457 CVE-2026-11159: Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak
Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17942P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17942 [MEDIUM] CWE-1300 CVE-2026-17942: Side-channel information leakage in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote att
Side-channel information leakage in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-1923P4MEDIUMCVSS 4.3fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-03-05
CVE-2025-1923 [MEDIUM] CWE-1021 CVE-2025-1923: Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed a
Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2026-7946P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7946 [MEDIUM] CWE-693 CVE-2026-7946: Insufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to
Insufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14072P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14072 [MEDIUM] CWE-451 CVE-2026-14072: Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote a
Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd