cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 264 of 292
CVE-2024-13178P4MEDIUMCVSS 4.3fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842025-11-14
CVE-2024-13178 [MEDIUM] CWE-451 CVE-2024-13178: Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-11919P4MEDIUMCVSS 4.3fixed in 129.0.6668.58≥ 129.0.6668.58, < 129.0.6668.582025-11-14
CVE-2024-11919 [MEDIUM] CWE-451 CVE-2024-11919: Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-12441P4MEDIUMCVSS 4.3fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12441 [MEDIUM] CWE-125 CVE-2025-12441: Out of bounds read in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perfor Out of bounds read in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14110P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14110 [MEDIUM] CWE-451 CVE-2026-14110: Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote at Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17907P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17907 [MEDIUM] CWE-1300 CVE-2026-17907: Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11668P4MEDIUMCVSS 4.3fixed in 149.0.7827.102≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11668 [MEDIUM] CWE-457 CVE-2026-11668: Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a re Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted video file. (Chromium security severity: High)
nvd
CVE-2026-7942P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7942 [MEDIUM] CWE-472 CVE-2026-7942: Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7904P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7904 [MEDIUM] CWE-125 CVE-2026-7904: Out of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to per Out of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14410P4MEDIUMCVSS 4.3fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14410 [MEDIUM] CWE-451 CVE-2026-14410: Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attack Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14013P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14013 [MEDIUM] CWE-451 CVE-2026-14013: Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacke Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5878P4MEDIUMCVSS 4.3fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5878 [MEDIUM] CWE-451 CVE-2026-5878: Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5882P4MEDIUMCVSS 4.3fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5882 [MEDIUM] CWE-451 CVE-2026-5882: Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacke Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-13636P4MEDIUMCVSS 4.3fixed in 143.0.7499.40≥ 143.0.7499.41, < 143.0.7499.412025-12-02
CVE-2025-13636 [MEDIUM] CWE-290 CVE-2025-13636: Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted domain name. (Chromium security severity: Low)
nvd
CVE-2025-9479P4MEDIUMCVSS 4.3fixed in 133.0.6943.141≥ 133.0.6943.141, < 133.0.6943.1412025-11-14
CVE-2025-9479 [MEDIUM] CWE-125 CVE-2025-9479: Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to poten Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11257P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11257 [MEDIUM] CWE-284 CVE-2026-11257: Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote att Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-5875P4MEDIUMCVSS 4.3fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5875 [MEDIUM] CWE-639 CVE-2026-5875: Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11162P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11162 [MEDIUM] CWE-200 CVE-2026-11162: Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacke Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8562P4MEDIUMCVSS 4.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8562 [MEDIUM] CWE-1300 CVE-2026-8562: Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a re Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13984P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13984 [MEDIUM] CWE-451 CVE-2026-13984: Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11280P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11280 [MEDIUM] CWE-20 CVE-2026-11280: Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remo Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
Google Chrome vulnerabilities | cvebase