cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 265 of 292
CVE-2026-11285P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11285 [MEDIUM] CWE-451 CVE-2026-11285: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowe Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-8567P4MEDIUMCVSS 4.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8567 [MEDIUM] CWE-472 CVE-2026-8567: Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attac Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14046P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14046 [MEDIUM] CWE-346 CVE-2026-14046: Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowe Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-8537P4MEDIUMCVSS 4.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8537 [MEDIUM] CWE-942 CVE-2026-8537: Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17802P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17802 [MEDIUM] CWE-1300 CVE-2026-17802: Side-channel information leakage in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a Side-channel information leakage in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7933P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7933 [MEDIUM] CWE-125 CVE-2026-7933: Out of bounds read in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to Out of bounds read in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Medium)
nvd
CVE-2026-11234P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11234 [MEDIUM] CWE-693 CVE-2026-11234: Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remot Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-3942P4MEDIUMCVSS 4.3fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3942 [MEDIUM] CWE-451 CVE-2026-3942: Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote a Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-3927P4MEDIUMCVSS 4.3fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3927 [MEDIUM] CWE-451 CVE-2026-3927: Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote a Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11254P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11254 [MEDIUM] CWE-451 CVE-2026-11254: Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11261P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11261 [MEDIUM] CWE-20 CVE-2026-11261: Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacke Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11245P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11245 [MEDIUM] CWE-451 CVE-2026-11245: Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote at Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11274P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11274 [MEDIUM] CWE-284 CVE-2026-11274: Inappropriate implementation in DOM Distiller in Google Chrome on iOS prior to 149.0.7827.53 allowed Inappropriate implementation in DOM Distiller in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17857P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17857 [MEDIUM] CWE-346 CVE-2026-17857: Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote att Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-15130P4MEDIUMCVSS 4.3fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15130 [MEDIUM] CWE-602 CVE-2026-15130: Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a rem Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-15131P4MEDIUMCVSS 4.3fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15131 [MEDIUM] CWE-20 CVE-2026-15131: Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-3938P4MEDIUMCVSS 4.3fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3938 [MEDIUM] CWE-284 CVE-2026-3938: Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remot Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14053P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14053 [MEDIUM] CWE-346 CVE-2026-14053: Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remo Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-7961P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7961 [MEDIUM] CWE-20 CVE-2026-7961: Insufficient validation of untrusted input in Permissions in Google Chrome prior to 148.0.7778.96 al Insufficient validation of untrusted input in Permissions in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-13991P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13991 [MEDIUM] CWE-20 CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0. Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase