cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 267 of 292
CVE-2026-8004P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8004 [MEDIUM] CWE-693 CVE-2026-8004: Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attac Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2026-8005P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8005 [MEDIUM] CWE-20 CVE-2026-8005: Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed a Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2026-5889P4MEDIUMCVSS 4.3fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5889 [MEDIUM] CWE-326 CVE-2026-5889: Cryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an attacker to read pot Cryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an attacker to read potentially sensitive information from encrypted PDFs via a brute-force attack. (Chromium security severity: Medium)
nvd
CVE-2026-13907P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13907 [MEDIUM] CWE-451 CVE-2026-13907: Inappropriate implementation in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remo Inappropriate implementation in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13895P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13895 [MEDIUM] CWE-451 CVE-2026-13895: Inappropriate implementation in Autofill in Google Chrome prior to 150.0.7871.47 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13956P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13956 [MEDIUM] CWE-451 CVE-2026-13956: Incorrect security UI in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker Incorrect security UI in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13857P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13857 [MEDIUM] CWE-451 CVE-2026-13857: Inappropriate implementation in Geometry in Google Chrome prior to 150.0.7871.47 allowed a remote at Inappropriate implementation in Geometry in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13860P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13860 [MEDIUM] CWE-451 CVE-2026-13860: Incorrect security UI in Autofill in Google Chrome on Windows prior to 150.0.7871.47 allowed a remot Incorrect security UI in Autofill in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13986P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13986 [MEDIUM] CWE-451 CVE-2026-13986: Inappropriate implementation in Media UI in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed Inappropriate implementation in Media UI in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7993P4MEDIUMCVSS 4.2fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7993 [MEDIUM] CWE-20 CVE-2026-7993: Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 148.0.77 Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7947P4MEDIUMCVSS 4.2fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7947 [MEDIUM] CWE-20 CVE-2026-7947: Insufficient validation of untrusted input in Network in Google Chrome prior to 148.0.7778.96 allowe Insufficient validation of untrusted input in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14137P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14137 [MEDIUM] CWE-20 CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0. Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-12729P4MEDIUMCVSS 4.2fixed in 142.0.7444.137≥ 142.0.7444.137, < 142.0.7444.1372025-11-10
CVE-2025-12729 [MEDIUM] CWE-451 CVE-2025-12729: Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7934P4MEDIUMCVSS 4.2fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7934 [MEDIUM] CWE-20 CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 Insufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14138P4MEDIUMCVSS 4.2fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14138 [MEDIUM] CWE-451 CVE-2026-14138: Inappropriate implementation in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 al Inappropriate implementation in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14028P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14028 [MEDIUM] CWE-451 CVE-2026-14028: Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a rem Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14030P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14030 [MEDIUM] CWE-451 CVE-2026-14030: Inappropriate implementation in SplitView in Google Chrome on Linux prior to 150.0.7871.47 allowed a Inappropriate implementation in SplitView in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-13983P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13983 [MEDIUM] CWE-451 CVE-2026-13983: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowe Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9986P4MEDIUMCVSS 4.2fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9986 [MEDIUM] CWE-20 CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778 Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2019-5868P4MEDIUMCVSS 5.5fixed in 76.0.3809.100≥ unspecified, < 76.0.3809.1002019-11-25
CVE-2019-5868 [MEDIUM] CWE-416 CVE-2019-5868: Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potent Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
Google Chrome vulnerabilities | cvebase