cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82

Vulnerabilities

Page 27 of 292
CVE-2025-10890P3CRITICALCVSS 9.1fixed in 140.0.7339.207≥ 140.0.7339.207, < 140.0.7339.2072025-09-24
CVE-2025-10890 [CRITICAL] CWE-1300 CVE-2025-10890: Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote att Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13851P3CRITICALCVSS 9.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13851 [CRITICAL] CWE-20 CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 15 Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13852P3CRITICALCVSS 9.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13852 [CRITICAL] CWE-20 CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 15 Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9881P3CRITICALCVSS 9.0fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9881 [CRITICAL] CWE-416 CVE-2026-9881: Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical)
nvd
CVE-2026-1862P3HIGHCVSS 8.8fixed in 144.0.7559.132≥ 144.0.7559.132, < 144.0.7559.1322026-02-03
CVE-2026-1862 [HIGH] CWE-843 CVE-2026-1862: Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potential Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9119P3HIGHCVSS 8.8fixed in 148.0.7778.178≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9119 [HIGH] CWE-122 CVE-2026-9119: Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13870P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13870 [HIGH] CWE-416 CVE-2026-13870: Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attack Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5272P3HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5272 [HIGH] CWE-122 CVE-2026-5272: Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to ex Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13788P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13788 [HIGH] CWE-416 CVE-2026-13788: Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote att Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13899P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13899 [HIGH] CWE-416 CVE-2026-13899: Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2020-6468P3HIGHCVSS 8.8fixed in 83.0.4103.61≥ unspecified, < 83.0.4103.612020-05-21
CVE-2020-6468 [HIGH] CWE-787 CVE-2020-6468: Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-7342P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7342 [HIGH] CWE-416 CVE-2026-7342: Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attac Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8509P3HIGHCVSS 8.8fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8509 [HIGH] CWE-122 CVE-2026-8509: Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-9118P3HIGHCVSS 8.8fixed in 148.0.7778.178≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9118 [HIGH] CWE-416 CVE-2026-9118: Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker t Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11102P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11102 [HIGH] CWE-474 CVE-2026-11102: Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-13885P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13885 [HIGH] CWE-416 CVE-2026-13885: Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10885P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10885 [HIGH] CWE-416 CVE-2026-10885: Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote att Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10896P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10896 [HIGH] CWE-416 CVE-2026-10896: Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote att Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-9884P3HIGHCVSS 8.8fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9884 [HIGH] CWE-416 CVE-2026-9884: Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13805P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13805 [HIGH] CWE-416 CVE-2026-13805: Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to ex Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase