cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 271 of 292
CVE-2013-2915P4MEDIUMCVSS 4.3≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2915 [MEDIUM] CVE-2013-2915: Google Chrome before 30.0.1599.66 preserves pending NavigationEntry objects in certain invalid circu Google Chrome before 30.0.1599.66 preserves pending NavigationEntry objects in certain invalid circumstances, which allows remote attackers to spoof the address bar via a URL with a malformed scheme, as demonstrated by a nonexistent:12121 URL.
nvd
CVE-2022-0118P4MEDIUMCVSS 4.3fixed in 97.0.4692.71≥ unspecified, < 97.0.4692.712022-02-12
CVE-2022-0118 [MEDIUM] CVE-2022-0118: Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote att Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2016-1616P4MEDIUMCVSS 4.3≤ 47.0.2526.1062016-01-25
CVE-2016-1616 [MEDIUM] CWE-254 CVE-2016-1616: The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.2564.82 allows remote attackers to spoof URLs via vectors involving an unfocused custom button.
nvd
CVE-2022-0110P4MEDIUMCVSS 4.3fixed in 97.0.4692.71≥ unspecified, < 97.0.4692.712022-02-12
CVE-2022-0110 [MEDIUM] CWE-1021 CVE-2022-0110: Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker t Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-13717P4MEDIUMCVSS 4.3fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13717 [MEDIUM] CWE-922 CVE-2019-13717: Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote at Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
nvd
CVE-2015-1263P4MEDIUMCVSS 4.3≤ 42.0.2311.1522015-05-20
CVE-2015-1263 [MEDIUM] CWE-17 CVE-2015-1263: The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file.
nvd
CVE-2016-1664P4MEDIUMCVSS 4.3≤ 50.0.2661.872016-05-14
CVE-2016-1664 [MEDIUM] CWE-254 CVE-2016-1664: The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2023-2465P4MEDIUMCVSS 4.3fixed in 113.0.5672.63≥ 113.0.5672.63, < 113.0.5672.632023-05-03
CVE-2023-2465 [MEDIUM] CVE-2023-2465: Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attack Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13808P4MEDIUMCVSS 4.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13808 [MEDIUM] CWE-20 CVE-2026-13808: Insufficient data validation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowe Insufficient data validation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: High)
nvd
CVE-2019-13708P4MEDIUMCVSS 4.3fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13708 [MEDIUM] CWE-290 CVE-2019-13708: Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a r Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-13718P4MEDIUMCVSS 4.3fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13718 [MEDIUM] CVE-2019-13718: Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote atta Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2010-3246P4MEDIUMCVSS 4.3fixed in 6.0.472.532010-09-07
CVE-2010-3246 [MEDIUM] CVE-2010-3246: Google Chrome before 6.0.472.53 does not properly handle the _blank value for the target attribute o Google Chrome before 6.0.472.53 does not properly handle the _blank value for the target attribute of unspecified elements, which allows remote attackers to bypass the pop-up blocker via unknown vectors.
nvd
CVE-2023-2463P4MEDIUMCVSS 4.3fixed in 113.0.5672.63≥ 113.0.5672.63, < 113.0.5672.632023-05-03
CVE-2023-2463 [MEDIUM] CVE-2023-2463: Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-2467P4MEDIUMCVSS 4.3fixed in 113.0.5672.63≥ 113.0.5672.63, < 113.0.5672.632023-05-03
CVE-2023-2467 [MEDIUM] CVE-2023-2467: Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2012-2899P4MEDIUMCVSS 4.3≤ 21.0.1180.81v21.0.1180.0+43 more2014-01-05
CVE-2012-2899 [MEDIUM] CWE-79 CVE-2012-2899: Google Chrome before 21.0.1180.82 on iOS makes certain incorrect calls to WebView methods that trigg Google Chrome before 21.0.1180.82 on iOS makes certain incorrect calls to WebView methods that trigger use of an applewebdata: URL, which allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors involving the document.write method.
nvd
CVE-2023-2462P4MEDIUMCVSS 4.3fixed in 113.0.5672.63≥ 113.0.5672.63, < 113.0.5672.632023-05-03
CVE-2023-2462 [MEDIUM] CVE-2023-2462: Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-37967P4MEDIUMCVSS 4.3fixed in 94.0.4606.54≥ unspecified, < 94.0.4606.542021-10-08
CVE-2021-37967 [MEDIUM] CWE-346 CVE-2021-37967: Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-1875P4MEDIUMCVSS 4.3fixed in 102.0.5005.61≥ unspecified, < 102.0.5005.612022-07-27
CVE-2022-1875 [MEDIUM] CWE-668 CVE-2022-1875: Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacke Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2010-3247P4MEDIUMCVSS 4.3fixed in 6.0.472.532010-09-07
CVE-2010-3247 [MEDIUM] CWE-20 CVE-2010-3247: Google Chrome before 6.0.472.53 does not properly restrict the characters in URLs, which allows remo Google Chrome before 6.0.472.53 does not properly restrict the characters in URLs, which allows remote attackers to spoof the appearance of the URL bar via homographic sequences.
nvd
CVE-2022-1307P4MEDIUMCVSS 4.3fixed in 100.0.4896.88≥ unspecified, < 100.0.4896.882022-07-25
CVE-2022-1307 [MEDIUM] CWE-290 CVE-2022-1307: Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allow Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase