cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 274 of 292
CVE-2024-8908P4MEDIUMCVSS 4.3fixed in 129.0.6668.58≥ 129.0.6668.58, < 129.0.6668.582024-09-17
CVE-2024-8908 [MEDIUM] CWE-290 CVE-2024-8908: Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-1917P4MEDIUMCVSS 4.3fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-03-05
CVE-2025-1917 [MEDIUM] CWE-1021 CVE-2025-1917: Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowe Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4917P4MEDIUMCVSS 4.3fixed in 103.0.5060.53≥ 103.0.5060.53, < 103.0.5060.532023-07-29
CVE-2022-4917 [MEDIUM] CWE-346 CVE-2022-4917: Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-8909P4MEDIUMCVSS 4.3fixed in 129.0.6668.58≥ 129.0.6668.58, < 129.0.6668.582024-09-17
CVE-2024-8909 [MEDIUM] CWE-451 CVE-2024-8909: Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote a Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-0448P4MEDIUMCVSS 4.3fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0448 [MEDIUM] CWE-79 CVE-2025-0448: Inappropriate implementation in Compositing in Google Chrome prior to 132.0.6834.83 allowed a remote Inappropriate implementation in Compositing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-8033P4MEDIUMCVSS 4.3fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-8033 [MEDIUM] CVE-2024-8033: Inappropriate implementation in WebApp Installs in Google Chrome on Windows prior to 128.0.6613.84 a Inappropriate implementation in WebApp Installs in Google Chrome on Windows prior to 128.0.6613.84 allowed an attacker who convinced a user to install a malicious application to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-11117P4MEDIUMCVSS 4.3fixed in 131.0.6778.69≥ 131.0.6778.69, < 131.0.6778.692024-11-12
CVE-2024-11117 [MEDIUM] CWE-79 CVE-2024-11117: Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-8581P4MEDIUMCVSS 4.3fixed in 139.0.7258.66≥ 139.0.7258.66, < 139.0.7258.662025-08-07
CVE-2025-8581 [MEDIUM] CWE-79 CVE-2025-8581: Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-7020P4MEDIUMCVSS 4.3fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-09-23
CVE-2024-7020 [MEDIUM] CWE-451 CVE-2024-7020: Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-9921P4MEDIUMCVSS 4.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9921 [MEDIUM] CWE-457 CVE-2026-9921: Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote atta Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin information via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9935P4MEDIUMCVSS 4.3fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9935 [MEDIUM] CWE-457 CVE-2026-9935: Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to lea Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-8580P4MEDIUMCVSS 4.3fixed in 139.0.7258.66≥ 139.0.7258.66, < 139.0.7258.662025-08-07
CVE-2025-8580 [MEDIUM] CWE-79 CVE-2025-8580: Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-7281P4MEDIUMCVSS 4.3fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052024-09-23
CVE-2023-7281 [MEDIUM] CWE-451 CVE-2023-7281: Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remot Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-8583P4MEDIUMCVSS 4.3fixed in 139.0.7258.66≥ 139.0.7258.66, < 139.0.7258.662025-08-07
CVE-2025-8583 [MEDIUM] CWE-451 CVE-2025-8583: Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-9907P4MEDIUMCVSS 4.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9907 [MEDIUM] CWE-125 CVE-2026-9907: Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote atta Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13107P4MEDIUMCVSS 4.3fixed in 140.0.7339.80≥ 140.0.7339.80, < 140.0.7339.802025-11-14
CVE-2025-13107 [MEDIUM] CWE-451 CVE-2025-13107: Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-9955P4MEDIUMCVSS 4.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9955 [MEDIUM] CWE-200 CVE-2026-9955: Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7983P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7983 [MEDIUM] CWE-125 CVE-2026-7983: Out of bounds read in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak Out of bounds read in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-7021P4MEDIUMCVSS 4.3fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602025-11-14
CVE-2024-7021 [MEDIUM] CWE-451 CVE-2024-7021: Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14418P4MEDIUMCVSS 4.3fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14418 [MEDIUM] CWE-457 CVE-2026-14418: Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase