cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 275 of 292
CVE-2025-13102P4MEDIUMCVSS 4.3fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-11-14
CVE-2025-13102 [MEDIUM] CWE-451 CVE-2025-13102: Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 a Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11695P4MEDIUMCVSS 4.3fixed in 149.0.7827.102≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11695 [MEDIUM] CWE-693 CVE-2026-11695: Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11685P4MEDIUMCVSS 4.3fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11685 [MEDIUM] CWE-20 CVE-2026-11685: Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4453P4MEDIUMCVSS 4.3fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4453 [MEDIUM] CWE-472 CVE-2026-4453: Integer overflow in Dawn in Google Chrome on Mac prior to 146.0.7680.153 allowed a remote attacker t Integer overflow in Dawn in Google Chrome on Mac prior to 146.0.7680.153 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7999P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7999 [MEDIUM] CWE-200 CVE-2026-7999: Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11291P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11291 [MEDIUM] CWE-346 CVE-2026-11291: Inappropriate implementation in Android Autofill in Google Chrome on Android prior to 149.0.7827.53 Inappropriate implementation in Android Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-12911P4MEDIUMCVSS 4.3fixed in 140.0.7339.80≥ 140.0.7339.80, < 140.0.7339.802025-11-08
CVE-2025-12911 [MEDIUM] CWE-451 CVE-2025-12911: Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-7979P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7979 [MEDIUM] CWE-346 CVE-2026-7979: Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attac Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7986P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7986 [MEDIUM] CWE-346 CVE-2026-7986: Insufficient policy enforcement in Autofill in Google Chrome prior to 148.0.7778.96 allowed a remote Insufficient policy enforcement in Autofill in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8576P4MEDIUMCVSS 4.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8576 [MEDIUM] CWE-942 CVE-2026-8576: Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11178P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11178 [MEDIUM] CWE-346 CVE-2026-11178: Insufficient policy enforcement in WebView in Google Chrome on Android prior to 149.0.7827.53 allowe Insufficient policy enforcement in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11253P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11253 [MEDIUM] CWE-362 CVE-2026-11253: Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11126P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11126 [MEDIUM] CWE-20 CVE-2026-11126: Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2026-11212P4MEDIUMCVSS 4.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11212 [MEDIUM] CWE-284 CVE-2026-11212: Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attac Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2026-7936P4MEDIUMCVSS 4.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7936 [MEDIUM] CWE-125 CVE-2026-7936: Object lifecycle issue in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to pe Object lifecycle issue in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-12728P4MEDIUMCVSS 4.2fixed in 142.0.7444.137fixed in 142.0.7444.134+2 more2025-11-10
CVE-2025-12728 [MEDIUM] CWE-451 CVE-2025-12728: Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13973P4MEDIUMCVSS 4.2fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13973 [MEDIUM] CWE-451 CVE-2026-13973: Inappropriate implementation in UI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker Inappropriate implementation in UI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13992P4MEDIUMCVSS 4.2fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13992 [MEDIUM] CWE-451 CVE-2026-13992: Inappropriate implementation in UI in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote a Inappropriate implementation in UI in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-12447P4MEDIUMCVSS 4.2fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12447 [MEDIUM] CWE-306 CVE-2025-12447: Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-12444P4MEDIUMCVSS 4.2fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12444 [MEDIUM] CWE-306 CVE-2025-12444: Incorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 allowed a remote atta Incorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
Google Chrome vulnerabilities | cvebase