Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82
Vulnerabilities
Page 28 of 292
CVE-2026-10965P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10965 [HIGH] CWE-472 CVE-2026-10965: Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to ex
Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10987P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10987 [HIGH] CWE-472 CVE-2026-10987: Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute
Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10964P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10964 [HIGH] CWE-472 CVE-2026-10964: Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute
Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10963P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10963 [HIGH] CWE-472 CVE-2026-10963: Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute
Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11074P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11074 [HIGH] CWE-416 CVE-2026-11074: Use after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker
Use after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-7023P3HIGHCVSS 8.8fixed in 128.0.6537.0≥ 128.0.6537.0, < 128.0.6537.02024-09-23
CVE-2024-7023 [HIGH] CWE-20 CVE-2024-7023: Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote atta
Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-13038P3HIGHCVSS 8.8fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13038 [HIGH] CWE-416 CVE-2026-13038: Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote atta
Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-6299P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6299 [HIGH] CWE-416 CVE-2026-6299: Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to ex
Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-6317P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6317 [HIGH] CWE-416 CVE-2026-6317: Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute
Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6305P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6305 [HIGH] CWE-122 CVE-2026-6305: Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to
Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2026-6306P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6306 [HIGH] CWE-122 CVE-2026-6306: Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to
Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2026-6302P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6302 [HIGH] CWE-416 CVE-2026-6302: Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execut
Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10986P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10986 [HIGH] CWE-472 CVE-2026-10986: Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execu
Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-13830P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13830 [HIGH] CWE-416 CVE-2026-13830: Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attac
Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2026-14149P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14149 [HIGH] CWE-416 CVE-2026-14149: Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker t
Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-9910P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9910 [HIGH] CWE-125 CVE-2026-9910: Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attac
Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6315P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6315 [HIGH] CWE-416 CVE-2026-6315: Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote a
Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6316P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6316 [HIGH] CWE-416 CVE-2026-6316: Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execut
Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7355P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7355 [HIGH] CWE-416 CVE-2026-7355: Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execut
Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7348P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7348 [HIGH] CWE-416 CVE-2026-7348: Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execu
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd