Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 281 of 292
CVE-2018-20067P4MEDIUMCVSS 4.3fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802019-01-09
CVE-2018-20067 [MEDIUM] CVE-2018-20067: A renderer initiated back navigation was incorrectly allowed to cancel a browser initiated one in Na
A renderer initiated back navigation was incorrectly allowed to cancel a browser initiated one in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.
nvd
CVE-2018-20068P4MEDIUMCVSS 4.3fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802019-01-09
CVE-2018-20068 [MEDIUM] CWE-20 CVE-2018-20068: Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 71.0.3578.80 allowed
Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.
nvd
CVE-2022-4025P4MEDIUMCVSS 4.3fixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802023-01-02
CVE-2022-4025 [MEDIUM] CWE-203 CVE-2022-4025: Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attack
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
nvd
CVE-2023-1228P4MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1228 [MEDIUM] CVE-2023-1228: Insufficient policy enforcement in Intents in Google Chrome on Android prior to 111.0.5563.64 allowe
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1223P4MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1223 [MEDIUM] CVE-2023-1223: Insufficient policy enforcement in Autofill in Google Chrome on Android prior to 111.0.5563.64 allow
Insufficient policy enforcement in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7932P4MEDIUMCVSS 4.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7932 [MEDIUM] CWE-693 CVE-2026-7932: Insufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local
Insufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1230P4MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1230 [MEDIUM] CVE-2023-1230: Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 111.0.5563.64 a
Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious WebApp to spoof the contents of the PWA installer via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-12434P4MEDIUMCVSS 4.2fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12434 [MEDIUM] CWE-362 CVE-2025-12434: Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who con
Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-1186P4MEDIUMCVSS 5.0fixed in 10.0.648.1272011-03-11
CVE-2011-1186 [MEDIUM] CWE-20 CVE-2011-1186: Google Chrome before 10.0.648.127 on Linux does not properly handle parallel execution of calls to t
Google Chrome before 10.0.648.127 on Linux does not properly handle parallel execution of calls to the print method, which might allow remote attackers to cause a denial of service (application crash) via crafted JavaScript code.
nvd
CVE-2011-1413P4MEDIUMCVSS 5.0fixed in 10.0.648.1272011-03-11
CVE-2011-1413 [MEDIUM] CVE-2011-1413: Google Chrome before 10.0.648.127 on Linux does not properly mitigate an unspecified flaw in an X se
Google Chrome before 10.0.648.127 on Linux does not properly mitigate an unspecified flaw in an X server, which allows remote attackers to cause a denial of service (application crash) via vectors involving long messages.
nvd
CVE-2012-2867P4MEDIUMCVSS 5.0≤ 21.0.1180.88v21.0.1180.0+50 more2012-08-31
CVE-2012-2867 [MEDIUM] CVE-2012-2867: The SPDY implementation in Google Chrome before 21.0.1180.89 allows remote attackers to cause a deni
The SPDY implementation in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2011-3083P4MEDIUMCVSS 5.0≤ 19.0.1084.452012-05-16
CVE-2011-3083 [MEDIUM] CWE-119 CVE-2011-3083: browser/profiles/profile_impl_io_data.cc in Google Chrome before 19.0.1084.46 does not properly hand
browser/profiles/profile_impl_io_data.cc in Google Chrome before 19.0.1084.46 does not properly handle a malformed ftp URL in the SRC attribute of a VIDEO element, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted web page.
nvd
CVE-2011-1450P4MEDIUMCVSS 5.0fixed in 11.0.696.572011-05-03
CVE-2011-1450 [MEDIUM] CWE-20 CVE-2011-1450: Google Chrome before 11.0.696.57 does not properly present file dialogs, which allows remote attacke
Google Chrome before 11.0.696.57 does not properly present file dialogs, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "dangling pointers."
nvd
CVE-2010-3248P4MEDIUMCVSS 5.0fixed in 6.0.472.532010-09-07
CVE-2010-3248 [MEDIUM] CVE-2010-3248: Google Chrome before 6.0.472.53 does not properly restrict copying to the clipboard, which has unspe
Google Chrome before 6.0.472.53 does not properly restrict copying to the clipboard, which has unspecified impact and attack vectors.
nvd
CVE-2013-0834P4MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0834 [MEDIUM] CWE-119 CVE-2013-0834: Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bound
Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving glyphs.
nvd
CVE-2009-0411P4MEDIUMCVSS 5.0≤ 1.0.154.43v0.2.152.1+10 more2009-02-03
CVE-2009-0411 [MEDIUM] CWE-264 CVE-2009-0411: Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cook
Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script.
nvd
CVE-2011-0782P4MEDIUMCVSS 5.0fixed in 9.0.597.842011-02-04
CVE-2011-0782 [MEDIUM] CVE-2011-0782: Google Chrome before 9.0.597.84 on Mac OS X does not properly mitigate an unspecified flaw in the Ma
Google Chrome before 9.0.597.84 on Mac OS X does not properly mitigate an unspecified flaw in the Mac OS X 10.5 SSL libraries, which allows remote attackers to cause a denial of service (application crash) via unknown vectors.
nvd
CVE-2010-0662P4MEDIUMCVSS 5.0≤ 4.0.249.0v0.2.149.27+45 more2010-02-18
CVE-2010-0662 [MEDIUM] CWE-189 CVE-2010-0662: The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.
The ParamTraits::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not use the correct variables in calculations designed to prevent integer overflows, which allows attackers to leverage renderer access to cause a denial of service or possibly have unspecified other impact via bitmap data, related to deserializatio
nvd
CVE-2013-0909P4MEDIUMCVSS 5.0≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0909 [MEDIUM] CWE-200 CVE-2013-0909: The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HT
The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HTTP Referer information via unspecified vectors.
nvd
CVE-2010-2899P4MEDIUMCVSS 5.0fixed in 5.0.375.1252010-07-28
CVE-2010-2899 [MEDIUM] CVE-2010-2899: Unspecified vulnerability in the layout implementation in Google Chrome before 5.0.375.125 allows re
Unspecified vulnerability in the layout implementation in Google Chrome before 5.0.375.125 allows remote attackers to obtain sensitive information from process memory via unknown vectors.
nvd