cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 283 of 292
CVE-2010-4483P4MEDIUMCVSS 4.3≤ 8.0.552.2142010-12-07
CVE-2010-4483 [MEDIUM] CWE-264 CVE-2010-4483: Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVA Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via a crafted web site.
nvd
CVE-2018-6177P4MEDIUMCVSS 4.3fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6177 [MEDIUM] CWE-200 CVE-2018-6177: Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2010-4491P4MEDIUMCVSS 4.3≤ 8.0.552.2142010-12-07
CVE-2010-4491 [MEDIUM] CWE-264 CVE-2010-4491: Google Chrome before 8.0.552.215 does not properly restrict privileged extensions, which allows remo Google Chrome before 8.0.552.215 does not properly restrict privileged extensions, which allows remote attackers to cause a denial of service (memory corruption) via a crafted extension.
nvd
CVE-2011-3875P4MEDIUMCVSS 4.3fixed in 15.0.874.1022011-10-25
CVE-2011-3875 [MEDIUM] CWE-20 CVE-2011-3875: Google Chrome before 15.0.874.102 does not properly handle drag and drop operations on URL strings, Google Chrome before 15.0.874.102 does not properly handle drag and drop operations on URL strings, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
nvd
CVE-2010-1235P4MEDIUMCVSS 4.3≤ 4.1.249.1035v0.2.149.27+82 more2010-04-01
CVE-2010-1235 [MEDIUM] CWE-20 CVE-2010-1235: Unspecified vulnerability in Google Chrome before 4.1.249.1036 allows remote attackers to trigger th Unspecified vulnerability in Google Chrome before 4.1.249.1036 allows remote attackers to trigger the omission of a download warning dialog via unknown vectors.
nvd
CVE-2011-2361P4MEDIUMCVSS 4.3fixed in 13.0.782.1072011-08-03
CVE-2011-2361 [MEDIUM] CWE-287 CVE-2011-2361: The Basic Authentication dialog implementation in Google Chrome before 13.0.782.107 does not properl The Basic Authentication dialog implementation in Google Chrome before 13.0.782.107 does not properly handle strings, which might make it easier for remote attackers to capture credentials via a crafted web site.
nvd
CVE-2009-1413P4MEDIUMCVSS 4.3v1.0.154.36v1.0.154.39+5 more2009-04-24
CVE-2009-1413 [MEDIUM] CWE-264 CVE-2009-1413: Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attac Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Universal XSS attacks by calling setTimeout to trigger future execution of JavaScript code, and then modifying document.location to arrange for JavaScript execution in the context of an arbitrary web site. NOTE: this can be leveraged for
nvd
CVE-2018-20069P4MEDIUMCVSS 4.3fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802019-01-09
CVE-2018-20069 [MEDIUM] CVE-2018-20069: Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.
nvd
CVE-2025-13635P4MEDIUMCVSS 4.4fixed in 143.0.7499.40≥ 143.0.7499.41, < 143.0.7499.412025-12-02
CVE-2025-13635 [MEDIUM] CWE-290 CVE-2025-13635: Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local at Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-13905P4MEDIUMCVSS 4.2fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13905 [MEDIUM] CWE-362 CVE-2026-13905: Race in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to ob Race in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: Medium)
nvd
CVE-2026-10998P4MEDIUMCVSS 4.0fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10998 [MEDIUM] CWE-125 CVE-2026-10998: Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of bounds memory read via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-18018P4MEDIUMCVSS 4.0fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-18018 [MEDIUM] CWE-451 CVE-2026-18018: Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
nvd
CVE-2026-17902P4LOWCVSS 3.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17902 [LOW] CWE-200 CVE-2026-17902: Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a r Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2011-0470P4MEDIUMCVSS 5.0fixed in 8.0.552.2372011-01-14
CVE-2011-0470 [MEDIUM] CVE-2011-0470: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle extensions Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle extensions notification, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2012-5132P4MEDIUMCVSS 5.0≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5132 [MEDIUM] CVE-2012-5132: Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service (application crash) via a response with chunked transfer coding.
nvd
CVE-2011-0779P4MEDIUMCVSS 5.0fixed in 9.0.597.842011-02-04
CVE-2011-0779 [MEDIUM] CWE-20 CVE-2011-0779: Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows remote attackers to cause a denial of service (application crash) via a crafted extension.
nvd
CVE-2010-4008P4MEDIUMCVSS 4.3fixed in 7.0.517.442010-11-17
CVE-2010-4008 [MEDIUM] CWE-119 CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, an libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2012-2877P4MEDIUMCVSS 5.0≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2877 [MEDIUM] CWE-20 CVE-2012-2877: The extension system in Google Chrome before 22.0.1229.79 does not properly handle modal dialogs, wh The extension system in Google Chrome before 22.0.1229.79 does not properly handle modal dialogs, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2009-2974P4MEDIUMCVSS 5.0≤ 1.0.154.48v0.2.149.27+19 more2009-08-27
CVE-2009-2974 [MEDIUM] CVE-2009-2974: Google Chrome 1.0.154.65, 1.0.154.48, and earlier allows remote attackers to (1) cause a denial of s Google Chrome 1.0.154.65, 1.0.154.48, and earlier allows remote attackers to (1) cause a denial of service (application hang) via vectors involving a chromehtml: URI value for the document.location property or (2) cause a denial of service (application hang and CPU consumption) via vectors involving a series of function calls that set a chromehtml: URI value
nvd
CVE-2011-3954P4MEDIUMCVSS 5.0fixed in 17.0.963.462012-02-09
CVE-2011-3954 [MEDIUM] CWE-400 CVE-2011-3954: Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application c Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via vectors that trigger a large amount of database usage.
nvd
Google Chrome vulnerabilities | cvebase