cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 286 of 292
CVE-2010-3411P4MEDIUMCVSS 5.0fixed in 6.0.472.592010-09-16
CVE-2010-3411 [MEDIUM] CWE-617 CVE-2010-3411: Google Chrome before 6.0.472.59 on Linux does not properly handle cursors, which might allow attacke Google Chrome before 6.0.472.59 on Linux does not properly handle cursors, which might allow attackers to cause a denial of service (assertion failure) via unspecified vectors.
nvd
CVE-2011-2804P4MEDIUMCVSS 4.3fixed in 13.0.782.1072011-08-03
CVE-2011-2804 [MEDIUM] CWE-20 CVE-2011-2804: Google Chrome before 13.0.782.107 does not properly handle nested functions in PDF documents, which Google Chrome before 13.0.782.107 does not properly handle nested functions in PDF documents, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2010-4575P4MEDIUMCVSS 4.3fixed in 8.0.552.2242010-12-22
CVE-2010-4575 [MEDIUM] CWE-20 CVE-2010-4575: The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/theme_installed_infobar_de The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/theme_installed_infobar_delegate.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle incorrect tab interaction by an extension, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted
nvd
CVE-2011-1811P4MEDIUMCVSS 4.3fixed in 12.0.742.912011-06-09
CVE-2011-1811 [MEDIUM] CWE-20 CVE-2011-1811: Google Chrome before 12.0.742.91 does not properly handle a large number of form submissions, which Google Chrome before 12.0.742.91 does not properly handle a large number of form submissions, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2010-4489P4MEDIUMCVSS 4.3≤ 8.0.552.2142010-12-07
CVE-2010-4489 [MEDIUM] CWE-119 CVE-2010-4489: libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attac libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.
nvd
CVE-2010-3251P4MEDIUMCVSS 4.3fixed in 6.0.472.532010-09-07
CVE-2010-3251 [MEDIUM] CWE-476 CVE-2010-3251: The WebSockets implementation in Google Chrome before 6.0.472.53 allows remote attackers to cause a The WebSockets implementation in Google Chrome before 6.0.472.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
nvd
CVE-2023-3497P4MEDIUMCVSS 4.6fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-07-03
CVE-2023-3497 [MEDIUM] CWE-125 CVE-2023-3497: Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114. Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of service via physical access to the device. (Chromium security severity: Medium)
nvd
CVE-2010-3256P4MEDIUMCVSS 4.3fixed in 6.0.472.532010-09-07
CVE-2010-3256 [MEDIUM] CVE-2010-3256: Google Chrome before 6.0.472.53 does not properly limit the number of stored autocomplete entries, w Google Chrome before 6.0.472.53 does not properly limit the number of stored autocomplete entries, which has unspecified impact and attack vectors.
nvd
CVE-2026-13939P4LOWCVSS 3.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13939 [LOW] CWE-20 CVE-2026-13939: Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 150.0.78 Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17715P4LOWCVSS 3.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17715 [LOW] CWE-346 CVE-2026-17715: Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote a Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17702P4LOWCVSS 3.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17702 [LOW] CWE-346 CVE-2026-17702: Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attack Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11251P4LOWCVSS 3.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11251 [LOW] CWE-20 CVE-2026-11251: Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17826P4LOWCVSS 3.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17826 [LOW] CWE-346 CVE-2026-17826: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17732P4LOWCVSS 3.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17732 [LOW] CWE-346 CVE-2026-17732: Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacke Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8553P4LOWCVSS 3.1fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8553 [LOW] CWE-416 CVE-2026-8553: Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had com Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17957P4LOWCVSS 3.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17957 [LOW] CWE-346 CVE-2026-17957: Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.72 allowed a remote attack Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17997P4LOWCVSS 3.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17997 [LOW] CWE-346 CVE-2026-17997: Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote a Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-8568P4LOWCVSS 3.1fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8568 [LOW] CWE-693 CVE-2026-8568: Insufficient policy enforcement in AI in Google Chrome prior to 148.0.7778.168 allowed a remote atta Insufficient policy enforcement in AI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2009-2578P4MEDIUMCVSS 5.0v2.0.156.1v2.0.157.0+4 more2009-07-22
CVE-2009-2578 [MEDIUM] CVE-2009-2578: Google Chrome 2.x through 2.0.172 allows remote attackers to cause a denial of service (application Google Chrome 2.x through 2.0.172 allows remote attackers to cause a denial of service (application crash) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479.
nvd
CVE-2009-3934P4MEDIUMCVSS 4.3≤ 3.0.195.21v0.2.149.27+41 more2009-11-12
CVE-2009-3934 [MEDIUM] CVE-2009-3934: The WebFrameLoaderClient::dispatchDidChangeLocationWithinPage function in src/webkit/glue/webframelo The WebFrameLoaderClient::dispatchDidChangeLocationWithinPage function in src/webkit/glue/webframeloaderclient_impl.cc in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service via a page-local link, related to an "empty redirect chain," as demonstrated by a message in Yahoo! Mail.
nvd
Google Chrome vulnerabilities | cvebase