Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 287 of 292
CVE-2011-2787P4MEDIUMCVSS 4.3fixed in 13.0.782.1072011-08-03
CVE-2011-2787 [MEDIUM] CWE-20 CVE-2011-2787: Google Chrome before 13.0.782.107 does not properly address re-entrancy issues associated with the G
Google Chrome before 13.0.782.107 does not properly address re-entrancy issues associated with the GPU lock, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2009-3011P4MEDIUMCVSS 4.3≤ 1.0.154.48v0.2.149.27+18 more2009-08-31
CVE-2009-3011 [MEDIUM] CWE-79 CVE-2009-3011: Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta does not properly b
Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta does not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI or (2) ente
nvd
CVE-2025-13640P4LOWCVSS 3.5fixed in 143.0.7499.40fixed in 143.0.7499.41+1 more2025-12-02
CVE-2025-13640 [LOW] CVE-2025-13640: Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local at
Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass authentication via physical access to the device. (Chromium security severity: Low)
nvd
CVE-2026-17766P4LOWCVSS 3.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17766 [LOW] CWE-20 CVE-2026-17766: Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7
Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17984P4LOWCVSS 3.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17984 [LOW] CWE-346 CVE-2026-17984: Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a
Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-11219P4LOWCVSS 3.1fixed in 141.0.7390.54≥ 141.0.7390.54, < 141.0.7390.542025-11-06
CVE-2025-11219 [LOW] CWE-416 CVE-2025-11219: Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentiall
Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-7966P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7966 [LOW] CWE-20 CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96
Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-7968P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7968 [LOW] CWE-20 CVE-2026-7968: Insufficient validation of untrusted input in CORS in Google Chrome prior to 148.0.7778.96 allowed a
Insufficient validation of untrusted input in CORS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-12017P4LOWCVSS 3.1fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12017 [LOW] CWE-20 CVE-2026-12017: Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11244P4LOWCVSS 3.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11244 [LOW] CWE-20 CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827
Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-7944P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7944 [LOW] CWE-20 CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache in Google Chrome prior to 148.0.7778.
Insufficient validation of untrusted input in Persistent Cache in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7945P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7945 [LOW] CWE-20 CVE-2026-7945: Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a
Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9950P4LOWCVSS 3.1fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9950 [LOW] CWE-20 CVE-2026-9950: Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 al
Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11240P4LOWCVSS 3.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11240 [LOW] CWE-20 CVE-2026-11240: Insufficient validation of untrusted input in Loader in Google Chrome prior to 149.0.7827.53 allowed
Insufficient validation of untrusted input in Loader in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-8536P4LOWCVSS 3.1fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8536 [LOW] CWE-20 CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.777
Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass site Isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17720P4LOWCVSS 3.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17720 [LOW] CWE-346 CVE-2026-17720: Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remot
Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17980P4LOWCVSS 3.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17980 [LOW] CWE-451 CVE-2026-17980: Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remo
Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-8554P4LOWCVSS 3.1fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8554 [LOW] CWE-843 CVE-2026-8554: Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacke
Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7360P4LOWCVSS 3.1fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7360 [LOW] CWE-20 CVE-2026-7360: Insufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138
Insufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-18000P4LOWCVSS 3.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-18000 [LOW] CWE-346 CVE-2026-18000: Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a
Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd