cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 288 of 292
CVE-2026-8579P4LOWCVSS 3.1fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8579 [LOW] CWE-20 CVE-2026-8579: Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted print file. (Chromium security severity: Medium)
nvd
CVE-2011-0783P4MEDIUMCVSS 4.3fixed in 9.0.597.842011-02-04
CVE-2011-0783 [MEDIUM] CVE-2011-0783: Unspecified vulnerability in Google Chrome before 9.0.597.84 allows user-assisted remote attackers t Unspecified vulnerability in Google Chrome before 9.0.597.84 allows user-assisted remote attackers to cause a denial of service (application crash) via vectors involving a "bad volume setting."
nvd
CVE-2010-2120P4MEDIUMCVSS 4.3v1.0.154.482010-06-01
CVE-2010-2120 [MEDIUM] CWE-399 CVE-2010-2120: Google Chrome 1.0.154.48 allows remote attackers to cause a denial of service (resource consumption) Google Chrome 1.0.154.48 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
nvd
CVE-2011-3024P4MEDIUMCVSS 4.3fixed in 17.0.963.562012-02-16
CVE-2011-3024 [MEDIUM] CWE-295 CVE-2011-3024: Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service (application c Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service (application crash) via an empty X.509 certificate.
nvd
CVE-2010-4485P4MEDIUMCVSS 4.3≤ 8.0.552.2142010-12-07
CVE-2010-4485 [MEDIUM] CWE-264 CVE-2010-4485: Google Chrome before 8.0.552.215 does not properly restrict the generation of file dialogs, which al Google Chrome before 8.0.552.215 does not properly restrict the generation of file dialogs, which allows remote attackers to cause a denial of service (reduced usability and possible application crash) via a crafted web site.
nvd
CVE-2009-1414P4MEDIUMCVSS 4.3v2.0.156.1v2.0.157.0+3 more2009-04-24
CVE-2009-1414 [MEDIUM] CWE-264 CVE-2009-1414: Google Chrome 2.0.x lets modifications to the global object persist across a page transition, which Google Chrome 2.0.x lets modifications to the global object persist across a page transition, which makes it easier for attackers to conduct Universal XSS attacks via unspecified vectors.
nvd
CVE-2016-5166P4LOWCVSS 3.1≤ 52.0.2743.1162016-09-11
CVE-2016-5166 [LOW] CWE-200 CVE-2016-5166: The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0 The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:// URL that is referenced by an http:// URL, which makes it easier for user-assisted remote attackers to discover NetNTLM hashes and conduct SMB relay attacks via a crafted web page that is accesse
nvd
CVE-2010-0650P4LOWCVSS 2.6fixed in 4.0.249.782010-02-18
CVE-2010-0650 [LOW] CWE-264 CVE-2010-0650: WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypa WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.
nvd
CVE-2026-17860P4LOWCVSS 3.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17860 [LOW] CWE-20 CVE-2026-17860: Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922 Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-15115P4LOWCVSS 3.3fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15115 [LOW] CWE-20 CVE-2026-15115: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 15 Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6312P4LOWCVSS 3.1fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6312 [LOW] CWE-284 CVE-2026-6312: Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remo Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9920P4LOWCVSS 3.1fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9920 [LOW] CWE-457 CVE-2026-9920: Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attack Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7965P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7965 [LOW] CWE-20 CVE-2026-7965: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 148.0.7778.96 allow Insufficient validation of untrusted input in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-6313P4LOWCVSS 3.1fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6313 [LOW] CWE-284 CVE-2026-6313: Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote at Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13982P4LOWCVSS 3.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13982 [LOW] CWE-451 CVE-2026-13982: Incorrect security UI in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker Incorrect security UI in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11675P4LOWCVSS 3.1fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11675 [LOW] CWE-20 CVE-2026-11675: Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who ha Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8556P4LOWCVSS 3.1fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8556 [LOW] CWE-119 CVE-2026-8556: Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13963P4LOWCVSS 3.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13963 [LOW] CWE-352 CVE-2026-13963: Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote at Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13944P4LOWCVSS 3.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13944 [LOW] CWE-352 CVE-2026-13944: Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9944P4LOWCVSS 3.1fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9944 [LOW] CWE-457 CVE-2026-9944: Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who ha Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase