Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 289 of 292
CVE-2026-7959P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7959 [LOW] CWE-284 CVE-2026-7959: Inappropriate implementation in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote
Inappropriate implementation in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-7909P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7909 [LOW] CWE-693 CVE-2026-7909: Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remo
Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11247P4LOWCVSS 3.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11247 [LOW] CWE-693 CVE-2026-11247: Insufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 all
Insufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11686P4LOWCVSS 3.1fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11686 [LOW] CWE-20 CVE-2026-11686: Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103
Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11684P4LOWCVSS 3.1fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11684 [LOW] CWE-693 CVE-2026-11684: Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote
Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utility process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11691P4LOWCVSS 3.1fixed in 149.0.7827.102≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11691 [LOW] CWE-20 CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103
Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13948P4LOWCVSS 3.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13948 [LOW] CWE-451 CVE-2026-13948: Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an att
Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2026-13945P4LOWCVSS 3.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13945 [LOW] CWE-451 CVE-2026-13945: Insufficient policy enforcement in Extensions in Google Chrome on Linux prior to 150.0.7871.47 allow
Insufficient policy enforcement in Extensions in Google Chrome on Linux prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2026-10011P4LOWCVSS 3.1fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-10011 [LOW] CWE-200 CVE-2026-10011: Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attac
Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-16417P4LOWCVSS 3.1fixed in 150.0.7871.182≥ 150.0.7871.182, < 150.0.7871.1822026-07-21
CVE-2026-16417 [LOW] CWE-457 CVE-2026-16417: Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8545P4LOWCVSS 3.1fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8545 [LOW] CWE-119 CVE-2026-8545: Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker
Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8572P4LOWCVSS 3.1fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8572 [LOW] CWE-693 CVE-2026-8572: Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allow
Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8578P4LOWCVSS 3.1fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8578 [LOW] CWE-125 CVE-2026-8578: Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacke
Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-12032P4LOWCVSS 3.1fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12032 [LOW] CWE-346 CVE-2026-12032: Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowe
Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7954P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7954 [LOW] CWE-362 CVE-2026-7954: Race in Shared Storage in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had com
Race in Shared Storage in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-8022P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8022 [LOW] CWE-1021 CVE-2026-8022: Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attac
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted MHTML page. (Chromium security severity: Low)
nvd
CVE-2026-7937P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7937 [LOW] CWE-693 CVE-2026-7937: Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attac
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2010-4484P4MEDIUMCVSS 5.0≤ 8.0.552.2142010-12-07
CVE-2010-4484 [MEDIUM] CVE-2010-4484: Google Chrome before 8.0.552.215 does not properly handle HTML5 databases, which allows attackers to
Google Chrome before 8.0.552.215 does not properly handle HTML5 databases, which allows attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2010-2652P4MEDIUMCVSS 5.0fixed in 5.0.375.992010-07-06
CVE-2010-2652 [MEDIUM] CVE-2010-2652: Google Chrome before 5.0.375.99 does not properly implement modal dialogs, which allows attackers to
Google Chrome before 5.0.375.99 does not properly implement modal dialogs, which allows attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2011-2761P4MEDIUMCVSS 4.3v14.0.794.02011-07-18
CVE-2011-2761 [MEDIUM] CWE-399 CVE-2011-2761: Google Chrome 14.0.794.0 does not properly handle a reload of a page generated in response to a POST
Google Chrome 14.0.794.0 does not properly handle a reload of a page generated in response to a POST, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web site, related to GetWidget methods.
nvd