cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82

Vulnerabilities

Page 29 of 292
CVE-2026-7358P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7358 [HIGH] CWE-416 CVE-2026-7358: Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to ex Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14086P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14086 [HIGH] CWE-602 CVE-2026-14086: Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote atta Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-11460P3HIGHCVSS 8.8fixed in 141.0.7390.65≥ 141.0.7390.65, < 141.0.7390.652025-11-06
CVE-2025-11460 [HIGH] CWE-416 CVE-2025-11460: Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execu Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)
nvd
CVE-2026-5286P3HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5286 [HIGH] CWE-416 CVE-2026-5286: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7335P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7335 [HIGH] CWE-416 CVE-2026-7335: Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execut Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7356P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7356 [HIGH] CWE-416 CVE-2026-7356: Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to e Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11117P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11117 [HIGH] CWE-416 CVE-2026-11117: Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5872P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5872 [HIGH] CWE-416 CVE-2026-5872: Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5861P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5861 [HIGH] CWE-416 CVE-2026-5861: Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute ar Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5879P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5879 [HIGH] CWE-20 CVE-2026-5879: Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 a Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5866P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5866 [HIGH] CWE-416 CVE-2026-5866: Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9976P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9976 [HIGH] CWE-94 CVE-2026-9976: Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attack Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14430P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14430 [HIGH] CWE-472 CVE-2026-14430: Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14006P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14006 [HIGH] CWE-416 CVE-2026-14006: Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to ex Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9883P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9883 [HIGH] CWE-416 CVE-2026-9883: Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-9969P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9969 [HIGH] CWE-20 CVE-2026-9969: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8527P3HIGHCVSS 8.8fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8527 [HIGH] CWE-20 CVE-2026-8527: Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 all Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5883P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5883 [HIGH] CWE-416 CVE-2026-5883: Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-30573P3HIGHCVSS 8.8fixed in 92.0.4515.107≥ unspecified, < 92.0.4515.1072021-08-03
CVE-2021-30573 [HIGH] CWE-416 CVE-2021-30573: Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potential Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-11262P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11262 [HIGH] CWE-416 CVE-2026-11262: Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to exec Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
nvd
Google Chrome vulnerabilities | cvebase