cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 290 of 292
CVE-2010-2649P4MEDIUMCVSS 4.3fixed in 5.0.375.992010-07-06
CVE-2010-2649 [MEDIUM] CVE-2010-2649: Unspecified vulnerability in Google Chrome before 5.0.375.99 allows remote attackers to cause a deni Unspecified vulnerability in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (application crash) via an invalid image.
nvd
CVE-2021-37964P4LOWCVSS 3.3fixed in 94.0.4606.54≥ unspecified, < 94.0.4606.542021-10-08
CVE-2021-37964 [LOW] CVE-2021-37964: Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606. Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireless access point to to potentially carryout a wifi impersonation attack via a crafted ONC file.
nvd
CVE-2017-5081P4LOWCVSS 3.3fixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5081 [LOW] CWE-20 CVE-2017-5081: Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.
nvd
CVE-2019-13762P4LOWCVSS 3.3fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13762 [LOW] CWE-667 CVE-2019-13762: Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allow Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.
nvd
CVE-2026-13942P4LOWCVSS 3.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13942 [LOW] CWE-20 CVE-2026-13942: Inappropriate implementation in Video Capture in Google Chrome on ChromeOS prior to 150.0.7871.47 al Inappropriate implementation in Video Capture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13955P4LOWCVSS 3.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13955 [LOW] CWE-20 CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0. Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2024-6996P4LOWCVSS 3.1fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-6996 [LOW] CWE-362 CVE-2024-6996: Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a use Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7949P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7949 [LOW] CWE-125 CVE-2026-7949: Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-3929P4LOWCVSS 3.1fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3929 [LOW] CWE-1300 CVE-2026-3929: Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8017P4LOWCVSS 3.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8017 [LOW] CWE-1300 CVE-2026-8017: Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote a Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-9991P4LOWCVSS 3.1fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9991 [LOW] CWE-200 CVE-2026-9991: Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9959P4LOWCVSS 3.1fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9959 [LOW] CWE-362 CVE-2026-9959: Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7351P4LOWCVSS 3.1fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7351 [LOW] CWE-362 CVE-2026-7351: Race in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who convinced a user to i Race in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2018-6053P4LOWCVSS 3.3fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6053 [LOW] CWE-200 CVE-2018-6053: Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.
nvd
CVE-2019-13679P4LOWCVSS 3.3fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13679 [LOW] CWE-732 CVE-2019-13679: Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote at Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to show print dialogs via a crafted PDF file.
nvd
CVE-2022-4923P4LOWCVSS 3.1fixed in 99.0.4844.51≥ 99.0.4844.51, < 99.0.4844.512023-07-29
CVE-2022-4923 [LOW] CVE-2022-4923: Inappropriate implementation in Omnibox in Google Chrome prior to 99.0.4844.51 allowed an attacker i Inappropriate implementation in Omnibox in Google Chrome prior to 99.0.4844.51 allowed an attacker in a privileged network position to perform a man-in-the-middle attack via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2026-18011P4LOWCVSS 2.4fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-18011 [LOW] CWE-200 CVE-2026-18011: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: Low)
nvd
CVE-2011-2784P4LOWCVSS 2.1fixed in 13.0.782.1072011-08-03
CVE-2011-2784 [LOW] CWE-200 CVE-2011-2784: Google Chrome before 13.0.782.107 allows remote attackers to obtain sensitive information via a requ Google Chrome before 13.0.782.107 allows remote attackers to obtain sensitive information via a request for the GL program log, which reveals a local path in an unspecified log entry.
nvd
CVE-2026-12440CRITICALCVSS 9.6≥ 149.0.7827.155, < 149.0.7827.1552026-06-17
CVE-2026-12440 [CRITICAL] CWE-416 CVE-2026-12440: Use after free in DigitalCredentials in Google Chrome on Windows prior to 149 Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
cvelistv5
CVE-2026-12443HIGHCVSS 8.8≥ 149.0.7827.155, < 149.0.7827.1552026-06-17
CVE-2026-12443 [HIGH] CWE-416 CVE-2026-12443: Use after free in Web Authentication in Google Chrome prior to 149 Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
cvelistv5
Google Chrome vulnerabilities | cvebase