cbcvebase.

Google Chrome vulnerabilities

5,463 known vulnerabilities affecting google/chrome.

Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65

Vulnerabilities

Page 3 of 274
CVE-2025-10585P1CRITICALCVSS 9.8KEVfixed in 140.0.7339.185≥ 140.0.7339.185, < 140.0.7339.1852025-09-24
CVE-2025-10585 [CRITICAL] CWE-843 CVE-2025-10585: Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potential Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-37975P1HIGHCVSS 8.8KEVfixed in 94.0.4606.71≥ unspecified, < 94.0.4606.712021-10-08
CVE-2021-37975 [HIGH] CWE-416 CVE-2021-37975: Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-1096P1HIGHCVSS 8.8KEVfixed in 99.0.4844.84≥ unspecified, < 99.0.4844.842022-07-23
CVE-2022-1096 [HIGH] CWE-843 CVE-2022-1096: Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-17480P1HIGHCVSS 8.8KEVfixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-17480 [HIGH] CWE-787 CVE-2018-17480: Execution of user supplied Javascript during array deserialization leading to an out of bounds write Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2022-3038P1HIGHCVSS 8.8KEVfixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3038 [HIGH] CWE-416 CVE-2022-3038: Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21166P1HIGHCVSS 8.8KEVfixed in 89.0.4389.72≥ unspecified, < 89.0.4389.722021-03-09
CVE-2021-21166 [HIGH] CWE-362 CVE-2021-21166: Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially e Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5030P1HIGHCVSS 8.8KEVfixed in 57.0.2987.98fixed in 57.0.2987.1082017-04-24
CVE-2017-5030 [HIGH] CWE-125 CVE-2017-5030: Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Window Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2024-4671P1CRITICALCVSS 9.6KEVfixed in 124.0.6367.201≥ 124.0.6367.201, < 124.0.6367.2012024-05-14
CVE-2024-4671 [CRITICAL] CWE-416 CVE-2024-4671: Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-37973P1CRITICALCVSS 9.6KEVfixed in 94.0.4606.61≥ unspecified, < 94.0.4606.612021-10-08
CVE-2021-37973 [CRITICAL] CWE-416 CVE-2021-37973: Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had c Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2025-13223P1HIGHCVSS 8.8KEVfixed in 142.0.7444.1752025-11-17
CVE-2025-13223 [HIGH] CWE-843 CVE-2025-13223: Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potential Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2016-5198P1HIGHCVSS 8.8KEVfixed in 54.0.2840.90fixed in 54.0.2840.85+1 more2017-01-19
CVE-2016-5198 [HIGH] CWE-125 CVE-2016-5198: V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
nvd
CVE-2021-21148P1HIGHCVSS 8.8KEVfixed in 88.0.4324.150≥ unspecified, < 88.0.4324.1502021-02-09
CVE-2021-21148 [HIGH] CWE-787 CVE-2021-21148: Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to pote Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-2136P1CRITICALCVSS 9.6KEVfixed in 112.0.5615.137≥ 112.0.5615.137, < 112.0.5615.1372023-04-19
CVE-2023-2136 [CRITICAL] CWE-190 CVE-2023-2136: Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2017-5070P1HIGHCVSS 8.8KEVfixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5070 [HIGH] CWE-843 CVE-2017-5070: Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.30 Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2024-4761P1HIGHCVSS 8.8KEVfixed in 124.0.6367.207≥ 124.0.6367.207, < 124.0.6367.2072024-05-14
CVE-2024-4761 [HIGH] CWE-787 CVE-2024-4761: Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perf Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11645P1HIGHCVSS 8.8KEVfixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11645 [HIGH] CWE-125 CVE-2026-11645: Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacke Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3075P1CRITICALCVSS 9.6KEVfixed in 105.0.5195.102≥ unspecified, < 105.0.5195.1022022-09-26
CVE-2022-3075 [CRITICAL] CWE-20 CVE-2022-3075: Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attac Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2016-1646P2HIGHCVSS 8.8KEVfixed in 49.0.2623.1082016-03-29
CVE-2016-1646 [HIGH] CWE-125 CVE-2016-1646: The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome befo The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2026-3910P1HIGHCVSS 8.8KEVfixed in 146.0.7680.75≥ 146.0.7680.75, < 146.0.7680.752026-03-13
CVE-2026-3910 [HIGH] CWE-94 CVE-2026-3910: Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3723P1HIGHCVSS 8.8KEVfixed in 107.0.5304.87≥ unspecified, < 107.0.5304.872022-11-01
CVE-2022-3723 [HIGH] CWE-843 CVE-2022-3723: Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase