cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82

Vulnerabilities

Page 32 of 292
CVE-2026-8002P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8002 [HIGH] CWE-416 CVE-2026-8002: Use after free in Audio in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to Use after free in Audio in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17935P3HIGHCVSS 8.8≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17935 [HIGH] CWE-122 CVE-2026-17935: Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11303P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11303 [HIGH] CWE-416 CVE-2026-11303: Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
nvd
CVE-2026-13031P3HIGHCVSS 8.8fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13031 [HIGH] CWE-416 CVE-2026-13031: Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execut Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9992P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9992 [HIGH] CWE-416 CVE-2026-9992: Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to exec Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9978P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9978 [HIGH] CWE-416 CVE-2026-9978: Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-15125P3HIGHCVSS 8.8fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15125 [HIGH] CWE-863 CVE-2026-15125: Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote atta Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11307P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11307 [HIGH] CWE-416 CVE-2026-11307: Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
nvd
CVE-2026-11305P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11305 [HIGH] CWE-416 CVE-2026-11305: Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
nvd
CVE-2026-11670P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11670 [HIGH] CWE-416 CVE-2026-11670: Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2026-11306P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11306 [HIGH] CWE-416 CVE-2026-11306: Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
nvd
CVE-2026-9887P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9887 [HIGH] CWE-416 CVE-2026-9887: Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical)
nvd
CVE-2026-17920P3HIGHCVSS 8.8≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17920 [HIGH] CWE-416 CVE-2026-17920: Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a use Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2021-30561P3HIGHCVSS 8.8fixed in 91.0.4472.164≥ unspecified, < 91.0.4472.1642021-08-03
CVE-2021-30561 [HIGH] CWE-843 CVE-2021-30561: Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-13791P3HIGHCVSS 8.1fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13791 [HIGH] CWE-20 CVE-2026-13791: Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allo Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2026-11224P3HIGHCVSS 8.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11224 [HIGH] CWE-416 CVE-2026-11224: Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attac Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2021-21106P3CRITICALCVSS 9.6fixed in 87.0.4280.141≥ unspecified, < 87.0.4280.1412021-01-08
CVE-2021-21106 [CRITICAL] CWE-416 CVE-2021-21106: Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2023-1531P3HIGHCVSS 8.8fixed in 111.0.5563.110≥ 111.0.5563.110, < 111.0.5563.1102023-03-21
CVE-2023-1531 [HIGH] CWE-416 CVE-2023-1531: Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potent Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-0808P3CRITICALCVSS 9.8fixed in 121.0.6167.85≥ 121.0.6167.85, < 121.0.6167.852024-01-24
CVE-2024-0808 [CRITICAL] CWE-191 CVE-2024-0808: Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to pote Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
nvd
CVE-2014-3188P3CRITICALCVSS 10.0≤ 38.0.2125.72014-10-08
CVE-2014-3188 [CRITICAL] CWE-94 CVE-2014-3188: Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the int Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.
nvd
Google Chrome vulnerabilities | cvebase