Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82
Vulnerabilities
Page 33 of 292
CVE-2026-5902P3CRITICALCVSS 9.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5902 [CRITICAL] CWE-362 CVE-2026-5902: Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had c
Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-10881P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10881 [CRITICAL] CWE-125 CVE-2026-10881: Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attac
Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2025-4609P3CRITICALCVSS 9.6fixed in 136.0.7103.113≥ 136.0.7103.113, < 136.0.7103.1132025-08-22
CVE-2025-4609 [CRITICAL] CWE-732 CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-13934P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13934 [CRITICAL] CWE-20 CVE-2026-13934: Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.4
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11043P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11043 [CRITICAL] CWE-787 CVE-2026-11043: Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacke
Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10966P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10966 [CRITICAL] CWE-20 CVE-2026-10966: Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote atta
Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)
nvd
CVE-2026-17691P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17691 [CRITICAL] CWE-787 CVE-2026-17691: Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote att
Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17713P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17713 [CRITICAL] CWE-20 CVE-2026-17713: Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151
Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14387P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14387 [CRITICAL] CWE-472 CVE-2026-14387: Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potent
Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14017P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14017 [CRITICAL] CWE-693 CVE-2026-14017: Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote
Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11052P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11052 [CRITICAL] CWE-843 CVE-2026-11052: Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker w
Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11061P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11061 [CRITICAL] CWE-125 CVE-2026-11061: Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potenti
Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11066P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11066 [CRITICAL] CWE-20 CVE-2026-11066: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14097P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14097 [CRITICAL] CWE-693 CVE-2026-14097: Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowe
Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-9918P3CRITICALCVSS 9.6fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9918 [CRITICAL] CWE-269 CVE-2026-9918: Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attac
Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14056P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14056 [CRITICAL] CWE-20 CVE-2026-14056: Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed
Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Low)
nvd
CVE-2026-15900P3CRITICALCVSS 9.6fixed in 150.0.7871.128≥ 150.0.7871.128, < 150.0.7871.1282026-07-20
CVE-2026-15900 [CRITICAL] CWE-416 CVE-2026-15900: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-14101P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14101 [CRITICAL] CWE-693 CVE-2026-14101: Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a
Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11152P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11152 [CRITICAL] CWE-416 CVE-2026-11152: Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to
Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11146P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11146 [CRITICAL] CWE-20 CVE-2026-11146: Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 all
Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd