Google Chrome vulnerabilities

3,975 known vulnerabilities affecting google/chrome.

Total CVEs
3,975
CISA KEV
74
actively exploited
Public exploits
63
Exploited in wild
65
Severity breakdown
CRITICAL297HIGH2024MEDIUM1626LOW17UNKNOWN11

Vulnerabilities

Page 36 of 199
CVE-2023-5855HIGHCVSS 8.8fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5855 [HIGH] CWE-416 CVE-2023-5855: Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker wh Use after free in Reading Mode in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
nvd
CVE-2023-5852HIGHCVSS 8.8fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5852 [HIGH] CWE-416 CVE-2023-5852: Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who co Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
nvd
CVE-2023-5854HIGHCVSS 8.8fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5854 [HIGH] CWE-416 CVE-2023-5854: Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who co Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
nvd
CVE-2023-5858MEDIUMCVSS 4.3fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5858 [MEDIUM] CWE-346 CVE-2023-5858: Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a r Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5853MEDIUMCVSS 4.3fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5853 [MEDIUM] CWE-346 CVE-2023-5853: Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacke Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5850MEDIUMCVSS 4.3fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5850 [MEDIUM] CVE-2023-5850: Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacke Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
nvd
CVE-2023-5859MEDIUMCVSS 4.3fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5859 [MEDIUM] CWE-346 CVE-2023-5859: Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remot Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5851MEDIUMCVSS 4.3fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5851 [MEDIUM] CWE-346 CVE-2023-5851: Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5480MEDIUMCVSS 6.1fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5480 [MEDIUM] CWE-79 CVE-2023-5480: Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote a Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)
nvd
CVE-2023-5472HIGHCVSS 8.8fixed in 118.0.5993.117≥ 118.0.5993.117, < 118.0.5993.1172023-10-25
CVE-2023-5472 [HIGH] CWE-416 CVE-2023-5472: Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to pot Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5476HIGHCVSS 8.8fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5476 [HIGH] CWE-416 CVE-2023-5476: Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5474HIGHCVSS 8.8fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5474 [HIGH] CWE-787 CVE-2023-5474: Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who co Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
nvd
CVE-2023-5218HIGHCVSS 8.8fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5218 [HIGH] CWE-416 CVE-2023-5218: Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker t Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2023-5479MEDIUMCVSS 6.5fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5479 [MEDIUM] CVE-2023-5479: Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an at Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5485MEDIUMCVSS 4.3fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5485 [MEDIUM] CWE-79 CVE-2023-5485: Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5484MEDIUMCVSS 6.5fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5484 [MEDIUM] CVE-2023-5484: Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5475MEDIUMCVSS 6.5fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5475 [MEDIUM] CVE-2023-5475: Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2023-5473MEDIUMCVSS 6.3fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5473 [MEDIUM] CWE-416 CVE-2023-5473: Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had com Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5486MEDIUMCVSS 4.3fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5486 [MEDIUM] CVE-2023-5486: Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attac Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5487MEDIUMCVSS 6.5fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5487 [MEDIUM] CVE-2023-5487: Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attack Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase