Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82
Vulnerabilities
Page 37 of 292
CVE-2026-13774P3HIGHCVSS 8.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13774 [HIGH] CWE-416 CVE-2026-13774: Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinc
Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)
nvd
CVE-2026-14111P3HIGHCVSS 8.1fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14111 [HIGH] CWE-416 CVE-2026-14111: Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinc
Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2020-16025P3CRITICALCVSS 9.6fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16025 [CRITICAL] CWE-787 CVE-2020-16025: Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker w
Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-16024P3CRITICALCVSS 9.6fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16024 [CRITICAL] CWE-787 CVE-2020-16024: Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had
Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21201P3CRITICALCVSS 9.6fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21201 [CRITICAL] CWE-416 CVE-2021-21201: Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who h
Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-30547P3HIGHCVSS 8.8fixed in 91.0.4472.101≥ unspecified, < 91.0.4472.1012021-06-15
CVE-2021-30547 [HIGH] CWE-787 CVE-2021-30547: Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to po
Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2024-3157P3CRITICALCVSS 9.6fixed in 123.0.6312.122≥ 123.0.6312.122, < 123.0.6312.1222024-04-10
CVE-2024-3157 [CRITICAL] CWE-787 CVE-2024-3157: Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote
Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)
nvd
CVE-2017-15407P3HIGHCVSS 8.8fixed in 63.0.3239.842018-08-28
CVE-2017-15407 [HIGH] CWE-787 CVE-2017-15407: Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a re
Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.
nvd
CVE-2026-3916P3CRITICALCVSS 9.6fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3916 [CRITICAL] CWE-125 CVE-2026-3916: Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker t
Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9872P3CRITICALCVSS 9.6fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9872 [CRITICAL] CWE-787 CVE-2026-9872: Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote atta
Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10892P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10892 [CRITICAL] CWE-787 CVE-2026-10892: Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attac
Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-14392P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14392 [CRITICAL] CWE-787 CVE-2026-14392: Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to pot
Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14106P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14106 [CRITICAL] CWE-20 CVE-2026-14106: Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.4
Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14420P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14420 [CRITICAL] CWE-125 CVE-2026-14420: Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attack
Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-11659P3CRITICALCVSS 9.6fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11659 [CRITICAL] CWE-20 CVE-2026-11659: Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker t
Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5288P3CRITICALCVSS 9.6fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5288 [CRITICAL] CWE-416 CVE-2026-5288: Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attac
Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11282P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11282 [CRITICAL] CWE-693 CVE-2026-11282: Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed
Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-9876P3CRITICALCVSS 9.6fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9876 [CRITICAL] CWE-416 CVE-2026-9876: Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacke
Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-11163P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11163 [CRITICAL] CWE-416 CVE-2026-11163: Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attac
Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13882P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13882 [CRITICAL] CWE-362 CVE-2026-13882: Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised th
Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd