cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82

Vulnerabilities

Page 38 of 292
CVE-2026-14152P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14152 [CRITICAL] CWE-787 CVE-2026-14152: Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attac Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-16424P3CRITICALCVSS 9.6fixed in 150.0.7871.182≥ 150.0.7871.182, < 150.0.7871.1822026-07-21
CVE-2026-16424 [CRITICAL] CWE-416 CVE-2026-16424: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11198P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11198 [CRITICAL] CWE-20 CVE-2026-11198: Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
nvd
CVE-2026-17721P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17721 [CRITICAL] CWE-787 CVE-2026-17721: Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to po Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17727P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17727 [CRITICAL] CWE-787 CVE-2026-17727: Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote att Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17726P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17726 [CRITICAL] CWE-190 CVE-2026-17726: Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attack Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-15113P3CRITICALCVSS 9.6fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15113 [CRITICAL] CWE-416 CVE-2026-15113: Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote atta Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17940P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17940 [CRITICAL] CWE-20 CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior t Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-18015P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-18015 [CRITICAL] CWE-693 CVE-2026-18015: Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4352P3HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4352 [HIGH] CWE-843 CVE-2023-4352: Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5346P3HIGHCVSS 8.8fixed in 117.0.5938.149≥ 117.0.5938.149, < 117.0.5938.1492023-10-05
CVE-2023-5346 [HIGH] CWE-843 CVE-2023-5346: Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potential Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14038P3CRITICALCVSS 9.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14038 [CRITICAL] CWE-20 CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 a Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-3061P3CRITICALCVSS 9.1fixed in 145.0.7632.116fixed in 145.0.7632.117+1 more2026-02-23
CVE-2026-3061 [CRITICAL] CWE-125 CVE-2026-3061: Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to pe Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-2649P3HIGHCVSS 8.8fixed in 145.0.7632.109≥ 145.0.7632.109, < 145.0.7632.1092026-02-18
CVE-2026-2649 [HIGH] CWE-472 CVE-2026-2649: Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potenti Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4673P3HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4673 [HIGH] CWE-122 CVE-2026-4673: Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-3538P3HIGHCVSS 8.8fixed in 145.0.7632.159≥ 145.0.7632.159, < 145.0.7632.1592026-03-04
CVE-2026-3538 [HIGH] CWE-472 CVE-2026-3538: Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to poten Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-2648P3HIGHCVSS 8.8fixed in 145.0.7632.109≥ 145.0.7632.109, < 145.0.7632.1092026-02-18
CVE-2026-2648 [HIGH] CWE-122 CVE-2026-2648: Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2026-3536P3HIGHCVSS 8.8fixed in 145.0.7632.159fixed in 145.0.7632.160+1 more2026-03-04
CVE-2026-3536 [HIGH] CWE-472 CVE-2026-3536: Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to pote Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-4674P3HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4674 [HIGH] CWE-125 CVE-2026-4674: Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perf Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13630P3HIGHCVSS 8.8fixed in 143.0.7499.40≥ 143.0.7499.41, < 143.0.7499.412025-12-02
CVE-2025-13630 [HIGH] CWE-843 CVE-2025-13630: Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase