cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82

Vulnerabilities

Page 39 of 292
CVE-2025-11756P3HIGHCVSS 8.8fixed in 141.0.7390.107≥ 141.0.7390.107, < 141.0.7390.1072025-11-06
CVE-2025-11756 [HIGH] CWE-416 CVE-2025-11756: Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker w Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-3913P3HIGHCVSS 8.8fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3913 [HIGH] CWE-122 CVE-2026-3913: Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to p Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-1861P3HIGHCVSS 8.8fixed in 144.0.7559.132≥ 144.0.7559.132, < 144.0.7559.1322026-02-03
CVE-2026-1861 [HIGH] CWE-122 CVE-2026-1861: Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13633P3HIGHCVSS 8.8fixed in 143.0.7499.40≥ 143.0.7499.41, < 143.0.7499.412025-12-02
CVE-2025-13633 [HIGH] CWE-416 CVE-2025-13633: Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attac Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2011-0485P3CRITICALCVSS 10.0fixed in 8.0.552.2372011-01-14
CVE-2011-0485 [CRITICAL] CWE-20 CVE-2011-0485: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle speech data Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle speech data, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "stale pointer."
nvd
CVE-2026-10883P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10883 [HIGH] CWE-787 CVE-2026-10883: Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potenti Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-0899P3HIGHCVSS 8.8fixed in 144.0.7559.59fixed in 144.0.7559.60+1 more2026-01-20
CVE-2026-0899 [HIGH] CWE-125 CVE-2026-0899: Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11024P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11024 [HIGH] CWE-121 CVE-2026-11024: Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to p Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-4457P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4457 [HIGH] CWE-843 CVE-2026-4457: Type Confusion in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potential Type Confusion in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-3917P3HIGHCVSS 8.8fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3917 [HIGH] CWE-416 CVE-2026-3917: Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potent Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-21125P3HIGHCVSS 8.1fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21125 [HIGH] CWE-59 CVE-2021-21125: Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
nvd
CVE-2026-3918P3HIGHCVSS 8.8fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3918 [HIGH] CWE-416 CVE-2026-3918: Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potent Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14024P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14024 [HIGH] CWE-416 CVE-2026-14024: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker w Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13825P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13825 [HIGH] CWE-457 CVE-2026-13825: Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to poten Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-3544P3HIGHCVSS 8.8fixed in 145.0.7632.159fixed in 145.0.7632.160+1 more2026-03-04
CVE-2026-3544 [HIGH] CWE-122 CVE-2026-3544: Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-11205P3HIGHCVSS 8.8fixed in 141.0.7390.54≥ 141.0.7390.54, < 141.0.7390.542025-11-06
CVE-2025-11205 [HIGH] CWE-122 CVE-2025-11205: Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-3542P3HIGHCVSS 8.8fixed in 145.0.7632.159fixed in 145.0.7632.160+1 more2026-03-04
CVE-2026-3542 [HIGH] CWE-284 CVE-2026-3542: Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remot Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13777P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13777 [HIGH] CWE-20 CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-4444P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4444 [HIGH] CWE-121 CVE-2026-4444: Stack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker t Stack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4463P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4463 [HIGH] CWE-122 CVE-2026-4463: Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase