Google Chrome vulnerabilities
5,463 known vulnerabilities affecting google/chrome.
Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65
Vulnerabilities
Page 4 of 274
CVE-2026-3909P1HIGHCVSS 8.8KEVfixed in 146.0.7680.80≥ 146.0.7680.75, < 146.0.7680.752026-03-13
CVE-2026-3909 [HIGH] CWE-787 CVE-2026-3909: Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to per
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-7024P1HIGHCVSS 8.8KEVfixed in 120.0.6099.129≥ 120.0.6099.129, < 120.0.6099.1292023-12-21
CVE-2023-7024 [HIGH] CWE-787 CVE-2023-7024: Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-16017P1CRITICALCVSS 9.6KEVfixed in 86.0.4240.198≥ unspecified, < 86.0.4240.1982021-01-08
CVE-2020-16017 [CRITICAL] CWE-416 CVE-2020-16017: Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker w
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-30563P1HIGHCVSS 8.8KEVfixed in 91.0.4472.164≥ unspecified, < 91.0.4472.1642021-08-03
CVE-2021-30563 [HIGH] CWE-843 CVE-2021-30563: Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21193P1HIGHCVSS 8.8KEVfixed in 89.0.4389.90≥ unspecified, < 89.0.4389.902021-03-16
CVE-2021-21193 [HIGH] CWE-416 CVE-2021-21193: Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentia
Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21206P1HIGHCVSS 8.8KEVfixed in 89.0.4389.128≥ unspecified, < 89.0.4389.1282021-04-26
CVE-2021-21206 [HIGH] CWE-416 CVE-2021-21206: Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potenti
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-16010P1CRITICALCVSS 9.6KEVfixed in 86.0.4240.185≥ unspecified, < 86.0.4240.1852020-11-03
CVE-2020-16010 [CRITICAL] CWE-787 CVE-2020-16010: Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attac
Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-4102P1HIGHCVSS 8.8KEVfixed in 96.0.4664.110≥ unspecified, < 96.0.4664.1102022-02-11
CVE-2021-4102 [HIGH] CWE-416 CVE-2021-4102: Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentiall
Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30554P1HIGHCVSS 8.8KEVfixed in 91.0.4472.114≥ unspecified, < 91.0.4472.1142021-07-02
CVE-2021-30554 [HIGH] CWE-416 CVE-2021-30554: Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potenti
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6572P1HIGHCVSS 8.8KEVfixed in 81.0.4044.92≥ unspecified, < 81.0.4044.922021-01-14
CVE-2020-6572 [HIGH] CWE-416 CVE-2020-6572: Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute
Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2020-16013P1HIGHCVSS 8.8KEVfixed in 86.0.4240.198≥ unspecified, < 86.0.4240.1982021-01-08
CVE-2020-16013 [HIGH] CWE-787 CVE-2020-16013: Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30533P2MEDIUMCVSS 6.5KEVfixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30533 [MEDIUM] CWE-863 CVE-2021-30533: Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a rem
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
nvd
CVE-2021-37976P2MEDIUMCVSS 6.5KEVfixed in 94.0.4606.71≥ unspecified, < 94.0.4606.712021-10-08
CVE-2021-37976 [MEDIUM] CWE-862 CVE-2021-37976: Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attac
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2022-2856P2MEDIUMCVSS 6.5KEVfixed in 104.0.5112.101fixed in 104.0.5112.102+1 more2022-09-26
CVE-2022-2856 [MEDIUM] CWE-20 CVE-2022-2856: Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.511
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
nvd
CVE-2021-38000P2MEDIUMCVSS 6.1KEVfixed in 95.0.4638.69≥ unspecified, < 95.0.4638.692021-11-23
CVE-2021-38000 [MEDIUM] CWE-601 CVE-2021-38000: Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
nvd
CVE-2020-16040P2MEDIUMCVSS 6.5ExploitedPoCfixed in 87.0.4280.88≥ unspecified, < 87.0.4280.882021-01-08
CVE-2020-16040 [MEDIUM] CWE-20 CVE-2020-16040: Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2025-4664P2MEDIUMCVSS 4.3ExploitedPoCfixed in 136.0.7103.113≥ 136.0.7103.113, < 136.0.7103.1132025-05-14
CVE-2025-4664 [MEDIUM] CVE-2025-4664: Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-2295P1HIGHCVSS 8.8ExploitedRansomwarefixed in 103.0.5060.114≥ unspecified, < 103.0.5060.1142022-07-28
CVE-2022-2295 [HIGH] CWE-843 CVE-2022-2295: Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15994P2HIGHCVSS 8.8Exploitedfixed in 86.0.4240.99≥ unspecified, < 86.0.4240.992020-11-03
CVE-2020-15994 [HIGH] CWE-416 CVE-2020-15994: Use after free in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially
Use after free in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5782P2HIGHCVSS 8.8Exploitedfixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5782 [HIGH] CWE-125 CVE-2019-5782: Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote att
Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd