Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82
Vulnerabilities
Page 41 of 292
CVE-2017-5112P3HIGHCVSS 8.8fixed in 61.0.3163.792017-10-27
CVE-2017-5112 [HIGH] CWE-119 CVE-2017-5112: Heap buffer overflow in WebGL in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote at
Heap buffer overflow in WebGL in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2021-21215P3MEDIUMCVSS 6.5fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21215 [MEDIUM] CWE-290 CVE-2021-21215: Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote att
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2026-13799P3HIGHCVSS 8.1fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13799 [HIGH] CWE-416 CVE-2026-13799: Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentia
Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2026-14032P3HIGHCVSS 8.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14032 [HIGH] CWE-416 CVE-2026-14032: Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed an attacker who c
Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2019-13734P3HIGHCVSS 8.8fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13734 [HIGH] CWE-787 CVE-2019-13734: Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to po
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2011-2841P4MEDIUMCVSS 6.8PoCfixed in 14.0.835.1632011-09-19
CVE-2011-2841 [MEDIUM] CWE-20 CVE-2011-2841: Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing
Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2018-6085P3HIGHCVSS 8.8fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172018-12-04
CVE-2018-6085 [HIGH] CWE-416 CVE-2018-6085: Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a
Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2012-5108P3CRITICALCVSS 9.3≤ 22.0.1229.91v22.0.1229.0+54 more2012-10-09
CVE-2012-5108 [CRITICAL] CWE-362 CVE-2012-5108: Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary cod
Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary code via vectors related to audio devices.
nvd
CVE-2026-0905P3CRITICALCVSS 9.8fixed in 144.0.7559.59fixed in 144.0.7559.60+1 more2026-01-20
CVE-2026-0905 [CRITICAL] CWE-200 CVE-2026-0905: Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack
Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)
nvd
CVE-2020-6402P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6402 [HIGH] CWE-20 CVE-2020-6402: Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
nvd
CVE-2024-9369P3CRITICALCVSS 9.6fixed in 129.0.6668.89≥ 129.0.6668.89, < 129.0.6668.892024-11-27
CVE-2024-9369 [CRITICAL] CWE-1284 CVE-2024-9369: Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attack
Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11037P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11037 [CRITICAL] CWE-787 CVE-2026-11037: Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to p
Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
nvd
CVE-2026-14416P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14416 [CRITICAL] CWE-125 CVE-2026-14416: Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to pote
Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-9967P3CRITICALCVSS 9.6fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9967 [CRITICAL] CWE-787 CVE-2026-9967: Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to pot
Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11119P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11119 [CRITICAL] CWE-20 CVE-2026-11119: Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a rem
Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11167P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11167 [CRITICAL] CWE-250 CVE-2026-11167: Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11082P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11082 [CRITICAL] CWE-416 CVE-2026-11082: Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had com
Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11029P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11029 [CRITICAL] CWE-20 CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149
Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11112P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11112 [CRITICAL] CWE-20 CVE-2026-11112: Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.78
Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2026-11207P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11207 [CRITICAL] CWE-20 CVE-2026-11207: Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allow
Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)
nvd