Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82
Vulnerabilities
Page 42 of 292
CVE-2026-6920P3CRITICALCVSS 9.6fixed in 147.0.7727.116≥ 147.0.7727.117, < 147.0.7727.1172026-04-23
CVE-2026-6920 [CRITICAL] CWE-125 CVE-2026-6920: Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attac
Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-16419P3CRITICALCVSS 9.6fixed in 150.0.7871.182≥ 150.0.7871.182, < 150.0.7871.1822026-07-21
CVE-2026-16419 [CRITICAL] CWE-125 CVE-2026-16419: Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a
Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3199P3HIGHCVSS 8.8fixed in 105.0.5195.125≥ unspecified, < 105.0.5195.1252022-09-26
CVE-2022-3199 [HIGH] CWE-416 CVE-2022-3199: Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to poten
Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2018-6139P3HIGHCVSS 8.8fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6139 [HIGH] CWE-20 CVE-2018-6139: Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.339
Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
nvd
CVE-2024-4331P3HIGHCVSS 8.8fixed in 124.0.6367.118≥ 124.0.6367.118, < 124.0.6367.1182024-05-01
CVE-2024-4331 [HIGH] CWE-416 CVE-2024-4331: Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attac
Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2013-6627P4MEDIUMCVSS 5.0PoC≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-13
CVE-2013-6627 [MEDIUM] CWE-119 CVE-2013-6627: net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP I
net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status codes, which allows remote web servers to cause a denial of service (out-of-bounds read) via a crafted response.
nvd
CVE-2024-5496P3HIGHCVSS 8.8fixed in 125.0.6422.141≥ 125.0.6422.141, < 125.0.6422.1412024-05-30
CVE-2024-5496 [HIGH] CWE-416 CVE-2024-5496: Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker t
Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5157P3HIGHCVSS 8.8fixed in 125.0.6422.76≥ 125.0.6422.76, < 125.0.6422.762024-05-22
CVE-2024-5157 [HIGH] CWE-416 CVE-2024-5157: Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to ex
Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7256P3HIGHCVSS 8.8fixed in 127.0.6533.88≥ 127.0.6533.88, < 127.0.6533.882024-08-01
CVE-2024-7256 [HIGH] CWE-345 CVE-2024-7256: Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a re
Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5836P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5836 [HIGH] CWE-474 CVE-2024-5836: Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker
Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2026-4677P3HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4677 [HIGH] CWE-125 CVE-2026-4677: Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote a
Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4675P3HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4675 [HIGH] CWE-122 CVE-2026-4675: Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to
Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-12695P3HIGHCVSS 8.8fixed in 131.0.6778.204≥ 131.0.6778.204, < 131.0.6778.2042024-12-18
CVE-2024-12695 [HIGH] CWE-787 CVE-2024-12695: Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to exec
Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10955P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10955 [HIGH] CWE-843 CVE-2026-10955: Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker
Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-3915P3HIGHCVSS 8.8fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3915 [HIGH] CWE-122 CVE-2026-3915: Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to p
Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-3537P3HIGHCVSS 8.8fixed in 145.0.7632.159≥ 145.0.7632.159, < 145.0.7632.1592026-03-04
CVE-2026-3537 [HIGH] CWE-787 CVE-2026-3537: Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remo
Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-4676P3HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4676 [HIGH] CWE-416 CVE-2026-4676: Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potenti
Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10995P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10995 [HIGH] CWE-122 CVE-2026-10995: Heap buffer overflow in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker w
Heap buffer overflow in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-3914P3HIGHCVSS 8.8fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3914 [HIGH] CWE-472 CVE-2026-3914: Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to poten
Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4439P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4439 [HIGH] CWE-125 CVE-2026-4439: Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a r
Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd