Google Chrome vulnerabilities
3,975 known vulnerabilities affecting google/chrome.
Total CVEs
3,975
CISA KEV
74
actively exploited
Public exploits
63
Exploited in wild
65
Severity breakdown
CRITICAL297HIGH2024MEDIUM1626LOW17UNKNOWN11
Vulnerabilities
Page 42 of 199
CVE-2023-2311MEDIUMCVSS 6.5fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-07-29
CVE-2023-2311 [MEDIUM] CVE-2023-2311: Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a
Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4922MEDIUMCVSS 6.5fixed in 99.0.4844.51≥ 99.0.4844.51, < 99.0.4844.512023-07-29
CVE-2022-4922 [MEDIUM] CVE-2022-4922: Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attack
Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4913MEDIUMCVSS 6.5fixed in 105.0.5195.52≥ 105.0.5195.52, < 105.0.5195.522023-07-29
CVE-2022-4913 [MEDIUM] CVE-2022-4913: Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote
Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to spoof extension storage via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4915MEDIUMCVSS 6.5fixed in 103.0.5060.134≥ 103.0.5060.134, < 103.0.5060.1342023-07-29
CVE-2022-4915 [MEDIUM] CVE-2022-4915: Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a re
Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4926MEDIUMCVSS 6.5fixed in 109.0.5414.119≥ 109.0.5414.119, < 109.0.5414.1192023-07-29
CVE-2022-4926 [MEDIUM] CWE-522 CVE-2022-4926: Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allow
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4909MEDIUMCVSS 6.3fixed in 107.0.5304.62≥ 107.0.5304.62, < 107.0.5304.622023-07-29
CVE-2022-4909 [MEDIUM] CVE-2022-4909: Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacke
Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially perform an ASLR bypass via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-4908MEDIUMCVSS 4.3fixed in 107.0.5304.62≥ 107.0.5304.62, < 107.0.5304.622023-07-29
CVE-2022-4908 [MEDIUM] CVE-2022-4908: Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a rem
Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-4323MEDIUMCVSS 6.5fixed in 90.0.4430.72≥ 90.0.4430.72, < 90.0.4430.722023-07-29
CVE-2021-4323 [MEDIUM] CVE-2021-4323: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allo
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to access local files via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2021-4324MEDIUMCVSS 6.5fixed in 90.0.4430.93≥ 90.0.4430.93, < 90.0.4430.932023-07-29
CVE-2021-4324 [MEDIUM] CVE-2021-4324: Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a re
Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to read arbitrary files via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2022-4911MEDIUMCVSS 6.5fixed in 106.0.5249.62≥ 106.0.5249.62, < 106.0.5249.622023-07-29
CVE-2022-4911 [MEDIUM] CWE-20 CVE-2022-4911: Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote at
Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2021-4321MEDIUMCVSS 4.3fixed in 91.0.4472.77≥ 91.0.4472.77, < 91.0.4472.772023-07-29
CVE-2021-4321 [MEDIUM] CVE-2021-4321: Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass co
Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-4917MEDIUMCVSS 4.3fixed in 103.0.5060.53≥ 103.0.5060.53, < 103.0.5060.532023-07-29
CVE-2022-4917 [MEDIUM] CWE-346 CVE-2022-4917: Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a
Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-4923LOWCVSS 3.1fixed in 99.0.4844.51≥ 99.0.4844.51, < 99.0.4844.512023-07-29
CVE-2022-4923 [LOW] CVE-2022-4923: Inappropriate implementation in Omnibox in Google Chrome prior to 99.0.4844.51 allowed an attacker i
Inappropriate implementation in Omnibox in Google Chrome prior to 99.0.4844.51 allowed an attacker in a privileged network position to perform a man-in-the-middle attack via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2023-3598HIGHCVSS 8.8fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-07-28
CVE-2023-3598 [HIGH] CWE-787 CVE-2023-3598: Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attac
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3497MEDIUMCVSS 4.6fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-07-03
CVE-2023-3497 [MEDIUM] CWE-125 CVE-2023-3497: Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.
Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of service via physical access to the device. (Chromium security severity: Medium)
nvd
CVE-2023-3421HIGHCVSS 8.8fixed in 114.0.5735.198≥ 114.0.5735.198, < 114.0.5735.1982023-06-26
CVE-2023-3421 [HIGH] CWE-416 CVE-2023-3421: Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potent
Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3420HIGHCVSS 8.8fixed in 114.0.5735.198≥ 114.0.5735.198, < 114.0.5735.1982023-06-26
CVE-2023-3420 [HIGH] CWE-843 CVE-2023-3420: Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potential
Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3422HIGHCVSS 8.8fixed in 114.0.5735.198≥ 114.0.5735.198, < 114.0.5735.1982023-06-26
CVE-2023-3422 [HIGH] CWE-416 CVE-2023-3422: Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convin
Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3216HIGHCVSS 8.8fixed in 114.0.5735.133≥ 114.0.5735.133, < 114.0.5735.1332023-06-13
CVE-2023-3216 [HIGH] CWE-843 CVE-2023-3216: Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3217HIGHCVSS 8.8fixed in 114.0.5735.133≥ 114.0.5735.133, < 114.0.5735.1332023-06-13
CVE-2023-3217 [HIGH] CWE-416 CVE-2023-3217: Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potent
Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd