cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 43 of 292
CVE-2026-4679P3HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4679 [HIGH] CWE-472 CVE-2026-4679: Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perf Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14385P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14385 [HIGH] CWE-122 CVE-2026-14385: Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attack Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-15112P3HIGHCVSS 8.8fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15112 [HIGH] CWE-416 CVE-2026-15112: Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potent Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13915P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13915 [HIGH] CWE-416 CVE-2026-13915: Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote att Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13928P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13928 [HIGH] CWE-20 CVE-2026-13928: Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 all Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13835P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13835 [HIGH] CWE-122 CVE-2026-13835: Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacke Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13817P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13817 [HIGH] CWE-20 CVE-2026-13817: Insufficient validation of untrusted input in Glic in Google Chrome prior to 150.0.7871.47 allowed a Insufficient validation of untrusted input in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10907P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10907 [HIGH] CWE-787 CVE-2026-10907: Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to po Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10989P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10989 [HIGH] CWE-122 CVE-2026-10989: Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10891P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10891 [HIGH] CWE-416 CVE-2026-10891: Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10988P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10988 [HIGH] CWE-416 CVE-2026-10988: Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had co Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13783P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13783 [HIGH] CWE-416 CVE-2026-13783: Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convin Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13784P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13784 [HIGH] CWE-416 CVE-2026-13784: Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convin Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-0900P3HIGHCVSS 8.8fixed in 144.0.7559.59fixed in 144.0.7559.60+1 more2026-01-20
CVE-2026-0900 [HIGH] CVE-2026-0900: Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14025P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14025 [HIGH] CWE-416 CVE-2026-14025: Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-4441P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4441 [HIGH] CWE-416 CVE-2026-4441: Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potenti Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-0908P3HIGHCVSS 8.8fixed in 144.0.7559.59fixed in 144.0.7559.60+1 more2026-01-20
CVE-2026-0908 [HIGH] CWE-416 CVE-2026-0908: Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potenti Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-10952P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10952 [HIGH] CWE-416 CVE-2026-10952: Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote att Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10951P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10951 [HIGH] CWE-416 CVE-2026-10951: Use after free in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker Use after free in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10932P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10932 [HIGH] CWE-416 CVE-2026-10932: Use after free in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to Use after free in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase