cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 44 of 292
CVE-2026-15129P3HIGHCVSS 8.8fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15129 [HIGH] CWE-416 CVE-2026-15129: Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potent Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-14087P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14087 [HIGH] CWE-20 CVE-2026-14087: Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote at Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-3543P3HIGHCVSS 8.8fixed in 145.0.7632.159fixed in 145.0.7632.160+1 more2026-03-04
CVE-2026-3543 [HIGH] CWE-284 CVE-2026-3543: Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacke Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7334P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7334 [HIGH] CWE-416 CVE-2026-7334: Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4450P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4450 [HIGH] CWE-787 CVE-2026-4450: Out of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to pote Out of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4461P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4461 [HIGH] CVE-2026-4461: Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacke Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14422P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14422 [HIGH] CWE-125 CVE-2026-14422: Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attack Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11191P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11191 [HIGH] CWE-125 CVE-2026-11191: Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attack Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-4442P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4442 [HIGH] CWE-122 CVE-2026-4442: Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to po Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4448P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4448 [HIGH] CWE-122 CVE-2026-4448: Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11629P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11629 [HIGH] CWE-416 CVE-2026-11629: Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potent Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2025-10501P3HIGHCVSS 8.8fixed in 140.0.7339.185≥ 140.0.7339.185, < 140.0.7339.1852025-09-24
CVE-2025-10501 [HIGH] CWE-416 CVE-2025-10501: Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to poten Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6358P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6358 [HIGH] CWE-416 CVE-2026-6358: Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker t Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-7359P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7359 [HIGH] CWE-416 CVE-2026-7359: Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had c Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-16807P3HIGHCVSS 8.8fixed in 150.0.7871.186≥ 150.0.7871.186, < 150.0.7871.1862026-07-23
CVE-2026-16807 [HIGH] CWE-787 CVE-2026-16807: Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14027P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14027 [HIGH] CWE-416 CVE-2026-14027: Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convi Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14078P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14078 [HIGH] CWE-20 CVE-2026-14078: Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-7339P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7339 [HIGH] CWE-122 CVE-2026-7339: Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9940P3HIGHCVSS 8.8fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9940 [HIGH] CWE-122 CVE-2026-9940: Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8531P3HIGHCVSS 8.8fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8531 [HIGH] CWE-122 CVE-2026-8531: Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote a Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase