cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 45 of 292
CVE-2026-14099P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14099 [HIGH] CWE-416 CVE-2026-14099: Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote att Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14415P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14415 [HIGH] CWE-122 CVE-2026-14415: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14009P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14009 [HIGH] CWE-20 CVE-2026-14009: Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote a Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9923P3HIGHCVSS 8.8fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9923 [HIGH] CWE-416 CVE-2026-9923: Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potenti Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4445P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4445 [HIGH] CWE-416 CVE-2026-4445: Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to poten Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4456P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4456 [HIGH] CWE-416 CVE-2026-4456: Use after free in Digital Credentials API in Google Chrome prior to 146.0.7680.153 allowed a remote Use after free in Digital Credentials API in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4449P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4449 [HIGH] CWE-416 CVE-2026-4449: Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potent Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11664P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11664 [HIGH] CWE-416 CVE-2026-11664: Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to pot Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6359P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6359 [HIGH] CWE-416 CVE-2026-6359: Use after free in Video in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacke Use after free in Video in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4455P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4455 [HIGH] CWE-122 CVE-2026-4455: Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2026-11091P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11091 [HIGH] CWE-125 CVE-2026-11091: Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attack Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7344P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7344 [HIGH] CWE-416 CVE-2026-7344: Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2025-13228P3HIGHCVSS 8.8fixed in 142.0.7444.59fixed in 142.0.7444.60+1 more2025-11-18
CVE-2025-13228 [HIGH] CWE-843 CVE-2025-13228: Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13230P3HIGHCVSS 8.8fixed in 142.0.7444.59fixed in 142.0.7444.60+1 more2025-11-18
CVE-2025-13230 [HIGH] CWE-843 CVE-2025-13230: Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13226P3HIGHCVSS 8.8fixed in 142.0.7444.59fixed in 142.0.7444.60+1 more2025-11-18
CVE-2025-13226 [HIGH] CWE-843 CVE-2025-13226: Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13229P3HIGHCVSS 8.8fixed in 142.0.7444.59fixed in 142.0.7444.60+1 more2025-11-18
CVE-2025-13229 [HIGH] CWE-843 CVE-2025-13229: Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13227P3HIGHCVSS 8.8fixed in 142.0.7444.59fixed in 142.0.7444.60+1 more2025-11-18
CVE-2025-13227 [HIGH] CWE-843 CVE-2025-13227: Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9961P3HIGHCVSS 8.8fixed in 148.0.7778.215fixed in 148.0.7778.216+1 more2026-05-28
CVE-2026-9961 [HIGH] CWE-416 CVE-2026-9961: Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 allowed a remote attacker Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14084P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14084 [HIGH] CWE-20 CVE-2026-14084: Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 all Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2026-15904P3HIGHCVSS 8.8fixed in 150.0.7871.128≥ 150.0.7871.128, < 150.0.7871.1282026-07-20
CVE-2026-15904 [HIGH] CWE-416 CVE-2026-15904: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase