Google Chrome vulnerabilities

3,975 known vulnerabilities affecting google/chrome.

Total CVEs
3,975
CISA KEV
74
actively exploited
Public exploits
63
Exploited in wild
65
Severity breakdown
CRITICAL297HIGH2024MEDIUM1626LOW17UNKNOWN11

Vulnerabilities

Page 46 of 199
CVE-2023-1534HIGHCVSS 8.8fixed in 111.0.5563.110≥ 111.0.5563.110, < 111.0.5563.1102023-03-21
CVE-2023-1534 [HIGH] CWE-125 CVE-2023-1534: Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who h Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-1227HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1227 [HIGH] CWE-416 CVE-2023-1227: Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker w Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)
nvd
CVE-2023-1222HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1222 [HIGH] CWE-787 CVE-2023-1222: Heap buffer overflow in Web Audio API in Google Chrome prior to 111.0.5563.64 allowed a remote attac Heap buffer overflow in Web Audio API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1219HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1219 [HIGH] CWE-787 CVE-2023-1219: Heap buffer overflow in Metrics in Google Chrome prior to 111.0.5563.64 allowed a remote attacker wh Heap buffer overflow in Metrics in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-1215HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1215 [HIGH] CWE-843 CVE-2023-1215: Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potential Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-1218HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1218 [HIGH] CWE-416 CVE-2023-1218: Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potent Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-1214HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1214 [HIGH] CWE-843 CVE-2023-1214: Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-1213HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1213 [HIGH] CWE-416 CVE-2023-1213: Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to p Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-1216HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1216 [HIGH] CWE-416 CVE-2023-1216: Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-1220HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1220 [HIGH] CWE-787 CVE-2023-1220: Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who ha Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-1231MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1231 [MEDIUM] CVE-2023-1231: Inappropriate implementation in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed Inappropriate implementation in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to potentially spoof the contents of the omnibox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1234MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1234 [MEDIUM] CVE-2023-1234: Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-1221MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1221 [MEDIUM] CVE-2023-1221: Insufficient policy enforcement in Extensions API in Google Chrome prior to 111.0.5563.64 allowed an Insufficient policy enforcement in Extensions API in Google Chrome prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2023-1225MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1225 [MEDIUM] CVE-2023-1225: Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 111.0.5563.64 allowed Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 111.0.5563.64 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1224MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1224 [MEDIUM] CVE-2023-1224: Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1236MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1236 [MEDIUM] CVE-2023-1236: Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote a Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-1226MEDIUMCVSS 6.5fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1226 [MEDIUM] CVE-2023-1226: Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1223MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1223 [MEDIUM] CVE-2023-1223: Insufficient policy enforcement in Autofill in Google Chrome on Android prior to 111.0.5563.64 allow Insufficient policy enforcement in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1233MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1233 [MEDIUM] CVE-2023-1233: Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from API via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2023-1229MEDIUMCVSS 4.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1229 [MEDIUM] CWE-276 CVE-2023-1229: Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd