Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 47 of 292
CVE-2026-15904P3HIGHCVSS 8.8fixed in 150.0.7871.128≥ 150.0.7871.128, < 150.0.7871.1282026-07-20
CVE-2026-15904 [HIGH] CWE-416 CVE-2026-15904: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker
Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11272P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11272 [HIGH] CWE-20 CVE-2026-11272: Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.78
Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11041P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11041 [HIGH] CWE-20 CVE-2026-11041: Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 149.0.7827.
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-12020P3HIGHCVSS 8.8fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12020 [HIGH] CWE-416 CVE-2026-12020: Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker
Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11079P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11079 [HIGH] CWE-20 CVE-2026-11079: Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory write via a crafted video file. (Chromium security severity: Medium)
nvd
CVE-2026-17786P3HIGHCVSS 8.8≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17786 [HIGH] CWE-20 CVE-2026-17786: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allow
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2026-11681P3HIGHCVSS 8.8fixed in 149.0.7827.102≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11681 [HIGH] CWE-416 CVE-2026-11681: Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker
Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-16423P3HIGHCVSS 8.8fixed in 150.0.7871.182≥ 150.0.7871.182, < 150.0.7871.1822026-07-21
CVE-2026-16423 [HIGH] CWE-416 CVE-2026-16423: Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convince
Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13027P3HIGHCVSS 8.8fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13027 [HIGH] CWE-416 CVE-2026-13027: Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to p
Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11304P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11304 [HIGH] CWE-416 CVE-2026-11304: Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potent
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low)
nvd
CVE-2026-10002P3HIGHCVSS 8.8fixed in 148.0.7778.215fixed in 148.0.7778.216+1 more2026-05-28
CVE-2026-10002 [HIGH] CWE-416 CVE-2026-10002: Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to poten
Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2026-17899P3HIGHCVSS 8.8≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17899 [HIGH] CWE-693 CVE-2026-17899: Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attac
Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2013-2931P3CRITICALCVSS 10.0≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-13
CVE-2013-2931 [CRITICAL] CVE-2013-2931: Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.48 allow attackers to execute
Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.48 allow attackers to execute arbitrary code or possibly have other impact via unknown vectors.
nvd
CVE-2011-1301P3CRITICALCVSS 9.3fixed in 10.0.648.2052011-04-15
CVE-2011-1301 [CRITICAL] CWE-416 CVE-2011-1301: Use-after-free vulnerability in the GPU process in Google Chrome before 10.0.648.205 allows remote a
Use-after-free vulnerability in the GPU process in Google Chrome before 10.0.648.205 allows remote attackers to execute arbitrary code via unknown vectors.
nvd
CVE-2016-5157P3HIGHCVSS 8.8≤ 52.0.2743.1162016-09-11
CVE-2016-5157 [HIGH] CWE-119 CVE-2016-5157: Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDF
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
nvd
CVE-2026-9964P3HIGHCVSS 8.1fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9964 [HIGH] CWE-416 CVE-2026-9964: Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who
Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2026-12012P3HIGHCVSS 8.1fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12012 [HIGH] CWE-416 CVE-2026-12012: Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileg
Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2020-16011P3CRITICALCVSS 9.6fixed in 86.0.4240.183≥ unspecified, < 86.0.4240.1832020-11-03
CVE-2020-16011 [CRITICAL] CWE-787 CVE-2020-16011: Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attac
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6573P3CRITICALCVSS 9.6fixed in 85.0.4183.102≥ unspecified, < 85.0.4183.1022020-09-21
CVE-2020-6573 [CRITICAL] CWE-416 CVE-2020-6573: Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6493P3CRITICALCVSS 9.6fixed in 83.0.4103.97≥ unspecified, < 83.0.4103.972020-06-03
CVE-2020-6493 [CRITICAL] CWE-416 CVE-2020-6493: Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker
Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd