Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 49 of 292
CVE-2023-4860P3CRITICALCVSS 9.6fixed in 115.0.5790.98≥ 115.0.5790.98, < 115.0.5790.982024-07-16
CVE-2023-4860 [CRITICAL] CWE-303 CVE-2023-4860: Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attack
Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2019-13726P3HIGHCVSS 8.8fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13726 [HIGH] CWE-119 CVE-2019-13726: Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker
Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2021-30588P3HIGHCVSS 8.8fixed in 92.0.4515.107≥ unspecified, < 92.0.4515.1072021-08-03
CVE-2021-30588 [HIGH] CWE-843 CVE-2021-30588: Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentiall
Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13725P3HIGHCVSS 8.8fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13725 [HIGH] CWE-416 CVE-2019-13725: Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to exec
Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2019-13735P3HIGHCVSS 8.8fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13735 [HIGH] CWE-787 CVE-2019-13735: Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker t
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2011-3046P3CRITICALCVSS 10.0fixed in 17.0.963.782012-03-09
CVE-2011-3046 [CRITICAL] CWE-79 CVE-2011-3046: The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigat
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
nvd
CVE-2023-4354P3HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4354 [HIGH] CWE-787 CVE-2023-4354: Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who h
Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2012-2764P4HIGHCVSS 7.2PoC≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2764 [HIGH] CVE-2012-2764: Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow loca
Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory.
nvd
CVE-2023-5857P3HIGHCVSS 8.8fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5857 [HIGH] CVE-2023-5857: Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially execute arbitrary code via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2024-2176P3HIGHCVSS 8.8fixed in 122.0.6261.111≥ 122.0.6261.111, < 122.0.6261.1112024-03-06
CVE-2024-2176 [HIGH] CWE-416 CVE-2024-2176: Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potent
Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5472P3HIGHCVSS 8.8fixed in 118.0.5993.117≥ 118.0.5993.117, < 118.0.5993.1172023-10-25
CVE-2023-5472 [HIGH] CWE-416 CVE-2023-5472: Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to pot
Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2885P3HIGHCVSS 8.8fixed in 123.0.6312.86≥ 123.0.6312.86, < 123.0.6312.862024-03-26
CVE-2024-2885 [HIGH] CWE-416 CVE-2024-2885: Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentia
Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6100P3HIGHCVSS 8.8fixed in 126.0.6478.114≥ 126.0.6478.114, < 126.0.6478.1142024-06-20
CVE-2024-6100 [HIGH] CWE-843 CVE-2024-6100: Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute a
Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13872P3CRITICALCVSS 9.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13872 [CRITICAL] CWE-20 CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 15
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2014-3177P3CRITICALCVSS 10.0≤ 37.0.2062.93v37.0.2062.0+80 more2014-08-27
CVE-2014-3177 [CRITICAL] CVE-2014-3177: Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the s
Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3176.
nvd
CVE-2025-10200P3HIGHCVSS 8.8fixed in 140.0.7339.127≥ 140.0.7339.127, < 140.0.7339.1272025-09-10
CVE-2025-10200 [HIGH] CWE-416 CVE-2025-10200: Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote
Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2025-7657P3HIGHCVSS 8.8fixed in 138.0.7204.157≥ 138.0.7204.157, < 138.0.7204.1572025-07-15
CVE-2025-7657 [HIGH] CWE-416 CVE-2025-7657: Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to poten
Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-6192P3HIGHCVSS 8.8fixed in 137.0.7151.119≥ 137.0.7151.119, < 137.0.7151.1192025-06-18
CVE-2025-6192 [HIGH] CWE-416 CVE-2025-6192: Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to pote
Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-3172P3HIGHCVSS 8.8fixed in 121.0.6167.85≥ 121.0.6167.85, < 121.0.6167.852024-07-16
CVE-2024-3172 [HIGH] CWE-20 CVE-2024-3172: Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote at
Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-9965P3HIGHCVSS 8.8fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9965 [HIGH] CVE-2024-9965: Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed
Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
nvd