cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 50 of 292
CVE-2024-12693P3HIGHCVSS 8.8fixed in 131.0.6778.204≥ 131.0.6778.204, < 131.0.6778.2042024-12-18
CVE-2024-12693 [HIGH] CWE-787 CVE-2024-12693: Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5859P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5859 [HIGH] CWE-472 CVE-2026-5859: Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to poten Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13903P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13903 [HIGH] CWE-602 CVE-2026-13903: Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remot Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-13631P3HIGHCVSS 8.8fixed in 143.0.7499.40≥ 143.0.7499.41, < 143.0.7499.412025-12-02
CVE-2025-13631 [HIGH] CVE-2025-13631: Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowe Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. (Chromium security severity: High)
nvd
CVE-2026-9121P3HIGHCVSS 8.8fixed in 148.0.7778.178≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9121 [HIGH] CWE-125 CVE-2026-9121: Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to p Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13938P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13938 [HIGH] CWE-472 CVE-2026-13938: Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perfo Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13918P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13918 [HIGH] CWE-416 CVE-2026-13918: Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote att Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10897P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10897 [HIGH] CWE-787 CVE-2026-10897: Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacke Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13897P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13897 [HIGH] CWE-284 CVE-2026-13897: Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remo Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11042P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11042 [HIGH] CWE-416 CVE-2026-11042: Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convin Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7896P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7896 [HIGH] CWE-472 CVE-2026-7896: Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to poten Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-4459P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4459 [HIGH] CWE-125 CVE-2026-4459: Out of bounds read and write in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote a Out of bounds read and write in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-3936P3HIGHCVSS 8.8fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3936 [HIGH] CWE-416 CVE-2026-3936: Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attack Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7354P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7354 [HIGH] CWE-125 CVE-2026-7354: Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote atta Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13720P3HIGHCVSS 8.8fixed in 143.0.7499.40fixed in 143.0.7499.41+1 more2025-12-02
CVE-2025-13720 [HIGH] CWE-704 CVE-2025-13720: Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had comprom Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-16807P3HIGHCVSS 8.8fixed in 150.0.7871.186≥ 150.0.7871.186, < 150.0.7871.1862026-07-23
CVE-2026-16807 [HIGH] CWE-787 CVE-2026-16807: Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14041P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14041 [HIGH] CWE-602 CVE-2026-14041: Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote a Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11648P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11648 [HIGH] CWE-416 CVE-2026-11648: Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote at Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7361P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7361 [HIGH] CWE-416 CVE-2026-7361: Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentia Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-3541P3HIGHCVSS 8.8fixed in 145.0.7632.159fixed in 145.0.7632.160+1 more2026-03-04
CVE-2026-3541 [HIGH] CWE-284 CVE-2026-3541: Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attack Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase