cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 51 of 292
CVE-2025-13042P3HIGHCVSS 8.8fixed in 142.0.7444.162≥ 142.0.7444.166, < 142.0.7444.1662025-11-12
CVE-2025-13042 [HIGH] CWE-787 CVE-2025-13042: Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacke Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-12727P3HIGHCVSS 8.8fixed in 142.0.7444.134fixed in 142.0.7444.135+1 more2025-11-10
CVE-2025-12727 [HIGH] CWE-787 CVE-2025-12727: Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacke Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-10500P3HIGHCVSS 8.8fixed in 140.0.7339.185≥ 140.0.7339.185, < 140.0.7339.1852025-09-24
CVE-2025-10500 [HIGH] CWE-416 CVE-2025-10500: Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6360P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6360 [HIGH] CWE-416 CVE-2026-6360: Use after free in FileSystem in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to p Use after free in FileSystem in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4464P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4464 [HIGH] CWE-472 CVE-2026-4464: Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to pote Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-4452P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4452 [HIGH] CWE-472 CVE-2026-4452: Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 allowed a remote attac Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4451P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4451 [HIGH] CWE-20 CVE-2026-4451: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 al Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13638P3HIGHCVSS 8.8fixed in 143.0.7499.40≥ 143.0.7499.41, < 143.0.7499.412025-12-02
CVE-2025-13638 [HIGH] CWE-416 CVE-2025-13638: Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14102P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14102 [HIGH] CWE-416 CVE-2026-14102: Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to pot Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11630P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11630 [HIGH] CWE-416 CVE-2026-11630: Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-2321P3HIGHCVSS 8.8fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2321 [HIGH] CWE-416 CVE-2026-2321: Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convin Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-12438P3HIGHCVSS 8.8fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12438 [HIGH] CWE-416 CVE-2025-12438: Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remo Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14005P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14005 [HIGH] CWE-416 CVE-2026-14005: Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attack Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9965P3HIGHCVSS 8.8fixed in 148.0.7778.215fixed in 148.0.7778.216+1 more2026-05-28
CVE-2026-9965 [HIGH] CWE-787 CVE-2026-9965: Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to p Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14394P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14394 [HIGH] CWE-416 CVE-2026-14394: Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentiall Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11177P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11177 [HIGH] CWE-416 CVE-2026-11177: Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who conv Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11080P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11080 [HIGH] CWE-416 CVE-2026-11080: Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attack Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8519P3HIGHCVSS 8.8fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8519 [HIGH] CWE-472 CVE-2026-8519: Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attac Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2025-12432P3HIGHCVSS 8.8fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12432 [HIGH] CWE-362 CVE-2025-12432: Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-3926P3HIGHCVSS 8.8fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3926 [HIGH] CWE-125 CVE-2026-3926: Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perfor Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase