cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 52 of 292
CVE-2026-7973P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7973 [HIGH] CWE-472 CVE-2026-7973: Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacke Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14040P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14040 [HIGH] CWE-416 CVE-2026-14040: Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinc Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2026-5912P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5912 [HIGH] CWE-472 CVE-2026-5912: Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perf Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11301P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11301 [HIGH] CWE-125 CVE-2026-11301: Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2026-11698P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11698 [HIGH] CWE-416 CVE-2026-11698: Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacke Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11687P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11687 [HIGH] CWE-416 CVE-2026-11687: Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11699P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11699 [HIGH] CWE-416 CVE-2026-11699: Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacke Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-15123P3HIGHCVSS 8.8fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15123 [HIGH] CWE-122 CVE-2026-15123: Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attack Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13026P3HIGHCVSS 8.8fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13026 [HIGH] CWE-416 CVE-2026-13026: Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remo Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4458P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4458 [HIGH] CWE-416 CVE-2026-4458: Use after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an attacker who convin Use after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2026-12035P3HIGHCVSS 8.8fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12035 [HIGH] CWE-416 CVE-2026-12035: Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacke Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10890P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10890 [HIGH] CWE-416 CVE-2026-10890: Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local netw Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)
nvd
CVE-2026-15110P3HIGHCVSS 8.8fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15110 [HIGH] CWE-416 CVE-2026-15110: Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convin Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2016-1629P3CRITICALCVSS 9.8≤ 48.0.2564.1092016-02-21
CVE-2016-1629 [CRITICAL] CWE-264 CVE-2016-1629: Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy an Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.
nvd
CVE-2026-17650P3HIGHCVSS 8.3≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17650 [HIGH] CWE-416 CVE-2026-17650: Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-17653P3HIGHCVSS 8.3≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17653 [HIGH] CWE-416 CVE-2026-17653: Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had com Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-17660P3HIGHCVSS 8.3≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17660 [HIGH] CWE-20 CVE-2026-17660: Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowe Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2017-15399P3HIGHCVSS 8.8fixed in 62.0.3202.892018-08-28
CVE-2017-15399 [HIGH] CWE-416 CVE-2017-15399: A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potential A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-11170P3HIGHCVSS 8.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11170 [HIGH] CWE-693 CVE-2026-11170: Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-7978P3HIGHCVSS 8.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7978 [HIGH] CWE-693 CVE-2026-7978: Inappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a r Inappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase