Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 53 of 292
CVE-2018-16068P3CRITICALCVSS 9.6fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16068 [CRITICAL] CWE-20 CVE-2018-16068: Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to poten
Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2018-18335P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18335 [HIGH] CWE-787 CVE-2018-18335: Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to pot
Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6466P3CRITICALCVSS 9.6fixed in 83.0.4103.61≥ unspecified, < 83.0.4103.612020-05-21
CVE-2020-6466 [CRITICAL] CWE-416 CVE-2020-6466: Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had com
Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6424P3HIGHCVSS 8.8fixed in 80.0.3987.149≥ unspecified, < 80.0.3987.1492020-03-23
CVE-2020-6424 [HIGH] CWE-416 CVE-2020-6424: Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potenti
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21223P3CRITICALCVSS 9.6fixed in 90.0.4430.85≥ unspecified, < 90.0.4430.852021-04-26
CVE-2021-21223 [CRITICAL] CWE-190 CVE-2021-21223: Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had co
Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21154P3CRITICALCVSS 9.6fixed in 88.0.4324.182≥ unspecified, < 88.0.4324.1822021-02-22
CVE-2021-21154 [CRITICAL] CWE-787 CVE-2021-21154: Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker
Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21115P3CRITICALCVSS 9.6fixed in 87.0.4280.141≥ unspecified, < 87.0.4280.1412021-01-08
CVE-2021-21115 [CRITICAL] CWE-416 CVE-2021-21115: User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker w
User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2018-6086P3HIGHCVSS 8.8fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172018-12-04
CVE-2018-6086 [HIGH] CWE-416 CVE-2018-6086: A double-eviction in the Incognito mode cache that lead to a user-after-free in Networking Disk Cach
A double-eviction in the Incognito mode cache that lead to a user-after-free in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2021-21155P3CRITICALCVSS 9.6fixed in 88.0.4324.182≥ unspecified, < 88.0.4324.1822021-02-22
CVE-2021-21155 [CRITICAL] CWE-787 CVE-2021-21155: Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remot
Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2018-6174P3HIGHCVSS 8.8fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6174 [HIGH] CWE-190 CVE-2018-6174: Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote
Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2021-21150P3CRITICALCVSS 9.6fixed in 88.0.4324.182≥ unspecified, < 88.0.4324.1822021-02-22
CVE-2021-21150 [CRITICAL] CWE-416 CVE-2021-21150: Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote atta
Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21151P3CRITICALCVSS 9.6fixed in 88.0.4324.182≥ unspecified, < 88.0.4324.1822021-02-22
CVE-2021-21151 [CRITICAL] CWE-416 CVE-2021-21151: Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to pote
Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21146P3CRITICALCVSS 9.6fixed in 88.0.4324.146≥ unspecified, < 88.0.4324.1462021-02-09
CVE-2021-21146 [CRITICAL] CWE-416 CVE-2021-21146: Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who h
Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2026-17896P3HIGHCVSS 7.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17896 [HIGH] CWE-416 CVE-2026-17896: Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to exec
Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-38002P3CRITICALCVSS 9.6fixed in 95.0.4638.69≥ unspecified, < 95.0.4638.692021-11-23
CVE-2021-38002 [CRITICAL] CWE-416 CVE-2021-38002: Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to
Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2022-0790P3CRITICALCVSS 9.6fixed in 99.0.4844.51≥ unspecified, < 99.0.4844.512022-04-05
CVE-2022-0790 [CRITICAL] CWE-416 CVE-2022-0790: Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convi
Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6463P3HIGHCVSS 8.8fixed in 81.0.4044.122≥ unspecified, < 81.0.4044.1222020-05-21
CVE-2020-6463 [HIGH] CWE-416 CVE-2020-6463: Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potenti
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6524P3HIGHCVSS 8.8fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6524 [HIGH] CWE-787 CVE-2020-6524: Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0452P3CRITICALCVSS 9.6fixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802022-04-05
CVE-2022-0452 [CRITICAL] CWE-416 CVE-2022-0452: Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to
Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21156P3HIGHCVSS 8.8fixed in 88.0.4324.182≥ unspecified, < 88.0.4324.1822021-02-22
CVE-2021-21156 [HIGH] CWE-787 CVE-2021-21156: Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to pote
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.
nvd