Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 56 of 292
CVE-2024-0224P3HIGHCVSS 8.8fixed in 120.0.6099.199≥ 120.0.6099.199, < 120.0.6099.1992024-01-04
CVE-2024-0224 [HIGH] CWE-416 CVE-2024-0224: Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to pot
Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5997P3HIGHCVSS 8.8fixed in 119.0.6045.159≥ 119.0.6045.159, < 119.0.6045.1592023-11-15
CVE-2023-5997 [HIGH] CWE-416 CVE-2023-5997: Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 allowed a remote attac
Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6346P3HIGHCVSS 8.8fixed in 119.0.6045.199≥ 119.0.6045.199, < 119.0.6045.1992023-11-29
CVE-2023-6346 [HIGH] CWE-416 CVE-2023-6346: Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to pot
Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-1669P3HIGHCVSS 8.8fixed in 122.0.6261.57≥ 122.0.6261.57, < 122.0.6261.572024-02-21
CVE-2024-1669 [HIGH] CWE-787 CVE-2024-1669: Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attack
Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-3837P3HIGHCVSS 8.8fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3837 [HIGH] CWE-416 CVE-2024-3837: Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had com
Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-0518P3HIGHCVSS 8.8fixed in 120.0.6099.224≥ 120.0.6099.224, < 120.0.6099.2242024-01-16
CVE-2024-0518 [HIGH] CWE-843 CVE-2024-0518: Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6351P3HIGHCVSS 8.8fixed in 119.0.6045.199≥ 119.0.6045.199, < 119.0.6045.1992023-11-29
CVE-2023-6351 [HIGH] CWE-416 CVE-2023-6351: Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to pote
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
nvd
CVE-2024-1060P3HIGHCVSS 8.8fixed in 121.0.6167.139≥ 121.0.6167.139, < 121.0.6167.1392024-01-30
CVE-2024-1060 [HIGH] CWE-416 CVE-2024-1060: Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to poten
Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-12053P3HIGHCVSS 8.8fixed in 131.0.6778.108≥ 131.0.6778.108, < 131.0.6778.1082024-12-03
CVE-2024-12053 [HIGH] CWE-843 CVE-2024-12053: Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potential
Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-2476P3HIGHCVSS 8.8fixed in 134.0.6998.117≥ 134.0.6998.117, < 134.0.6998.1172025-03-19
CVE-2025-2476 [HIGH] CWE-416 CVE-2025-2476: Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potenti
Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2024-7532P3HIGHCVSS 8.8fixed in 127.0.6533.99≥ 127.0.6533.99, < 127.0.6533.992024-08-06
CVE-2024-7532 [HIGH] CWE-787 CVE-2024-7532: Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 allowed a remote attack
Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2024-6101P3HIGHCVSS 8.8fixed in 126.0.6478.114≥ 126.0.6478.114, < 126.0.6478.1142024-06-20
CVE-2024-6101 [HIGH] CWE-358 CVE-2024-6101: Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacke
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2627P3HIGHCVSS 8.8fixed in 123.0.6312.58≥ 123.0.6312.58, < 123.0.6312.582024-03-20
CVE-2024-2627 [HIGH] CWE-416 CVE-2024-2627: Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potent
Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-3158P3HIGHCVSS 8.8fixed in 123.0.6312.105≥ 123.0.6312.105, < 123.0.6312.1052024-04-06
CVE-2024-3158 [HIGH] CWE-416 CVE-2024-3158: Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to po
Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-9955P3HIGHCVSS 8.8fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9955 [HIGH] CWE-416 CVE-2024-9955: Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacke
Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-5497P3HIGHCVSS 8.8fixed in 125.0.6422.141≥ 125.0.6422.141, < 125.0.6422.1412024-05-30
CVE-2024-5497 [HIGH] CWE-787 CVE-2024-5497: Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote
Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2400P3HIGHCVSS 8.8fixed in 122.0.6261.128≥ 122.0.6261.128, < 122.0.6261.1282024-03-13
CVE-2024-2400 [HIGH] CWE-416 CVE-2024-2400: Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote atta
Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6102P3HIGHCVSS 8.8fixed in 126.0.6478.114≥ 126.0.6478.114, < 126.0.6478.1142024-06-20
CVE-2024-6102 [HIGH] CWE-787 CVE-2024-6102: Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attack
Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-4319P3HIGHCVSS 8.8fixed in 93.0.4577.82≥ 93.0.4577.82, < 93.0.4577.822023-07-29
CVE-2021-4319 [HIGH] CWE-416 CVE-2021-4319: Use after free in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to perform
Use after free in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4916P3HIGHCVSS 8.8fixed in 103.0.5060.53≥ 103.0.5060.53, < 103.0.5060.532023-07-29
CVE-2022-4916 [HIGH] CWE-416 CVE-2022-4916: Use after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform
Use after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd