cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 57 of 292
CVE-2022-4918P3HIGHCVSS 8.8fixed in 102.0.5005.61≥ 102.0.5005.61, < 102.0.5005.612023-07-29
CVE-2022-4918 [HIGH] CWE-416 CVE-2022-4918: Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform ar Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4919P3HIGHCVSS 8.8fixed in 101.0.4951.41≥ 101.0.4951.41, < 101.0.4951.412023-07-29
CVE-2022-4919 [HIGH] CWE-416 CVE-2022-4919: Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker t Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5495P3HIGHCVSS 8.8fixed in 125.0.6422.141≥ 125.0.6422.141, < 125.0.6422.1412024-05-30
CVE-2024-5495 [HIGH] CWE-416 CVE-2024-5495: Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7966P3HIGHCVSS 8.8fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-7966 [HIGH] CWE-119 CVE-2024-7966: Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacke Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5494P3HIGHCVSS 8.8fixed in 125.0.6422.141≥ 125.0.6422.141, < 125.0.6422.1412024-05-30
CVE-2024-5494 [HIGH] CWE-416 CVE-2024-5494: Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4921P3HIGHCVSS 8.8fixed in 99.0.4844.51≥ 99.0.4844.51, < 99.0.4844.512023-07-29
CVE-2022-4921 [HIGH] CWE-416 CVE-2022-4921: Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2021-4320P3HIGHCVSS 8.8fixed in 92.0.4515.107≥ 92.0.4515.107, < 92.0.4515.1072023-07-29
CVE-2021-4320 [HIGH] CWE-416 CVE-2021-4320: Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had co Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-4317P3HIGHCVSS 8.8fixed in 96.0.4664.93≥ 96.0.4664.93, < 96.0.4664.932023-07-29
CVE-2021-4317 [HIGH] CWE-416 CVE-2021-4317: Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6704P3HIGHCVSS 8.8fixed in 120.0.6099.109≥ 120.0.6099.109, < 120.0.6099.1092023-12-14
CVE-2023-6704 [HIGH] CWE-416 CVE-2023-6704: Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to pote Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted image file. (Chromium security severity: High)
nvd
CVE-2024-10827P3HIGHCVSS 8.8fixed in 130.0.6723.116≥ 130.0.6723.116, < 130.0.6723.1162024-11-06
CVE-2024-10827 [HIGH] CWE-416 CVE-2024-10827: Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to poten Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6103P3HIGHCVSS 8.8fixed in 126.0.6478.114≥ 126.0.6478.114, < 126.0.6478.1142024-06-20
CVE-2024-6103 [HIGH] CWE-416 CVE-2024-6103: Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-10230P3HIGHCVSS 8.8fixed in 130.0.6723.69≥ 130.0.6723.69, < 130.0.6723.692024-10-22
CVE-2024-10230 [HIGH] CWE-843 CVE-2024-10230: Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7550P3HIGHCVSS 8.8fixed in 127.0.6533.99≥ 127.0.6533.99, < 127.0.6533.992024-08-06
CVE-2024-7550 [HIGH] CWE-843 CVE-2024-7550: Type Confusion in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-0999P3HIGHCVSS 8.8fixed in 133.0.6943.126≥ 133.0.6943.126, < 133.0.6943.1262025-02-19
CVE-2025-0999 [HIGH] CWE-122 CVE-2025-0999: Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to pot Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7536P3HIGHCVSS 8.8fixed in 127.0.6533.99≥ 127.0.6533.99, < 127.0.6533.992024-08-06
CVE-2024-7536 [HIGH] CWE-416 CVE-2024-7536: Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to pote Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7967P3HIGHCVSS 8.8fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-7967 [HIGH] CWE-122 CVE-2024-7967: Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to p Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6991P3HIGHCVSS 8.8fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-6991 [HIGH] CWE-416 CVE-2024-6991: Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentia Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6989P3HIGHCVSS 8.8fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-6989 [HIGH] CWE-416 CVE-2024-6989: Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potent Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5834P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5834 [HIGH] CWE-94 CVE-2024-5834: Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attack Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7968P3HIGHCVSS 8.8fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-7968 [HIGH] CWE-416 CVE-2024-7968: Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase