Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 59 of 292
CVE-2024-9859P3HIGHCVSS 8.8fixed in 126.0.6478.126≥ 126.0.6478.126, < 126.0.6478.1262024-10-11
CVE-2024-9859 [HIGH] CWE-843 CVE-2024-9859: Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to
Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-5958P3HIGHCVSS 8.8fixed in 137.0.7151.103≥ 137.0.7151.103, < 137.0.7151.1032025-06-11
CVE-2025-5958 [HIGH] CWE-416 CVE-2025-5958: Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potent
Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-3619P3HIGHCVSS 8.8fixed in 135.0.7049.95≥ 135.0.7049.95, < 135.0.7049.952025-04-16
CVE-2025-3619 [HIGH] CWE-122 CVE-2025-3619: Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote a
Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2025-8578P3HIGHCVSS 8.8fixed in 139.0.7258.66≥ 139.0.7258.66, < 139.0.7258.662025-08-07
CVE-2025-8578 [HIGH] CWE-416 CVE-2025-8578: Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentia
Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-8292P3HIGHCVSS 8.8fixed in 138.0.7204.183≥ 138.0.7204.183, < 138.0.7204.1832025-07-30
CVE-2025-8292 [HIGH] CWE-416 CVE-2025-8292: Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to
Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-8576P3HIGHCVSS 8.8fixed in 139.0.7258.66≥ 139.0.7258.66, < 139.0.7258.662025-08-07
CVE-2025-8576 [HIGH] CWE-416 CVE-2025-8576: Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to po
Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2025-8901P3HIGHCVSS 8.8fixed in 139.0.7258.127≥ 139.0.7258.127, < 139.0.7258.1272025-08-13
CVE-2025-8901 [HIGH] CWE-787 CVE-2025-8901: Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to p
Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-10892P3HIGHCVSS 8.8fixed in 140.0.7339.207≥ 140.0.7339.207, < 140.0.7339.2072025-09-24
CVE-2025-10892 [HIGH] CWE-472 CVE-2025-10892: Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potenti
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14036P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14036 [HIGH] CWE-602 CVE-2026-14036: Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remot
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-3919P3HIGHCVSS 8.8fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3919 [HIGH] CWE-416 CVE-2026-3919: Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinc
Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-10502P3HIGHCVSS 8.8fixed in 140.0.7339.185≥ 140.0.7339.185, < 140.0.7339.1852025-09-24
CVE-2025-10502 [HIGH] CWE-122 CVE-2025-10502: Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to
Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2026-0902P3HIGHCVSS 8.8fixed in 144.0.7559.59fixed in 144.0.7559.60+1 more2026-01-20
CVE-2026-0902 [HIGH] CWE-474 CVE-2026-0902: Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-8010P3HIGHCVSS 8.8fixed in 138.0.7204.168≥ 138.0.7204.168, < 138.0.7204.1682025-07-22
CVE-2025-8010 [HIGH] CWE-843 CVE-2025-8010: Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potential
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-8011P3HIGHCVSS 8.8fixed in 138.0.7204.168≥ 138.0.7204.168, < 138.0.7204.1682025-07-22
CVE-2025-8011 [HIGH] CWE-843 CVE-2025-8011: Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potential
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11085P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11085 [HIGH] CWE-472 CVE-2026-11085: Integer overflow in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker
Integer overflow in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11248P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11248 [HIGH] CWE-693 CVE-2026-11248: Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote
Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11124P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11124 [HIGH] CWE-122 CVE-2026-11124: Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potent
Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11188P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11188 [HIGH] CWE-416 CVE-2026-11188: Use after free in USB in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker t
Use after free in USB in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11108P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11108 [HIGH] CWE-269 CVE-2026-11108: Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a rem
Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11295P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11295 [HIGH] CWE-269 CVE-2026-11295: Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd