Google Chrome vulnerabilities
5,463 known vulnerabilities affecting google/chrome.
Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65
Vulnerabilities
Page 6 of 274
CVE-2020-6404P3HIGHCVSS 8.8PoCfixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6404 [HIGH] CWE-787 CVE-2020-6404: Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attack
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-6702P2HIGHCVSS 8.8fixed in 120.0.6099.109≥ 120.0.6099.109, < 120.0.6099.1092023-12-14
CVE-2023-6702 [HIGH] CWE-843 CVE-2023-6702: Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2019-5796P3HIGHCVSS 7.5PoCfixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5796 [HIGH] CWE-362 CVE-2019-5796: Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2010-2300P3CRITICALCVSS 10.0PoCfixed in 5.0.375.702010-06-15
CVE-2010-2300 [CRITICAL] CVE-2010-2300: Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebC
Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to handlers for DOM mutation events, aka rdar problem 7948784. NOTE: this might overlap CVE
nvd
CVE-2008-6994P3CRITICALCVSS 9.3PoCv0.2.149.272009-08-19
CVE-2008-6994 [CRITICAL] CWE-119 CVE-2008-6994: Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in
Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.149.27 allows user-assisted remote attackers to execute arbitrary code via a web page with a long TITLE element, which triggers the overflow when the user saves the page and a long filename is generated. NOTE: it might be possible to
nvd
CVE-2023-4357P2HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4357 [HIGH] CWE-20 CVE-2023-4357: Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a
Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2019-5797P3HIGHCVSS 7.5PoCfixed in 73.0.3683.75≥ unspecified, < 73.0.3683.752022-09-29
CVE-2019-5797 [HIGH] CWE-415 CVE-2019-5797: Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potent
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2024-1283P2CRITICALCVSS 9.8fixed in 121.0.6167.160≥ 121.0.6167.160, < 121.0.6167.1602024-02-07
CVE-2024-1283 [CRITICAL] CWE-787 CVE-2024-1283: Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to p
Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10973P3HIGHCVSS 7.4PoCfixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10973 [HIGH] CWE-457 CVE-2026-10973: Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak
Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-6519P3MEDIUMCVSS 6.5PoCfixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6519 [MEDIUM] CVE-2020-6519: Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass cont
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2015-8664P3HIGHCVSS 8.8PoC≤ 47.0.2526.802015-12-24
CVE-2015-8664 [HIGH] CVE-2015-8664: Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Go
Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an RGBA pixel array with crafted dimensions, a different vulnerability than CVE-2015-6792.
nvd
CVE-2023-6112P2HIGHCVSS 8.8fixed in 119.0.6045.159≥ 119.0.6045.159, < 119.0.6045.1592023-11-15
CVE-2023-6112 [HIGH] CWE-416 CVE-2023-6112: Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to p
Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2008-6998P3CRITICALCVSS 9.3PoCv0.2.149.272009-08-19
CVE-2008-6998 [CRITICAL] CWE-119 CVE-2008-6998: Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other
Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number of path elements, which triggers the overflow when the status bar is updated after the user hovers
nvd
CVE-2015-6787P3CRITICALCVSS 10.0PoC≤ 46.0.2490.862015-12-06
CVE-2015-6787 [CRITICAL] CVE-2015-6787: Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2023-2724P2HIGHCVSS 8.8fixed in 113.0.5672.126≥ 113.0.5672.126, < 113.0.5672.1262023-05-16
CVE-2023-2724 [HIGH] CWE-843 CVE-2023-2724: Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-0907P2CRITICALCVSS 9.8fixed in 144.0.7559.59fixed in 144.0.7559.60+1 more2026-01-20
CVE-2026-0907 [CRITICAL] CWE-451 CVE-2026-0907: Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacke
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2013-2842P3HIGHCVSS 7.5PoC≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2842 [HIGH] CWE-399 CVE-2013-2842: Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets.
nvd
CVE-2023-4355P2HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4355 [HIGH] CWE-787 CVE-2023-4355: Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4069P2HIGHCVSS 8.8fixed in 115.0.5790.170≥ 115.0.5790.170, < 115.0.5790.1702023-08-03
CVE-2023-4069 [HIGH] CWE-843 CVE-2023-4069: Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potential
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-2935P2HIGHCVSS 8.8fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-05-30
CVE-2023-2935 [HIGH] CWE-843 CVE-2023-2935: Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd