Google Chrome vulnerabilities

3,975 known vulnerabilities affecting google/chrome.

Total CVEs
3,975
CISA KEV
74
actively exploited
Public exploits
61
Exploited in wild
65
Severity breakdown
CRITICAL297HIGH2029MEDIUM1630LOW17UNKNOWN2

Vulnerabilities

Page 6 of 199
CVE-2026-5292HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5292 [HIGH] CWE-125 CVE-2026-5292: Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker t Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-5287HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5287 [HIGH] CWE-416 CVE-2026-5287: Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-5284HIGHCVSS 7.5fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5284 [HIGH] CWE-416 CVE-2026-5284: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had co Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-5282HIGHCVSS 8.1fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5282 [HIGH] CWE-125 CVE-2026-5282: Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker t Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-5274HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5274 [HIGH] CWE-472 CVE-2026-5274: Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to per Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-5278HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5278 [HIGH] CWE-416 CVE-2026-5278: Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote atta Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-5277HIGHCVSS 7.5fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5277 [HIGH] CWE-472 CVE-2026-5277: Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attac Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-5281HIGHCVSS 8.8KEVfixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5281 [HIGH] CWE-416 CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had co Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-5291MEDIUMCVSS 6.5fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5291 [MEDIUM] CWE-200 CVE-2026-5291: Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote atta Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-5276MEDIUMCVSS 6.5fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5276 [MEDIUM] CWE-693 CVE-2026-5276: Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-5283MEDIUMCVSS 6.5fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5283 [MEDIUM] CWE-285 CVE-2026-5283: Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote atta Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-5273MEDIUMCVSS 6.3fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5273 [MEDIUM] CWE-416 CVE-2026-5273: Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-4680HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4680 [HIGH] CWE-416 CVE-2026-4680: Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execut Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-4678HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4678 [HIGH] CWE-416 CVE-2026-4678: Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execu Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-4673HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4673 [HIGH] CWE-122 CVE-2026-4673: Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-4675HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4675 [HIGH] CWE-122 CVE-2026-4675: Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-4676HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4676 [HIGH] CWE-416 CVE-2026-4676: Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-4679HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4679 [HIGH] CWE-472 CVE-2026-4679: Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perf Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-4674HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4674 [HIGH] CWE-125 CVE-2026-4674: Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perf Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-4677HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4677 [HIGH] CWE-125 CVE-2026-4677: Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote a Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd