Google Chrome vulnerabilities

3,975 known vulnerabilities affecting google/chrome.

Total CVEs
3,975
CISA KEV
74
actively exploited
Public exploits
63
Exploited in wild
65
Severity breakdown
CRITICAL297HIGH2024MEDIUM1626LOW17UNKNOWN11

Vulnerabilities

Page 61 of 199
CVE-2022-1141HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1141 [HIGH] CWE-416 CVE-2022-1141: Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.
nvd
CVE-2022-1144HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1144 [HIGH] CWE-416 CVE-2022-1144: Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convin Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
nvd
CVE-2022-1133HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1133 [HIGH] CWE-416 CVE-2022-1133: Use after free in WebRTC Perf in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to p Use after free in WebRTC Perf in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-1135HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1135 [HIGH] CWE-416 CVE-2022-1135: Use after free in Shopping Cart in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to Use after free in Shopping Cart in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via standard feature user interaction.
nvd
CVE-2022-1130HIGHCVSS 8.1fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1130 [HIGH] CWE-476 CVE-2022-1130: Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 100.0.4896.60 Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to send arbitrary intents from any app via a malicious app.
nvd
CVE-2022-1096HIGHCVSS 8.8KEVfixed in 99.0.4844.84≥ unspecified, < 99.0.4844.842022-07-23
CVE-2022-1096 [HIGH] CWE-843 CVE-2022-1096: Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-1136HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1136 [HIGH] CWE-416 CVE-2022-1136: Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convince Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific set of user gestures.
nvd
CVE-2022-1127HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1127 [HIGH] CWE-416 CVE-2022-1127: Use after free in QR Code Generator in Google Chrome prior to 100.0.4896.60 allowed a remote attacke Use after free in QR Code Generator in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.
nvd
CVE-2022-1125HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1125 [HIGH] CWE-416 CVE-2022-1125: Use after free in Portals in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who conv Use after free in Portals in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.
nvd
CVE-2022-1131HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1131 [HIGH] CWE-416 CVE-2022-1131: Use after free in Cast UI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to poten Use after free in Cast UI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-1145HIGHCVSS 7.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1145 [HIGH] CWE-416 CVE-2022-1145: Use after free in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinc Use after free in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interaction and profile destruction.
nvd
CVE-2022-1142HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1142 [HIGH] CWE-787 CVE-2022-1142: Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
nvd
CVE-2022-1134HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1134 [HIGH] CWE-843 CVE-2022-1134: Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-1143HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1143 [HIGH] CWE-787 CVE-2022-1143: Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
nvd
CVE-2022-1138MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1138 [MEDIUM] CWE-1021 CVE-2022-1138: Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2022-1137MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1137 [MEDIUM] CWE-668 CVE-2022-1137: Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attack Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially sensitive information via a crafted HTML page.
nvd
CVE-2022-1146MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1146 [MEDIUM] CWE-203 CVE-2022-1146: Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a re Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-1128MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1128 [MEDIUM] CWE-22 CVE-2022-1128: Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 all Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-1129MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1129 [MEDIUM] CWE-290 CVE-2022-1129: Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2022-1139MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1139 [MEDIUM] CWE-203 CVE-2022-1139: Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd