cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 61 of 292
CVE-2019-5870P3CRITICALCVSS 9.6fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5870 [CRITICAL] CWE-416 CVE-2019-5870: Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentia Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2017-5059P3HIGHCVSS 8.8fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5059 [HIGH] CWE-843 CVE-2017-5059: Type confusion in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0 Type confusion in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to potentially obtain code execution via a crafted HTML page.
nvd
CVE-2020-6457P3CRITICALCVSS 9.6fixed in 81.0.4044.113≥ unspecified, < 81.0.4044.1132020-05-21
CVE-2020-6457 [CRITICAL] CWE-416 CVE-2020-6457: Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacke Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2022-2587P3CRITICALCVSS 9.8fixed in 102.0.5005.125≥ unspecified, < 102.0.5005.1252022-08-12
CVE-2022-2587 [CRITICAL] CWE-787 CVE-2022-2587: Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.
nvd
CVE-2017-5088P3HIGHCVSS 8.8fixed in 59.0.3071.104fixed in 59.0.3071.1172017-10-27
CVE-2017-5088 [HIGH] CWE-125 CVE-2017-5088: Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Wi Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2018-18356P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18356 [HIGH] CWE-190 CVE-2018-18356: An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0 An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21107P3CRITICALCVSS 9.6fixed in 87.0.4280.141≥ unspecified, < 87.0.4280.1412021-01-08
CVE-2021-21107 [CRITICAL] CWE-416 CVE-2021-21107: Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote at Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21142P3CRITICALCVSS 9.6fixed in 88.0.4324.146≥ unspecified, < 88.0.4324.1462021-02-09
CVE-2021-21142 [CRITICAL] CWE-416 CVE-2021-21142: Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6390P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6390 [HIGH] CWE-787 CVE-2020-6390: Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attac Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-13831P3HIGHCVSS 7.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13831 [HIGH] CWE-416 CVE-2026-13831: Out of bounds read and write in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacke Out of bounds read and write in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-38013P3CRITICALCVSS 9.6fixed in 96.0.4664.45≥ unspecified, < 96.0.4664.452021-12-23
CVE-2021-38013 [CRITICAL] CWE-787 CVE-2021-38013: Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 a Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-16014P3CRITICALCVSS 9.6fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16014 [CRITICAL] CWE-416 CVE-2020-16014: Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had com Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-16018P3CRITICALCVSS 9.6fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16018 [CRITICAL] CWE-416 CVE-2020-16018: Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6513P3HIGHCVSS 8.8fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6513 [HIGH] CWE-787 CVE-2020-6513: Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to p Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-15412P3HIGHCVSS 8.8fixed in 63.0.3239.842018-08-28
CVE-2017-15412 [HIGH] CWE-416 CVE-2017-15412: Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other pro Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-17979P3HIGHCVSS 7.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17979 [HIGH] CWE-362 CVE-2026-17979: Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17952P3HIGHCVSS 7.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17952 [HIGH] CWE-269 CVE-2026-17952: Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who c Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2026-17948P3HIGHCVSS 7.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17948 [HIGH] CWE-843 CVE-2026-17948: Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a use Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2022-0973P3CRITICALCVSS 9.6fixed in 99.0.4844.74≥ unspecified, < 99.0.4844.742022-07-21
CVE-2022-0973 [CRITICAL] CWE-416 CVE-2022-0973: Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-1309P3CRITICALCVSS 9.6fixed in 100.0.4896.88≥ unspecified, < 100.0.4896.882022-07-25
CVE-2022-1309 [CRITICAL] CWE-863 CVE-2022-1309: Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase