cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 62 of 292
CVE-2022-3890P3CRITICALCVSS 9.6fixed in 107.0.5304.106≥ unspecified, < 107.0.5304.1062022-11-09
CVE-2022-3890 [CRITICAL] CWE-787 CVE-2022-3890: Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remot Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-6517P3HIGHCVSS 8.8fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6517 [HIGH] CWE-787 CVE-2020-6517: Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6523P3HIGHCVSS 8.8fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6523 [HIGH] CWE-190 CVE-2020-6523: Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to pote Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6520P3HIGHCVSS 8.8fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6520 [HIGH] CWE-787 CVE-2020-6520: Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentia Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6111P3HIGHCVSS 8.8fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6111 [HIGH] CWE-20 CVE-2018-6111: An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359. An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2020-6548P3HIGHCVSS 8.8fixed in 84.0.4147.125≥ unspecified, < 84.0.4147.1252020-09-21
CVE-2020-6548 [HIGH] CWE-787 CVE-2020-6548: Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who h Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6515P3HIGHCVSS 8.8fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6515 [HIGH] CWE-416 CVE-2020-6515: Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to pote Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15972P3HIGHCVSS 8.8fixed in 86.0.4240.75≥ unspecified, < 86.0.4240.752020-11-03
CVE-2020-15972 [HIGH] CWE-416 CVE-2020-15972: Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentia Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2010P3CRITICALCVSS 9.3fixed in 102.0.5005.115≥ unspecified, < 102.0.5005.1152022-07-28
CVE-2022-2010 [CRITICAL] CWE-125 CVE-2022-2010: Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2010-0315P4MEDIUMCVSS 5.0PoC≤ 4.0.249.78v0.2.149.27+45 more2010-01-14
CVE-2010-0315 [MEDIUM] CVE-2010-0315: WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discove WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.
nvd
CVE-2023-7012P3CRITICALCVSS 9.6fixed in 117.0.5938.62≥ 117.0.5938.62, < 117.0.5938.622024-07-16
CVE-2023-7012 [CRITICAL] CWE-20 CVE-2023-7012: Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed a Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-11250P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11250 [CRITICAL] CWE-416 CVE-2026-11250: Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote at Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2018-17458P3HIGHCVSS 8.8fixed in 69.0.3497.92≥ unspecified, < 69.0.3497.922019-01-09
CVE-2018-17458 [HIGH] CWE-129 CVE-2018-17458: An improper update of the WebAssembly dispatch table in WebAssembly in Google Chrome prior to 69.0.3 An improper update of the WebAssembly dispatch table in WebAssembly in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2020-6542P3HIGHCVSS 8.8fixed in 84.0.4147.125≥ unspecified, < 84.0.4147.1252020-09-21
CVE-2020-6542 [HIGH] CWE-416 CVE-2020-6542: Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potenti Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6533P3HIGHCVSS 8.8fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6533 [HIGH] CWE-787 CVE-2020-6533: Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6464P3HIGHCVSS 8.8fixed in 81.0.4044.138≥ unspecified, < 81.0.4044.1382020-05-21
CVE-2020-6464 [HIGH] CWE-787 CVE-2020-6464: Type confusion in Blink in Google Chrome prior to 81.0.4044.138 allowed a remote attacker to potenti Type confusion in Blink in Google Chrome prior to 81.0.4044.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21160P3HIGHCVSS 8.8fixed in 89.0.4389.72≥ unspecified, < 89.0.4389.722021-03-09
CVE-2021-21160 [HIGH] CWE-787 CVE-2021-21160: Heap buffer overflow in WebAudio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to Heap buffer overflow in WebAudio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6430P3HIGHCVSS 8.8fixed in 81.0.4044.92≥ unspecified, < 81.0.4044.922020-04-13
CVE-2020-6430 [HIGH] CWE-843 CVE-2020-6430: Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15960P3HIGHCVSS 8.8fixed in 85.0.4183.121≥ unspecified, < 85.0.4183.1212020-09-21
CVE-2020-15960 [HIGH] CWE-787 CVE-2020-15960: Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2022-2853P3HIGHCVSS 8.8fixed in 104.0.5112.101≥ unspecified, < 104.0.5112.1012022-09-26
CVE-2022-2853 [HIGH] CWE-787 CVE-2022-2853: Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remo Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase