Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 64 of 292
CVE-2023-5856P3HIGHCVSS 8.8fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5856 [HIGH] CWE-416 CVE-2023-5856: Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who
Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4074P3HIGHCVSS 8.8fixed in 115.0.5790.170≥ 115.0.5790.170, < 115.0.5790.1702023-08-03
CVE-2023-4074 [HIGH] CWE-416 CVE-2023-4074: Use after free in Blink Task Scheduling in Google Chrome prior to 115.0.5790.170 allowed a remote at
Use after free in Blink Task Scheduling in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6347P3HIGHCVSS 8.8fixed in 119.0.6045.199≥ 119.0.6045.199, < 119.0.6045.1992023-11-29
CVE-2023-6347 [HIGH] CWE-416 CVE-2023-6347: Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potenti
Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-0222P3HIGHCVSS 8.8fixed in 120.0.6099.199≥ 120.0.6099.199, < 120.0.6099.1992024-01-04
CVE-2024-0222 [HIGH] CWE-416 CVE-2024-0222: Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had c
Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3732P3HIGHCVSS 8.8fixed in 115.0.5790.98≥ 115.0.5790.98, < 115.0.5790.982023-08-01
CVE-2023-3732 [HIGH] CWE-787 CVE-2023-3732: Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacke
Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6508P3HIGHCVSS 8.8fixed in 120.0.6099.62≥ 120.0.6099.62, < 120.0.6099.622023-12-06
CVE-2023-6508 [HIGH] CWE-416 CVE-2023-6508: Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to
Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6348P3HIGHCVSS 8.8fixed in 119.0.6045.199≥ 119.0.6045.199, < 119.0.6045.1992023-11-29
CVE-2023-6348 [HIGH] CWE-843 CVE-2023-6348: Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who
Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5186P3HIGHCVSS 8.8fixed in 117.0.5938.132≥ 117.0.5938.132, < 117.0.5938.1322023-09-28
CVE-2023-5186 [HIGH] CWE-416 CVE-2023-5186: Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who c
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)
nvd
CVE-2023-4429P3HIGHCVSS 8.8fixed in 116.0.5845.110≥ 116.0.5845.110, < 116.0.5845.1102023-08-23
CVE-2023-4429 [HIGH] CWE-416 CVE-2023-4429: Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to poten
Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3216P3HIGHCVSS 8.8fixed in 114.0.5735.133≥ 114.0.5735.133, < 114.0.5735.1332023-06-13
CVE-2023-3216 [HIGH] CWE-843 CVE-2023-3216: Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-1059P3HIGHCVSS 8.8fixed in 121.0.6167.139≥ 121.0.6167.139, < 121.0.6167.1392024-01-30
CVE-2024-1059 [HIGH] CWE-416 CVE-2024-1059: Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker
Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-1077P3HIGHCVSS 8.8fixed in 121.0.6167.139≥ 121.0.6167.139, < 121.0.6167.1392024-01-30
CVE-2024-1077 [HIGH] CWE-416 CVE-2024-1077: Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to pote
Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
nvd
CVE-2024-5830P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5830 [HIGH] CWE-843 CVE-2024-5830: Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an
Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6990P3HIGHCVSS 8.8fixed in 127.0.6533.88≥ 127.0.6533.88, < 127.0.6533.882024-08-01
CVE-2024-6990 [HIGH] CWE-457 CVE-2024-6990: Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attack
Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2023-4572P3HIGHCVSS 8.8fixed in 116.0.5845.140≥ 116.0.5845.140, < 116.0.5845.1402023-08-29
CVE-2023-4572 [HIGH] CWE-416 CVE-2023-4572: Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to
Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5476P3HIGHCVSS 8.8fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5476 [HIGH] CWE-416 CVE-2023-5476: Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to
Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5474P3HIGHCVSS 8.8fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5474 [HIGH] CWE-787 CVE-2023-5474: Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who co
Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
nvd
CVE-2024-1938P3HIGHCVSS 8.8fixed in 122.0.6261.94≥ 122.0.6261.94, < 122.0.6261.942024-02-29
CVE-2024-1938 [HIGH] CWE-843 CVE-2024-1938: Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4351P3HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4351 [HIGH] CWE-416 CVE-2023-4351: Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has
Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4349P3HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4349 [HIGH] CWE-416 CVE-2023-4349: Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote a
Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd