cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 65 of 292
CVE-2023-4358P3HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4358 [HIGH] CWE-416 CVE-2023-4358: Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potential Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-1673P3HIGHCVSS 8.8fixed in 122.0.6261.57≥ 122.0.6261.57, < 122.0.6261.572024-02-21
CVE-2024-1673 [HIGH] CWE-416 CVE-2024-1673: Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker wh Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
nvd
CVE-2024-9602P3HIGHCVSS 8.8fixed in 129.0.6668.100≥ 129.0.6668.100, < 129.0.6668.1002024-10-08
CVE-2024-9602 [HIGH] CWE-843 CVE-2024-9602: Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform a Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5493P3HIGHCVSS 8.8fixed in 125.0.6422.141≥ 125.0.6422.141, < 125.0.6422.1412024-05-30
CVE-2024-5493 [HIGH] CWE-787 CVE-2024-5493: Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3728P3HIGHCVSS 8.8fixed in 115.0.5790.98≥ 115.0.5790.98, < 115.0.5790.982023-08-01
CVE-2023-3728 [HIGH] CWE-416 CVE-2023-3728: Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potent Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4912P3HIGHCVSS 8.8fixed in 105.0.5195.52≥ 105.0.5195.52, < 105.0.5195.522023-07-29
CVE-2022-4912 [HIGH] CWE-843 CVE-2022-4912: Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potent Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3727P3HIGHCVSS 8.8fixed in 115.0.5790.98≥ 115.0.5790.98, < 115.0.5790.982023-08-01
CVE-2023-3727 [HIGH] CWE-416 CVE-2023-3727: Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potent Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7534P3HIGHCVSS 8.8fixed in 127.0.6533.99≥ 127.0.6533.99, < 127.0.6533.992024-08-06
CVE-2024-7534 [HIGH] CWE-122 CVE-2024-7534: Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6705P3HIGHCVSS 8.8fixed in 120.0.6099.109≥ 120.0.6099.109, < 120.0.6099.1092023-12-14
CVE-2023-6705 [HIGH] CWE-416 CVE-2023-6705: Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to poten Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-2313P3HIGHCVSS 8.8fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-07-29
CVE-2023-2313 [HIGH] CVE-2023-2313: Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High)
nvd
CVE-2024-10487P3HIGHCVSS 8.8fixed in 130.0.6723.92≥ 130.0.6723.92, < 130.0.6723.922024-10-29
CVE-2024-10487 [HIGH] CWE-787 CVE-2024-10487: Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to per Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2024-7535P3HIGHCVSS 8.8fixed in 127.0.6533.99≥ 127.0.6533.99, < 127.0.6533.992024-08-06
CVE-2024-7535 [HIGH] CWE-787 CVE-2024-7535: Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6703P3HIGHCVSS 8.8fixed in 120.0.6099.109≥ 120.0.6099.109, < 120.0.6099.1092023-12-14
CVE-2023-6703 [HIGH] CWE-416 CVE-2023-6703: Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potent Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7533P3HIGHCVSS 8.8fixed in 127.0.6533.99≥ 127.0.6533.99, < 127.0.6533.992024-08-06
CVE-2024-7533 [HIGH] CWE-416 CVE-2024-7533: Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker t Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2012-1846P3CRITICALCVSS 10.0≤ 17.0.963.662012-03-22
CVE-2012-1846 [CRITICAL] CWE-668 CVE-2012-1846: Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mecha Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected product may be clarified later; it was not identified by the researcher, who reportedly stated "it r
nvd
CVE-2024-5160P3HIGHCVSS 8.8fixed in 125.0.6422.76≥ 125.0.6422.76, < 125.0.6422.762024-05-22
CVE-2024-5160 [HIGH] CWE-787 CVE-2024-5160: Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to pe Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7025P3HIGHCVSS 8.8fixed in 129.0.6668.89≥ 129.0.6668.89, < 129.0.6668.892024-11-27
CVE-2024-7025 [HIGH] CWE-472 CVE-2024-7025: Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to pote Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7964P3HIGHCVSS 8.8fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-7964 [HIGH] CWE-416 CVE-2024-7964: Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote atta Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-1426P3HIGHCVSS 8.8fixed in 133.0.6943.126≥ 133.0.6943.126, < 133.0.6943.1262025-02-19
CVE-2025-1426 [HIGH] CWE-122 CVE-2025-1426: Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote att Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7972P3HIGHCVSS 8.8fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-7972 [HIGH] CWE-119 CVE-2024-7972: Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase