Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 66 of 292
CVE-2024-6988P3HIGHCVSS 8.8fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-6988 [HIGH] CWE-416 CVE-2024-6988: Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker
Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6994P3HIGHCVSS 8.8fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-6994 [HIGH] CWE-122 CVE-2024-6994: Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to
Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-10826P3HIGHCVSS 8.8fixed in 130.0.6723.116≥ 130.0.6723.116, < 130.0.6723.1162024-11-06
CVE-2024-10826 [HIGH] CWE-416 CVE-2024-10826: Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a r
Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-3067P3HIGHCVSS 8.8fixed in 135.0.7049.52≥ 135.0.7049.52, < 135.0.7049.522025-04-02
CVE-2025-3067 [HIGH] CVE-2025-3067: Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allow
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted app. (Chromium security severity: Medium)
nvd
CVE-2024-6997P3HIGHCVSS 8.8fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-6997 [HIGH] CWE-416 CVE-2024-6997: Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinc
Use after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-5837P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5837 [HIGH] CWE-843 CVE-2024-5837: Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5833P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5833 [HIGH] CWE-843 CVE-2024-5833: Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5835P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5835 [HIGH] CWE-787 CVE-2024-5835: Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker
Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-1006P3HIGHCVSS 8.8fixed in 133.0.6943.126≥ 133.0.6943.126, < 133.0.6943.1262025-02-19
CVE-2025-1006 [HIGH] CWE-416 CVE-2025-1006: Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to pote
Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted web app. (Chromium security severity: Medium)
nvd
CVE-2024-7970P3HIGHCVSS 8.8fixed in 128.0.6613.119≥ 128.0.6613.119, < 128.0.6613.1192024-09-03
CVE-2024-7970 [HIGH] CWE-787 CVE-2024-7970: Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to pote
Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-9121P3HIGHCVSS 8.8fixed in 129.0.6668.70≥ 129.0.6668.70, < 129.0.6668.702024-09-25
CVE-2024-9121 [HIGH] CWE-787 CVE-2024-9121: Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5842P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5842 [HIGH] CWE-416 CVE-2024-5842: Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who c
Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-6774P3HIGHCVSS 8.8fixed in 126.0.6478.182≥ 126.0.6478.182, < 126.0.6478.1822024-07-16
CVE-2024-6774 [HIGH] CWE-416 CVE-2024-6774: Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker
Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-4050P3HIGHCVSS 8.8fixed in 136.0.7103.59≥ 136.0.7103.59, < 136.0.7103.592025-05-05
CVE-2025-4050 [HIGH] CWE-787 CVE-2025-4050: Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote att
Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-8905P3HIGHCVSS 8.8fixed in 129.0.6668.58≥ 129.0.6668.58, < 129.0.6668.582024-09-17
CVE-2024-8905 [HIGH] CWE-787 CVE-2024-8905: Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-9603P3HIGHCVSS 8.8fixed in 129.0.6668.100≥ 129.0.6668.100, < 129.0.6668.1002024-10-08
CVE-2024-9603 [HIGH] CWE-843 CVE-2024-9603: Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potential
Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5847P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5847 [HIGH] CWE-416 CVE-2024-5847: Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potent
Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
nvd
CVE-2024-5846P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5846 [HIGH] CWE-416 CVE-2024-5846: Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potent
Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
nvd
CVE-2024-6775P3HIGHCVSS 8.8fixed in 126.0.6478.182≥ 126.0.6478.182, < 126.0.6478.1822024-07-16
CVE-2024-6775 [HIGH] CWE-416 CVE-2024-6775: Use after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed a remote attacker wh
Use after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5845P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5845 [HIGH] CWE-416 CVE-2024-5845: Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potenti
Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
nvd