cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 67 of 292
CVE-2025-0443P3HIGHCVSS 8.8fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0443 [HIGH] CWE-79 CVE-2025-0443: Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-8636P3HIGHCVSS 8.8fixed in 128.0.6613.137≥ 128.0.6613.137, < 128.0.6613.1372024-09-11
CVE-2024-8636 [HIGH] CWE-122 CVE-2024-8636: Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to p Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-7010P3HIGHCVSS 8.8fixed in 117.0.5938.62≥ 117.0.5938.62, < 117.0.5938.622024-07-16
CVE-2023-7010 [HIGH] CWE-416 CVE-2023-7010: Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potent Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-8198P3HIGHCVSS 8.8fixed in 128.0.6613.113≥ 128.0.6613.113, < 128.0.6613.1132024-08-28
CVE-2024-8198 [HIGH] CWE-122 CVE-2024-8198: Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-1918P3HIGHCVSS 8.8fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-03-05
CVE-2025-1918 [HIGH] CWE-125 CVE-2025-1918: Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to po Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Medium)
nvd
CVE-2024-8193P3HIGHCVSS 8.8fixed in 128.0.6613.113≥ 128.0.6613.113, < 128.0.6613.1132024-08-28
CVE-2024-8193 [HIGH] CWE-122 CVE-2024-8193: Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-8194P3HIGHCVSS 8.8fixed in 128.0.6613.113≥ 128.0.6613.113, < 128.0.6613.1132024-08-28
CVE-2024-8194 [HIGH] CWE-843 CVE-2024-8194: Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potential Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-11395P3HIGHCVSS 8.8fixed in 131.0.6778.85≥ 131.0.6778.85, < 131.0.6778.852024-11-19
CVE-2024-11395 [HIGH] CWE-843 CVE-2024-11395: Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-9866P3HIGHCVSS 8.8fixed in 140.0.7339.80≥ 140.0.7339.80, < 140.0.7339.802025-09-03
CVE-2025-9866 [HIGH] CWE-693 CVE-2025-9866: Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-11113P3HIGHCVSS 8.8fixed in 131.0.6778.69≥ 131.0.6778.69, < 131.0.6778.692024-11-12
CVE-2024-11113 [HIGH] CWE-416 CVE-2024-11113: Use after free in Accessibility in Google Chrome prior to 131.0.6778.69 allowed a remote attacker wh Use after free in Accessibility in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-3169P3HIGHCVSS 8.8fixed in 121.0.6167.139≥ 121.0.6167.139, < 121.0.6167.1392024-07-16
CVE-2024-3169 [HIGH] CWE-416 CVE-2024-3169: Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potential Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-3170P3HIGHCVSS 8.8fixed in 121.0.6167.85≥ 121.0.6167.85, < 121.0.6167.852024-07-16
CVE-2024-3170 [HIGH] CWE-416 CVE-2024-3170: Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potent Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-3066P3HIGHCVSS 8.8fixed in 135.0.7049.52≥ 135.0.7049.84, < 135.0.7049.842025-04-02
CVE-2025-3066 [HIGH] CWE-416 CVE-2025-3066: Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker t Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-1920P3HIGHCVSS 8.8fixed in 134.0.6998.88≥ 134.0.6998.88, < 134.0.6998.882025-03-10
CVE-2025-1920 [HIGH] CWE-843 CVE-2025-1920: Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-2136P3HIGHCVSS 8.8fixed in 134.0.6998.88≥ 134.0.6998.88, < 134.0.6998.882025-03-10
CVE-2025-2136 [HIGH] CWE-416 CVE-2025-2136: Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to pot Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-12694P3HIGHCVSS 8.8fixed in 131.0.6778.204≥ 131.0.6778.204, < 131.0.6778.2042024-12-18
CVE-2024-12694 [HIGH] CWE-416 CVE-2024-12694: Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-38023P3HIGHCVSS 8.8fixed in 92.0.4515.107≥ 92.0.4515.107, < 92.0.4515.1072024-09-23
CVE-2021-38023 [HIGH] CWE-416 CVE-2021-38023: Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to po Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-8879P3HIGHCVSS 8.8fixed in 139.0.7258.127≥ 139.0.7258.127, < 139.0.7258.1272025-08-13
CVE-2025-8879 [HIGH] CWE-122 CVE-2025-8879: Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)
nvd
CVE-2025-12725P3HIGHCVSS 8.8fixed in 142.0.7444.137fixed in 142.0.7444.134+2 more2025-11-10
CVE-2025-12725 [HIGH] CWE-125 CVE-2025-12725: Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote at Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-3620P3HIGHCVSS 8.8fixed in 135.0.7049.95≥ 135.0.7049.95, < 135.0.7049.952025-04-16
CVE-2025-3620 [HIGH] CWE-416 CVE-2025-3620: Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potential Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase