Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 68 of 292
CVE-2025-8882P3HIGHCVSS 8.8fixed in 139.0.7258.127≥ 139.0.7258.127, < 139.0.7258.1272025-08-13
CVE-2025-8882 [HIGH] CWE-416 CVE-2025-8882: Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convin
Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-4460P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4460 [HIGH] CWE-125 CVE-2026-4460: Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to per
Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4462P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4462 [HIGH] CWE-125 CVE-2026-4462: Out of bounds read in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to pe
Out of bounds read in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11172P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11172 [HIGH] CWE-451 CVE-2026-11172: Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a
Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11175P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11175 [HIGH] CWE-451 CVE-2026-11175: Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remot
Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11202P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11202 [HIGH] CWE-20 CVE-2026-11202: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowe
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11179P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11179 [HIGH] CWE-284 CVE-2026-11179: Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacke
Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7903P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7903 [HIGH] CWE-472 CVE-2026-7903: Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote at
Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10019P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-10019 [HIGH] CWE-472 CVE-2026-10019: Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-3173P3HIGHCVSS 8.8fixed in 120.0.6099.62≥ 120.0.6099.62, < 120.0.6099.622024-07-16
CVE-2024-3173 [HIGH] CWE-345 CVE-2024-3173: Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote att
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-10898P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10898 [HIGH] CWE-121 CVE-2026-10898: Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who h
Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10949P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10949 [HIGH] CWE-122 CVE-2026-10949: Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who
Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10929P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10929 [HIGH] CWE-122 CVE-2026-10929: Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827.53 allowed a remote at
Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10911P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10911 [HIGH] CWE-20 CVE-2026-10911: Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed
Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10917P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10917 [HIGH] CWE-20 CVE-2026-10917: Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed
Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10905P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10905 [HIGH] CWE-416 CVE-2026-10905: Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had
Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10894P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10894 [HIGH] CWE-416 CVE-2026-10894: Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacke
Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10908P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10908 [HIGH] CWE-416 CVE-2026-10908: Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote att
Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10884P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10884 [HIGH] CWE-416 CVE-2026-10884: Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who h
Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10933P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10933 [HIGH] CWE-416 CVE-2026-10933: Use after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker
Use after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd