Google Chrome vulnerabilities
5,463 known vulnerabilities affecting google/chrome.
Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65
Vulnerabilities
Page 7 of 274
CVE-2023-2936P2HIGHCVSS 8.8fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-05-30
CVE-2023-2936 [HIGH] CWE-843 CVE-2023-2936: Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-0517P2HIGHCVSS 8.8fixed in 120.0.6099.224≥ 120.0.6099.224, < 120.0.6099.2242024-01-16
CVE-2024-0517 [HIGH] CWE-787 CVE-2024-0517: Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to pote
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-38001P2HIGHCVSS 8.8fixed in 95.0.4638.69≥ unspecified, < 95.0.4638.692021-11-23
CVE-2021-38001 [HIGH] CWE-843 CVE-2021-38001: Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially
Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2998P2HIGHCVSS 8.8fixed in 104.0.5112.101≥ unspecified, < 104.0.5112.1012022-09-26
CVE-2022-2998 [HIGH] CWE-416 CVE-2022-2998: Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacke
Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-4178P2HIGHCVSS 8.8fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4178 [HIGH] CWE-416 CVE-2022-4178: Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who had com
Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3654P2HIGHCVSS 8.8fixed in 107.0.5304.62≥ unspecified, < 107.0.5304.622022-11-01
CVE-2022-3654 [HIGH] CWE-416 CVE-2022-3654: Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potent
Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-6551P2HIGHCVSS 8.8fixed in 84.0.4147.125≥ unspecified, < 84.0.4147.1252020-09-21
CVE-2020-6551 [HIGH] CWE-416 CVE-2020-6551: Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potenti
Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6550P2HIGHCVSS 8.8fixed in 84.0.4147.125≥ unspecified, < 84.0.4147.1252020-09-21
CVE-2020-6550 [HIGH] CWE-416 CVE-2020-6550: Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to pot
Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0289P2HIGHCVSS 8.8fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0289 [HIGH] CWE-416 CVE-2022-0289: Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to
Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-4427P2HIGHCVSS 8.1fixed in 116.0.5845.110≥ 116.0.5845.110, < 116.0.5845.1102023-08-23
CVE-2023-4427 [HIGH] CWE-125 CVE-2023-4427: Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-21132P2CRITICALCVSS 9.6fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21132 [CRITICAL] CWE-1021 CVE-2021-21132: Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote att
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2023-2725P2HIGHCVSS 8.8fixed in 113.0.5672.126≥ 113.0.5672.126, < 113.0.5672.1262023-05-16
CVE-2023-2725 [HIGH] CWE-416 CVE-2023-2725: Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convin
Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4362P2HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4362 [HIGH] CWE-787 CVE-2023-4362: Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker
Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-2625P2HIGHCVSS 8.8fixed in 123.0.6312.58≥ 123.0.6312.58, < 123.0.6312.582024-03-20
CVE-2024-2625 [HIGH] CVE-2024-2625: Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to po
Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-6549P2HIGHCVSS 8.8fixed in 84.0.4147.125≥ unspecified, < 84.0.4147.1252020-09-21
CVE-2020-6549 [HIGH] CWE-416 CVE-2020-6549: Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potenti
Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2010-0655P3CRITICALCVSS 9.3PoC≤ 4.0.249.78v0.2.149.27+45 more2010-02-18
CVE-2010-0655 [CRITICAL] CWE-399 CVE-2010-0655: Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attacker
Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving the display of a blocked popup window during navigation to a different web site.
nvd
CVE-2025-5959P2HIGHCVSS 8.8fixed in 137.0.7151.103≥ 137.0.7151.103, < 137.0.7151.1032025-06-11
CVE-2025-5959 [HIGH] CWE-843 CVE-2025-5959: Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute a
Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2012-4908P3HIGHCVSS 7.5PoC≤ 18.0.10253062012-09-13
CVE-2012-4908 [HIGH] CWE-264 CVE-2012-4908: Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Polic
Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors involving a symlink.
nvd
CVE-2020-6541P3HIGHCVSS 8.8fixed in 84.0.4147.105≥ unspecified, < 84.0.4147.1052020-09-21
CVE-2020-6541 [HIGH] CWE-416 CVE-2020-6541: Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potent
Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30560P3HIGHCVSS 8.8fixed in 91.0.4472.164≥ unspecified, < 91.0.4472.1642021-08-03
CVE-2021-30560 [HIGH] CWE-416 CVE-2021-30560: Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to po
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd