Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 71 of 292
CVE-2020-16016P3CRITICALCVSS 9.6fixed in 86.0.4240.193≥ unspecified, < 86.0.4240.1932021-01-08
CVE-2020-16016 [CRITICAL] CVE-2020-16016: Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attack
Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2017-5078P3HIGHCVSS 8.8fixed in 59.0.3071.862017-10-27
CVE-2017-5078 [HIGH] CVE-2017-5078: Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.
Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space charac
nvd
CVE-2017-5130P3HIGHCVSS 8.8fixed in 62.0.3202.622018-02-07
CVE-2017-5130 [HIGH] CWE-787 CVE-2017-5130: An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
nvd
CVE-2020-10531P3HIGHCVSS 8.8fixed in 80.0.3987.1222020-03-12
CVE-2020-10531 [HIGH] CWE-190 CVE-2020-10531: An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An int
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
nvd
CVE-2020-6449P3HIGHCVSS 8.8fixed in 80.0.3987.149≥ unspecified, < 80.0.3987.1492020-03-23
CVE-2020-6449 [HIGH] CWE-416 CVE-2020-6449: Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potenti
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6518P3HIGHCVSS 8.8fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6518 [HIGH] CWE-416 CVE-2020-6518: Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker w
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6427P3HIGHCVSS 8.8fixed in 80.0.3987.149≥ unspecified, < 80.0.3987.1492020-03-23
CVE-2020-6427 [HIGH] CWE-787 CVE-2020-6427: Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potenti
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6422P3HIGHCVSS 8.8fixed in 80.0.3987.149≥ unspecified, < 80.0.3987.1492020-03-23
CVE-2020-6422 [HIGH] CWE-787 CVE-2020-6422: Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potenti
Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6429P3HIGHCVSS 8.8fixed in 80.0.3987.149≥ unspecified, < 80.0.3987.1492020-03-23
CVE-2020-6429 [HIGH] CWE-787 CVE-2020-6429: Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potenti
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6428P3HIGHCVSS 8.8fixed in 80.0.3987.149≥ unspecified, < 80.0.3987.1492020-03-23
CVE-2020-6428 [HIGH] CWE-787 CVE-2020-6428: Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potenti
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6382P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6382 [HIGH] CWE-843 CVE-2020-6382: Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to pot
Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30602P3HIGHCVSS 8.8fixed in 92.0.4515.159≥ unspecified, < 92.0.4515.1592021-08-26
CVE-2021-30602 [HIGH] CWE-416 CVE-2021-30602: Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a
Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6388P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6388 [HIGH] CWE-362 CVE-2020-6388: Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to
Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30592P3HIGHCVSS 8.8fixed in 92.0.4515.131≥ unspecified, < 92.0.4515.1312021-08-26
CVE-2021-30592 [HIGH] CWE-787 CVE-2021-30592: Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who co
Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2020-6416P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6416 [HIGH] CWE-20 CVE-2020-6416: Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote atta
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-15401P3HIGHCVSS 8.8fixed in 62.0.3202.62≥ unspecified, < 62.0.3202.622019-01-09
CVE-2017-15401 [HIGH] CWE-125 CVE-2017-15401: A memory corruption bug in WebAssembly could lead to out of bounds read and write through V8 in WebA
A memory corruption bug in WebAssembly could lead to out of bounds read and write through V8 in WebAssembly in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2019-5787P3HIGHCVSS 8.8fixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5787 [HIGH] CWE-416 CVE-2019-5787: Use-after-garbage-collection in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attack
Use-after-garbage-collection in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5831P3HIGHCVSS 8.8fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5831 [HIGH] CWE-787 CVE-2019-5831: Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to pot
Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13730P3HIGHCVSS 8.8fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13730 [HIGH] CWE-787 CVE-2019-13730: Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to pot
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2008-6996P4MEDIUMCVSS 5.0PoCv0.2.149.272009-08-19
CVE-2008-6996 [MEDIUM] CVE-2008-6996: Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which mak
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references an executable file, possibly related to the "ask where to save each file before downloading" setting.
nvd