Google Chrome vulnerabilities

3,975 known vulnerabilities affecting google/chrome.

Total CVEs
3,975
CISA KEV
74
actively exploited
Public exploits
63
Exploited in wild
65
Severity breakdown
CRITICAL297HIGH2024MEDIUM1626LOW17UNKNOWN11

Vulnerabilities

Page 76 of 199
CVE-2021-30533MEDIUMCVSS 6.5KEVfixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30533 [MEDIUM] CWE-863 CVE-2021-30533: Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a rem Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
nvd
CVE-2021-30537MEDIUMCVSS 4.3fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30537 [MEDIUM] CWE-863 CVE-2021-30537: Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote a Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.
nvd
CVE-2021-30534MEDIUMCVSS 6.5fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30534 [MEDIUM] CWE-863 CVE-2021-30534: Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a re Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-30538MEDIUMCVSS 4.3fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30538 [MEDIUM] CWE-863 CVE-2021-30538: Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 al Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2021-30531MEDIUMCVSS 6.5fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30531 [MEDIUM] CVE-2021-30531: Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 al Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2021-30508HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30508 [HIGH] CWE-787 CVE-2021-30508: Heap buffer overflow in Media Feeds in Google Chrome prior to 90.0.4430.212 allowed an attacker who Heap buffer overflow in Media Feeds in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to enable certain features in Chrome to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30517HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30517 [HIGH] CWE-843 CVE-2021-30517: Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30513HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30513 [HIGH] CWE-843 CVE-2021-30513: Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30506HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30506 [HIGH] CWE-74 CVE-2021-30506: Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page.
nvd
CVE-2021-30515HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30515 [HIGH] CWE-416 CVE-2021-30515: Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to pote Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30511HIGHCVSS 8.1fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30511 [HIGH] CWE-125 CVE-2021-30511: Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who con Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2021-30520HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30520 [HIGH] CWE-416 CVE-2021-30520: Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convince Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30509HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30509 [HIGH] CWE-787 CVE-2021-30509: Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who con Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page and a crafted Chrome extension.
nvd
CVE-2021-30518HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30518 [HIGH] CWE-787 CVE-2021-30518: Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacke Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30516HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30516 [HIGH] CWE-787 CVE-2021-30516: Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker wh Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30510HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30510 [HIGH] CWE-416 CVE-2021-30510: Use after free in Aura in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentia Use after free in Aura in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30507HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30507 [HIGH] CWE-829 CVE-2021-30507: Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2021-30519HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30519 [HIGH] CWE-416 CVE-2021-30519: Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious payments app to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30512HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30512 [HIGH] CWE-416 CVE-2021-30512: Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker wh Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30514HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30514 [HIGH] CWE-416 CVE-2021-30514: Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd