cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 76 of 292
CVE-2022-3652P3HIGHCVSS 8.8fixed in 107.0.5304.62≥ unspecified, < 107.0.5304.622022-11-01
CVE-2022-3652 [HIGH] CWE-843 CVE-2022-3652: Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3888P3HIGHCVSS 8.8fixed in 107.0.5304.106≥ unspecified, < 107.0.5304.1062022-11-09
CVE-2022-3888 [HIGH] CWE-416 CVE-2022-3888: Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to po Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0472P3HIGHCVSS 8.8fixed in 109.0.5414.119≥ unspecified, < 109.0.5414.1192023-01-30
CVE-2023-0472 [HIGH] CWE-416 CVE-2023-0472: Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to poten Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3304P3HIGHCVSS 8.8fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3304 [HIGH] CWE-416 CVE-2022-3304: Use after free in CSS in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potential Use after free in CSS in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-4318P3HIGHCVSS 8.8fixed in 94.0.4606.54≥ 94.0.4606.54, < 94.0.4606.542023-07-29
CVE-2021-4318 [HIGH] CVE-2021-4318: Object corruption in Blink in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to poten Object corruption in Blink in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0473P3HIGHCVSS 8.8fixed in 109.0.5414.119≥ unspecified, < 109.0.5414.1192023-01-30
CVE-2023-0473 [HIGH] CWE-843 CVE-2023-0473: Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attack Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1214P3HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1214 [HIGH] CWE-843 CVE-2023-1214: Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4181P3HIGHCVSS 8.8fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4181 [HIGH] CWE-416 CVE-2022-4181: Use after free in Forms in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potenti Use after free in Forms in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4437P3HIGHCVSS 8.8fixed in 108.0.5359.124≥ unspecified, < 108.0.5359.1242022-12-14
CVE-2022-4437 [HIGH] CWE-416 CVE-2022-4437: Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to pot Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6707P3HIGHCVSS 8.8fixed in 120.0.6099.109≥ 120.0.6099.109, < 120.0.6099.1092023-12-14
CVE-2023-6707 [HIGH] CWE-416 CVE-2023-6707: Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentia Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-3307P3HIGHCVSS 8.8fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3307 [HIGH] CWE-362 CVE-2022-3307: Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potenti Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5159P3HIGHCVSS 8.8fixed in 125.0.6422.76≥ 125.0.6422.76, < 125.0.6422.762024-05-22
CVE-2024-5159 [HIGH] CWE-125 CVE-2024-5159: Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to p Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6706P3HIGHCVSS 8.8fixed in 120.0.6099.109≥ 120.0.6099.109, < 120.0.6099.1092023-12-14
CVE-2023-6706 [HIGH] CWE-416 CVE-2023-6706: Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convi Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0931P3HIGHCVSS 8.8fixed in 110.0.5481.177≥ 110.0.5481.177, < 110.0.5481.1772023-02-22
CVE-2023-0931 [HIGH] CWE-416 CVE-2023-0931: Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potent Use after free in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3450P3HIGHCVSS 8.8fixed in 106.0.5249.119≥ unspecified, < 106.0.5249.1192022-11-09
CVE-2022-3450 [HIGH] CWE-416 CVE-2022-3450: Use after free in Peer Connection in Google Chrome prior to 106.0.5249.119 allowed a remote attacker Use after free in Peer Connection in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4436P3HIGHCVSS 8.8fixed in 108.0.5359.124≥ unspecified, < 108.0.5359.1242022-12-14
CVE-2022-4436 [HIGH] CWE-416 CVE-2022-4436: Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-30603P3HIGHCVSS 7.5fixed in 92.0.4515.159≥ unspecified, < 92.0.4515.1592021-08-26
CVE-2021-30603 [HIGH] CWE-362 CVE-2021-30603: Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potential Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-3315P3HIGHCVSS 8.8fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3315 [HIGH] CWE-843 CVE-2022-3315: Type confusion in Blink in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potenti Type confusion in Blink in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-3306P3HIGHCVSS 8.8fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3306 [HIGH] CWE-416 CVE-2022-3306: Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attack Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0128P3HIGHCVSS 8.8fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0128 [HIGH] CWE-416 CVE-2023-0128: Use after free in Overview Mode in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed a remot Use after free in Overview Mode in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase