cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 77 of 292
CVE-2023-0928P3HIGHCVSS 8.8fixed in 110.0.5481.177≥ 110.0.5481.177, < 110.0.5481.1772023-02-22
CVE-2023-0928 [HIGH] CWE-416 CVE-2023-0928: Use after free in SwiftShader in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to Use after free in SwiftShader in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4439P3HIGHCVSS 8.8fixed in 108.0.5359.124≥ unspecified, < 108.0.5359.1242022-12-14
CVE-2022-4439 [HIGH] CWE-416 CVE-2022-4439: Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: High)
nvd
CVE-2022-3305P3HIGHCVSS 8.8fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3305 [HIGH] CWE-416 CVE-2022-3305: Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attack Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0929P3HIGHCVSS 8.8fixed in 110.0.5481.177≥ 110.0.5481.177, < 110.0.5481.1772023-02-22
CVE-2023-0929 [HIGH] CWE-416 CVE-2023-0929: Use after free in Vulkan in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to poten Use after free in Vulkan in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0696P3HIGHCVSS 8.8fixed in 110.0.5481.77≥ unspecified, < 110.0.5481.772023-02-07
CVE-2023-0696 [HIGH] CWE-843 CVE-2023-0696: Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6998P3HIGHCVSS 8.8fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-6998 [HIGH] CWE-416 CVE-2024-6998: Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker w Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-5844P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5844 [HIGH] CWE-787 CVE-2024-5844: Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-7000P3HIGHCVSS 8.8fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-7000 [HIGH] CWE-416 CVE-2024-7000: Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convince Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-0812P3HIGHCVSS 8.8fixed in 121.0.6167.85≥ 121.0.6167.85, < 121.0.6167.852024-01-24
CVE-2024-0812 [HIGH] CVE-2024-0812: Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remo Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-0807P3HIGHCVSS 8.8fixed in 121.0.6167.85≥ 121.0.6167.85, < 121.0.6167.852024-01-24
CVE-2024-0807 [HIGH] CWE-416 CVE-2024-0807: Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to pot Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6773P3HIGHCVSS 8.8fixed in 126.0.6478.182≥ 126.0.6478.182, < 126.0.6478.1822024-07-16
CVE-2024-6773 [HIGH] CWE-787 CVE-2024-6773: Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacke Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-9120P3HIGHCVSS 8.8fixed in 129.0.6668.70≥ 129.0.6668.70, < 129.0.6668.702024-09-25
CVE-2024-9120 [HIGH] CWE-416 CVE-2024-9120: Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3729P3HIGHCVSS 8.8fixed in 115.0.5790.98≥ 115.0.5790.131, < 115.0.5790.1312023-08-01
CVE-2023-3729 [HIGH] CWE-416 CVE-2023-3729: Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chromium security severity: High)
nvd
CVE-2025-0436P3HIGHCVSS 8.8fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0436 [HIGH] CWE-472 CVE-2025-0436: Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potent Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-8637P3HIGHCVSS 8.8fixed in 128.0.6613.137≥ 128.0.6613.137, < 128.0.6613.1372024-09-11
CVE-2024-8637 [HIGH] CWE-416 CVE-2024-8637: Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4452P3HIGHCVSS 8.8fixed in 107.0.5304.62≥ 107.0.5304.62, < 107.0.5304.622023-08-25
CVE-2022-4452 [HIGH] CVE-2022-4452: Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote atta Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-8638P3HIGHCVSS 8.8fixed in 128.0.6613.137≥ 128.0.6613.137, < 128.0.6613.1372024-09-11
CVE-2024-8638 [HIGH] CWE-843 CVE-2024-8638: Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potential Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-1914P3HIGHCVSS 8.8fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-03-05
CVE-2025-1914 [HIGH] CWE-125 CVE-2025-1914: Out of bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to perfor Out of bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-9957P3HIGHCVSS 8.8fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9957 [HIGH] CWE-416 CVE-2024-9957: Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who co Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-9961P3HIGHCVSS 8.8fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9961 [HIGH] CWE-416 CVE-2024-9961: Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote att Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase