Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 78 of 292
CVE-2024-9123P3HIGHCVSS 8.8fixed in 129.0.6668.70≥ 129.0.6668.70, < 129.0.6668.702024-09-25
CVE-2024-9123 [HIGH] CWE-472 CVE-2024-9123: Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perfor
Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-3174P3HIGHCVSS 8.8fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052024-07-16
CVE-2024-3174 [HIGH] CWE-79 CVE-2024-3174: Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacke
Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-2137P3HIGHCVSS 8.8fixed in 134.0.6998.88≥ 134.0.6998.88, < 134.0.6998.882025-03-10
CVE-2025-2137 [HIGH] CWE-125 CVE-2025-2137: Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perfor
Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-0762P3HIGHCVSS 8.8fixed in 132.0.6834.159≥ 132.0.6834.159, < 132.0.6834.1592025-01-29
CVE-2025-0762 [HIGH] CWE-416 CVE-2025-0762: Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to pot
Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2024-8639P3HIGHCVSS 8.8fixed in 128.0.6613.137≥ 128.0.6613.137, < 128.0.6613.1372024-09-11
CVE-2024-8639 [HIGH] CWE-416 CVE-2024-8639: Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote atta
Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-11112P3HIGHCVSS 8.8fixed in 131.0.6778.69≥ 131.0.6778.69, < 131.0.6778.692024-11-12
CVE-2024-11112 [HIGH] CWE-416 CVE-2024-11112: Use after free in Media in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker
Use after free in Media in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-3176P3HIGHCVSS 8.8fixed in 117.0.5938.62≥ 117.0.5938.62, < 117.0.5938.622024-07-16
CVE-2024-3176 [HIGH] CWE-787 CVE-2024-3176: Out of bounds write in SwiftShader in Google Chrome prior to 117.0.5938.62 allowed a remote attacker
Out of bounds write in SwiftShader in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-3168P3HIGHCVSS 8.8fixed in 122.0.6261.57≥ 122.0.6261.57, < 122.0.6261.572024-07-16
CVE-2024-3168 [HIGH] CWE-416 CVE-2024-3168: Use after free in DevTools in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to pote
Use after free in DevTools in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-9959P3HIGHCVSS 8.8fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9959 [HIGH] CWE-416 CVE-2024-9959: Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had
Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2024-3171P3HIGHCVSS 8.8fixed in 122.0.6261.57≥ 122.0.6261.57, < 122.0.6261.572024-07-16
CVE-2024-3171 [HIGH] CWE-416 CVE-2024-3171: Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker wh
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
nvd
CVE-2026-5292P3HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5292 [HIGH] CWE-125 CVE-2026-5292: Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker t
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11071P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11071 [HIGH] CWE-416 CVE-2026-11071: Use after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker wh
Use after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-1300P3CRITICALCVSS 10.0fixed in 10.0.648.2052011-04-15
CVE-2011-1300 [CRITICAL] CWE-189 CVE-2011-1300: The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the Web
The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox 4.x before 4.0.1 on Windows and in the GPU process in Google Chrome before 10.0.648.205 on Windows, allows remote attackers to execute arbitrary code via unspecifi
nvd
CVE-2026-7930P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7930 [HIGH] CWE-20 CVE-2026-7930: Insufficient validation of untrusted input in Cookies in Google Chrome prior to 148.0.7778.96 allowe
Insufficient validation of untrusted input in Cookies in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2023-4070P3HIGHCVSS 8.1fixed in 115.0.5790.170≥ 115.0.5790.170, < 115.0.5790.1702023-08-03
CVE-2023-4070 [HIGH] CWE-843 CVE-2023-4070: Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform a
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13803P3HIGHCVSS 8.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13803 [HIGH] CWE-843 CVE-2026-13803: Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who
Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13829P3HIGHCVSS 8.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13829 [HIGH] CWE-20 CVE-2026-13829: Insufficient validation of untrusted input in Settings in Google Chrome on Windows prior to 150.0.78
Insufficient validation of untrusted input in Settings in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13834P3HIGHCVSS 8.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13834 [HIGH] CWE-20 CVE-2026-13834: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10920P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10920 [HIGH] CWE-20 CVE-2026-10920: Insufficient validation of untrusted input in WebShare in Google Chrome on Mac prior to 149.0.7827.5
Insufficient validation of untrusted input in WebShare in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13951P3HIGHCVSS 8.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13951 [HIGH] CWE-693 CVE-2026-13951: Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote atta
Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd