Google Chrome vulnerabilities
5,463 known vulnerabilities affecting google/chrome.
Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65
Vulnerabilities
Page 8 of 274
CVE-2015-1265P3HIGHCVSS 7.5PoC≤ 42.0.2311.1522015-05-20
CVE-2015-1265 [HIGH] CVE-2015-1265: Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2026-13782P2CRITICALCVSS 10.0fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13782 [CRITICAL] CWE-416 CVE-2026-13782: Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-14104P2CRITICALCVSS 9.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14104 [CRITICAL] CWE-20 CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-12428P2HIGHCVSS 8.8fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12428 [HIGH] CWE-843 CVE-2025-12428: Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform ar
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2018-6084P3HIGHCVSS 7.8PoCfixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6084 [HIGH] CWE-20 CVE-2018-6084: Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359
Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via an executable file.
nvd
CVE-2014-7910P3HIGHCVSS 7.5PoC≤ 39.0.2171.452014-11-19
CVE-2014-7910 [HIGH] CVE-2014-7910: Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2026-14121P2CRITICALCVSS 9.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14121 [CRITICAL] CWE-416 CVE-2026-14121: Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attac
Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2015-6763P3HIGHCVSS 7.5PoC≤ 45.0.2454.1012015-10-15
CVE-2015-6763 [HIGH] CVE-2015-6763: Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2017-5115P3HIGHCVSS 8.8fixed in 61.0.3163.792017-10-27
CVE-2017-5115 [HIGH] CWE-704 CVE-2017-5115: Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to
Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
nvd
CVE-2026-2315P2HIGHCVSS 8.8fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2315 [HIGH] CVE-2026-2315: Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote atta
Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2017-15428P3HIGHCVSS 8.8fixed in 62.0.3202.94≥ unspecified, < 62.0.3202.942019-01-09
CVE-2017-15428 [HIGH] CWE-125 CVE-2017-15428: Insufficient data validation in V8 builtins string generator could lead to out of bounds read and wr
Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3202.94 and allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2022-2480P3HIGHCVSS 8.8fixed in 103.0.5060.134≥ unspecified, < 103.0.5060.1342022-07-28
CVE-2022-2480 [HIGH] CWE-416 CVE-2022-2480: Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attac
Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21118P3HIGHCVSS 8.8fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21118 [HIGH] CWE-119 CVE-2021-21118: Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker
Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2022-1232P3HIGHCVSS 8.8fixed in 100.0.4896.75≥ unspecified, < 100.0.4896.752022-07-25
CVE-2022-1232 [HIGH] CWE-843 CVE-2022-1232: Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentiall
Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-2723P3HIGHCVSS 8.8fixed in 113.0.5672.126≥ 113.0.5672.126, < 113.0.5672.1262023-05-16
CVE-2023-2723 [HIGH] CWE-416 CVE-2023-2723: Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who ha
Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-3833P3HIGHCVSS 8.8fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3833 [HIGH] CWE-374 CVE-2024-3833: Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker t
Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2018-6130P3MEDIUMCVSS 6.5PoCfixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6130 [MEDIUM] CWE-125 CVE-2018-6130: Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a re
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2018-6129P3MEDIUMCVSS 6.5PoCfixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6129 [MEDIUM] CWE-125 CVE-2018-6129: Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacke
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2023-3215P3HIGHCVSS 8.8fixed in 114.0.5735.133≥ 114.0.5735.133, < 114.0.5735.1332023-06-13
CVE-2023-3215 [HIGH] CWE-416 CVE-2023-3215: Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to poten
Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2173P3HIGHCVSS 8.8fixed in 122.0.6261.111≥ 122.0.6261.111, < 122.0.6261.1112024-03-06
CVE-2024-2173 [HIGH] CWE-787 CVE-2024-2173: Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker
Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd