cbcvebase.

Google Chrome vulnerabilities

5,463 known vulnerabilities affecting google/chrome.

Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65

Vulnerabilities

Page 8 of 274
CVE-2015-1265P3HIGHCVSS 7.5PoC≤ 42.0.2311.1522015-05-20
CVE-2015-1265 [HIGH] CVE-2015-1265: Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2026-13782P2CRITICALCVSS 10.0fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13782 [CRITICAL] CWE-416 CVE-2026-13782: Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-14104P2CRITICALCVSS 9.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14104 [CRITICAL] CWE-20 CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-12428P2HIGHCVSS 8.8fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12428 [HIGH] CWE-843 CVE-2025-12428: Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform ar Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2018-6084P3HIGHCVSS 7.8PoCfixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6084 [HIGH] CWE-20 CVE-2018-6084: Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359 Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via an executable file.
nvd
CVE-2014-7910P3HIGHCVSS 7.5PoC≤ 39.0.2171.452014-11-19
CVE-2014-7910 [HIGH] CVE-2014-7910: Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2026-14121P2CRITICALCVSS 9.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14121 [CRITICAL] CWE-416 CVE-2026-14121: Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attac Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2015-6763P3HIGHCVSS 7.5PoC≤ 45.0.2454.1012015-10-15
CVE-2015-6763 [HIGH] CVE-2015-6763: Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2017-5115P3HIGHCVSS 8.8fixed in 61.0.3163.792017-10-27
CVE-2017-5115 [HIGH] CWE-704 CVE-2017-5115: Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
nvd
CVE-2026-2315P2HIGHCVSS 8.8fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2315 [HIGH] CVE-2026-2315: Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote atta Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2017-15428P3HIGHCVSS 8.8fixed in 62.0.3202.94≥ unspecified, < 62.0.3202.942019-01-09
CVE-2017-15428 [HIGH] CWE-125 CVE-2017-15428: Insufficient data validation in V8 builtins string generator could lead to out of bounds read and wr Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3202.94 and allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2022-2480P3HIGHCVSS 8.8fixed in 103.0.5060.134≥ unspecified, < 103.0.5060.1342022-07-28
CVE-2022-2480 [HIGH] CWE-416 CVE-2022-2480: Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attac Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21118P3HIGHCVSS 8.8fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21118 [HIGH] CWE-119 CVE-2021-21118: Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2022-1232P3HIGHCVSS 8.8fixed in 100.0.4896.75≥ unspecified, < 100.0.4896.752022-07-25
CVE-2022-1232 [HIGH] CWE-843 CVE-2022-1232: Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-2723P3HIGHCVSS 8.8fixed in 113.0.5672.126≥ 113.0.5672.126, < 113.0.5672.1262023-05-16
CVE-2023-2723 [HIGH] CWE-416 CVE-2023-2723: Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who ha Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-3833P3HIGHCVSS 8.8fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3833 [HIGH] CWE-374 CVE-2024-3833: Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker t Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2018-6130P3MEDIUMCVSS 6.5PoCfixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6130 [MEDIUM] CWE-125 CVE-2018-6130: Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a re Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2018-6129P3MEDIUMCVSS 6.5PoCfixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6129 [MEDIUM] CWE-125 CVE-2018-6129: Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacke Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2023-3215P3HIGHCVSS 8.8fixed in 114.0.5735.133≥ 114.0.5735.133, < 114.0.5735.1332023-06-13
CVE-2023-3215 [HIGH] CWE-416 CVE-2023-3215: Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to poten Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2173P3HIGHCVSS 8.8fixed in 122.0.6261.111≥ 122.0.6261.111, < 122.0.6261.1112024-03-06
CVE-2024-2173 [HIGH] CWE-787 CVE-2024-2173: Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase