Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 82 of 292
CVE-2026-6297P3HIGHCVSS 8.3fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6297 [HIGH] CWE-416 CVE-2026-6297: Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged
Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-15122P3HIGHCVSS 8.3fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15122 [HIGH] CWE-20 CVE-2026-15122: Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871
Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11237P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11237 [HIGH] CWE-20 CVE-2026-11237: Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed
Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-12029P3HIGHCVSS 8.3fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12029 [HIGH] CWE-416 CVE-2026-12029: Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacke
Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-15120P3HIGHCVSS 8.3fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15120 [HIGH] CWE-416 CVE-2026-15120: Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9994P3HIGHCVSS 8.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9994 [HIGH] CWE-416 CVE-2026-9994: Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8574P3HIGHCVSS 8.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8574 [HIGH] CWE-416 CVE-2026-8574: Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-12034P3HIGHCVSS 8.3fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12034 [HIGH] CWE-20 CVE-2026-12034: Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-11679P3HIGHCVSS 8.3fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11679 [HIGH] CWE-416 CVE-2026-11679: Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attack
Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11700P3HIGHCVSS 8.3fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11700 [HIGH] CWE-416 CVE-2026-11700: Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had
Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13281P3HIGHCVSS 8.3fixed in 149.0.7827.200≥ 149.0.7827.201, < 149.0.7827.2012026-06-25
CVE-2026-13281 [HIGH] CWE-472 CVE-2026-13281: Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-9988P3HIGHCVSS 8.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9988 [HIGH] CWE-416 CVE-2026-9988: Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker
Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13806P3HIGHCVSS 8.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13806 [HIGH] CWE-20 CVE-2026-13806: Insufficient validation of untrusted input in Accessibility in Google Chrome prior to 150.0.7871.47
Insufficient validation of untrusted input in Accessibility in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11011P3HIGHCVSS 8.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11011 [HIGH] CWE-602 CVE-2026-11011: Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed
Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2017-5053P3CRITICALCVSS 9.6fixed in 57.0.2987.133fixed in 57.0.2987.1322017-10-27
CVE-2017-5053 [CRITICAL] CWE-125 CVE-2017-5053: An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf.
nvd
CVE-2010-0645P3CRITICALCVSS 9.3≤ 4.0.249.78v0.2.149.27+45 more2010-02-18
CVE-2010-0645 [CRITICAL] CWE-189 CVE-2010-0645: Multiple integer overflows in factory.cc in Google V8 before r3560, as used in Google Chrome before
Multiple integer overflows in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.
nvd
CVE-2026-7346P3HIGHCVSS 8.1fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7346 [HIGH] CWE-119 CVE-2026-7346: Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attac
Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13639P3HIGHCVSS 8.1fixed in 143.0.7499.40≥ 143.0.7499.41, < 143.0.7499.412025-12-02
CVE-2025-13639 [HIGH] CWE-79 CVE-2025-13639: Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote atta
Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14122P3HIGHCVSS 8.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14122 [HIGH] CWE-20 CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 15
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2020-15963P3CRITICALCVSS 9.6fixed in 85.0.4183.121≥ unspecified, < 85.0.4183.1212020-09-21
CVE-2020-15963 [CRITICAL] CVE-2020-15963: Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an att
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd