Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 84 of 292
CVE-2026-10003P3HIGHCVSS 7.5fixed in 148.0.7778.215fixed in 148.0.7778.216+1 more2026-05-28
CVE-2026-10003 [HIGH] CWE-416 CVE-2026-10003: Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convi
Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14426P3HIGHCVSS 7.5fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14426 [HIGH] CWE-416 CVE-2026-14426: Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11690P3HIGHCVSS 7.5fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11690 [HIGH] CWE-125 CVE-2026-11690: Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remo
Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11694P3HIGHCVSS 7.5fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11694 [HIGH] CWE-416 CVE-2026-11694: Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker w
Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11644P3HIGHCVSS 7.5fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11644 [HIGH] CWE-416 CVE-2026-11644: Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who co
Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)
nvd
CVE-2018-17466P3HIGHCVSS 8.8fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17466 [HIGH] CWE-125 CVE-2018-17466: Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker
Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2022-0466P3CRITICALCVSS 9.6fixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802022-04-05
CVE-2022-0466 [CRITICAL] CVE-2022-0466: Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed a
Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6385P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6385 [HIGH] CWE-754 CVE-2020-6385: Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote a
Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2020-6415P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6415 [HIGH] CWE-787 CVE-2020-6415: Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote a
Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6060P3HIGHCVSS 8.8fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6060 [HIGH] CWE-416 CVE-2018-6060: Use after free in WebAudio in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to pote
Use after free in WebAudio in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6124P3HIGHCVSS 8.8fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6124 [HIGH] CWE-704 CVE-2018-6124: Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote a
Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
nvd
CVE-2020-6414P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6414 [HIGH] CVE-2020-6414: Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a re
Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2019-5817P3HIGHCVSS 8.8fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5817 [HIGH] CWE-787 CVE-2019-5817: Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote at
Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6387P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6387 [HIGH] CWE-787 CVE-2020-6387: Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to po
Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.
nvd
CVE-2020-6398P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6398 [HIGH] CWE-908 CVE-2020-6398: Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker
Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2021-37972P3HIGHCVSS 8.8fixed in 94.0.4606.54≥ unspecified, < 94.0.4606.542021-10-08
CVE-2021-37972 [HIGH] CWE-125 CVE-2021-37972: Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker
Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5808P3HIGHCVSS 8.8fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5808 [HIGH] CWE-416 CVE-2019-5808: Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potenti
Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6407P3HIGHCVSS 8.8fixed in 80.0.3987.122≥ unspecified, < 80.0.3987.1222020-02-27
CVE-2020-6407 [HIGH] CWE-787 CVE-2020-6407: Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote atta
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6389P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6389 [HIGH] CWE-787 CVE-2020-6389: Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to po
Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.
nvd
CVE-2020-6409P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6409 [HIGH] CVE-2020-6409: Inappropriate implementation in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote atta
Inappropriate implementation in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker who convinced the user to enter a URI to bypass navigation restrictions via a crafted domain name.
nvd