cbcvebase.

Google Chrome vulnerabilities

5,463 known vulnerabilities affecting google/chrome.

Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65

Vulnerabilities

Page 9 of 274
CVE-2023-3217P3HIGHCVSS 8.8fixed in 114.0.5735.133≥ 114.0.5735.133, < 114.0.5735.1332023-06-13
CVE-2023-3217 [HIGH] CWE-416 CVE-2023-3217: Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potent Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4906P2HIGHCVSS 8.8fixed in 108.0.5359.71≥ 108.0.5359.71, < 108.0.5359.712023-07-29
CVE-2022-4906 [HIGH] CVE-2022-4906: Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 allowed a remote attac Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2174P3HIGHCVSS 8.8fixed in 122.0.6261.111≥ 122.0.6261.111, < 122.0.6261.1112024-03-06
CVE-2024-2174 [HIGH] CWE-787 CVE-2024-2174: Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacke Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-2314P3HIGHCVSS 8.8fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2314 [HIGH] CWE-122 CVE-2026-2314: Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2010-4577P3HIGHCVSS 7.5PoCfixed in 8.0.552.2242010-12-22
CVE-2010-4577 [HIGH] CWE-125 CVE-2010-4577: The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google C The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a
nvd
CVE-2017-5124P3MEDIUMCVSS 6.1PoCfixed in 62.0.3202.622018-02-07
CVE-2017-5124 [MEDIUM] CWE-79 CVE-2017-5124: Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
nvd
CVE-2025-0291P2HIGHCVSS 8.8fixed in 131.0.6778.264≥ 131.0.6778.264, < 131.0.6778.2642025-01-08
CVE-2025-0291 [HIGH] CWE-843 CVE-2025-0291: Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute a Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-3156P3HIGHCVSS 8.8fixed in 123.0.6312.105≥ 123.0.6312.105, < 123.0.6312.1052024-04-06
CVE-2024-3156 [HIGH] CWE-125 CVE-2024-3156: Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacke Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-0628P3HIGHCVSS 8.8fixed in 143.0.7499.192≥ 143.0.7499.192, < 143.0.7499.1922026-01-07
CVE-2026-0628 [HIGH] CWE-862 CVE-2026-0628: Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an a Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2024-0223P3HIGHCVSS 8.8fixed in 120.0.6099.199≥ 120.0.6099.199, < 120.0.6099.1992024-01-04
CVE-2024-0223 [HIGH] CWE-787 CVE-2024-0223: Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-2313P3HIGHCVSS 8.8fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2313 [HIGH] CWE-416 CVE-2026-2313: Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potential Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2008-5749P3MEDIUMCVSS 6.8PoCv1.0.154.362008-12-29
CVE-2008-5749 [MEDIUM] CWE-94 CVE-2008-5749: Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attacke Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI. NOTE: a third party disputes this issue, stating that Chrome "will ask for user permission" and "cannot launch the applet even [if] you have given out the permission.
nvd
CVE-2025-6191P3HIGHCVSS 8.8fixed in 137.0.7151.119≥ 137.0.7151.119, < 137.0.7151.1192025-06-18
CVE-2025-6191 [HIGH] CWE-472 CVE-2025-6191: Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potenti Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2019-13767P3HIGHCVSS 8.8fixed in 79.0.3945.88≥ unspecified, < 79.0.3945.882020-01-10
CVE-2019-13767 [HIGH] CWE-416 CVE-2019-13767: Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-13775P3CRITICALCVSS 9.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13775 [CRITICAL] CWE-416 CVE-2026-13775: Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had comp Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2024-6779P3CRITICALCVSS 9.6fixed in 126.0.6478.182≥ 126.0.6478.182, < 126.0.6478.1822024-07-16
CVE-2024-6779 [CRITICAL] CWE-787 CVE-2024-6779: Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4068P3HIGHCVSS 8.1fixed in 115.0.5790.170≥ 115.0.5790.170, < 115.0.5790.1702023-08-03
CVE-2023-4068 [HIGH] CWE-843 CVE-2023-4068: Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform a Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-10891P3HIGHCVSS 8.8fixed in 140.0.7339.207≥ 140.0.7339.207, < 140.0.7339.2072025-09-24
CVE-2025-10891 [HIGH] CWE-472 CVE-2025-10891: Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potenti Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-12036P3HIGHCVSS 8.8fixed in 142.0.7444.59fixed in 142.0.7444.60+1 more2025-11-06
CVE-2025-12036 [HIGH] CWE-125 CVE-2025-12036: Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3842P3HIGHCVSS 7.5fixed in 105.0.5195.125≥ unspecified, < 105.0.5195.1252023-01-02
CVE-2022-3842 [HIGH] CWE-416 CVE-2022-3842: Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who h Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase