Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 90 of 292
CVE-2021-30627P3HIGHCVSS 8.8fixed in 93.0.4577.82≥ unspecified, < 93.0.4577.822021-10-08
CVE-2021-30627 [HIGH] CWE-843 CVE-2021-30627: Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to p
Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0808P3HIGHCVSS 8.8fixed in 99.0.4844.51≥ unspecified, < 99.0.4844.512022-04-05
CVE-2022-0808 [HIGH] CWE-416 CVE-2022-0808: Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remo
Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in a series of user interaction to potentially exploit heap corruption via user interactions.
nvd
CVE-2022-1496P3HIGHCVSS 8.8fixed in 101.0.4951.41≥ unspecified, < 101.0.4951.412022-07-26
CVE-2022-1496 [HIGH] CWE-416 CVE-2022-1496: Use after free in File Manager in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to
Use after free in File Manager in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via specific and direct user interaction.
nvd
CVE-2023-5187P3HIGHCVSS 8.8fixed in 117.0.5938.132≥ 117.0.5938.132, < 117.0.5938.1322023-09-28
CVE-2023-5187 [HIGH] CWE-416 CVE-2023-5187: Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convin
Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3373P3HIGHCVSS 8.8fixed in 106.0.5249.91≥ unspecified, < 106.0.5249.912022-11-01
CVE-2022-3373 [HIGH] CWE-787 CVE-2022-3373: Out of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to perfo
Out of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4356P3HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4356 [HIGH] CWE-416 CVE-2023-4356: Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has co
Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-1141P3HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1141 [HIGH] CWE-416 CVE-2022-1141: Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who
Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.
nvd
CVE-2022-2859P3HIGHCVSS 8.8fixed in 104.0.5112.101≥ unspecified, < 104.0.5112.1012022-09-26
CVE-2022-2859 [HIGH] CWE-416 CVE-2022-2859: Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker
Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2022-3446P3HIGHCVSS 8.8fixed in 106.0.5249.119≥ unspecified, < 106.0.5249.1192022-11-09
CVE-2022-3446 [HIGH] CWE-787 CVE-2022-3446: Heap buffer overflow in WebSQL in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to
Heap buffer overflow in WebSQL in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-2930P3HIGHCVSS 8.8fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-05-30
CVE-2023-2930 [HIGH] CWE-416 CVE-2023-2930: Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinc
Use after free in Extensions in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-1633P3HIGHCVSS 8.8fixed in 101.0.4951.64≥ unspecified, < 101.0.4951.642022-07-26
CVE-2022-1633 [HIGH] CWE-416 CVE-2022-1633: Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote a
Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific user interactions.
nvd
CVE-2024-1674P3HIGHCVSS 8.8fixed in 122.0.6261.57≥ 122.0.6261.57, < 122.0.6261.572024-02-21
CVE-2024-1674 [HIGH] CVE-2024-1674: Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-0610P3HIGHCVSS 8.8fixed in 98.0.4758.102≥ unspecified, < 98.0.4758.1022022-04-05
CVE-2022-0610 [HIGH] CWE-787 CVE-2022-0610: Inappropriate implementation in Gamepad API in Google Chrome prior to 98.0.4758.102 allowed a remote
Inappropriate implementation in Gamepad API in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-0699P3HIGHCVSS 8.8fixed in 110.0.5481.77≥ unspecified, < 110.0.5481.772023-02-07
CVE-2023-0699 [HIGH] CWE-416 CVE-2023-0699: Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potential
Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)
nvd
CVE-2022-2613P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2613 [HIGH] CWE-416 CVE-2022-2613: Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attack
Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2024-7973P3HIGHCVSS 8.8fixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-7973 [HIGH] CWE-122 CVE-2024-7973: Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to
Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. (Chromium security severity: Medium)
nvd
CVE-2021-4100P3HIGHCVSS 8.8fixed in 96.0.4664.110≥ unspecified, < 96.0.4664.1102022-02-11
CVE-2021-4100 [HIGH] CWE-125 CVE-2021-4100: Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to
Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-3887P3HIGHCVSS 8.8fixed in 107.0.5304.106≥ unspecified, < 107.0.5304.1062022-11-09
CVE-2022-3887 [HIGH] CWE-416 CVE-2022-3887: Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to
Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0701P3HIGHCVSS 8.8fixed in 110.0.5481.77≥ unspecified, < 110.0.5481.772023-02-07
CVE-2023-0701 [HIGH] CWE-787 CVE-2023-0701: Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who
Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interaction . (Chromium security severity: Medium)
nvd
CVE-2023-0702P3HIGHCVSS 8.8fixed in 110.0.5481.77≥ unspecified, < 110.0.5481.772023-02-07
CVE-2023-0702 [HIGH] CWE-843 CVE-2023-0702: Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker wh
Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd