Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 91 of 292
CVE-2022-3200P3HIGHCVSS 8.8fixed in 105.0.5195.125≥ unspecified, < 105.0.5195.1252022-09-26
CVE-2022-3200 [HIGH] CWE-787 CVE-2022-3200: Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker
Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0138P3HIGHCVSS 8.8fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0138 [HIGH] CWE-787 CVE-2023-0138: Heap buffer overflow in libphonenumber in Google Chrome prior to 109.0.5414.74 allowed a remote atta
Heap buffer overflow in libphonenumber in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-3043P3HIGHCVSS 8.8fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3043 [HIGH] CWE-787 CVE-2022-3043: Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed
Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-0703P3HIGHCVSS 8.8fixed in 110.0.5481.77≥ unspecified, < 110.0.5481.772023-02-07
CVE-2023-0703 [HIGH] CWE-843 CVE-2023-0703: Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who con
Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)
nvd
CVE-2022-3653P3HIGHCVSS 8.8fixed in 107.0.5304.62≥ unspecified, < 107.0.5304.622022-11-01
CVE-2022-3653 [HIGH] CWE-787 CVE-2022-3653: Heap buffer overflow in Vulkan in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to
Heap buffer overflow in Vulkan in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3598P3HIGHCVSS 8.8fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-07-28
CVE-2023-3598 [HIGH] CWE-787 CVE-2023-3598: Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attac
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0930P3HIGHCVSS 8.8fixed in 110.0.5481.177≥ 110.0.5481.177, < 110.0.5481.1772023-02-22
CVE-2023-0930 [HIGH] CWE-787 CVE-2023-0930: Heap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to
Heap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4368P3HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4368 [HIGH] CVE-2023-4368: Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4193P3HIGHCVSS 8.8fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4193 [HIGH] CVE-2022-4193: Insufficient policy enforcement in File System API in Google Chrome prior to 108.0.5359.71 allowed a
Insufficient policy enforcement in File System API in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4438P3HIGHCVSS 8.8fixed in 108.0.5359.124≥ unspecified, < 108.0.5359.1242022-12-14
CVE-2022-4438 [HIGH] CWE-416 CVE-2022-4438: Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker wh
Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0136P3HIGHCVSS 8.8fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0136 [HIGH] CVE-2023-0136: Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74
Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to execute incorrect security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4194P3HIGHCVSS 8.8fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4194 [HIGH] CWE-416 CVE-2022-4194: Use after free in Accessibility in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to
Use after free in Accessibility in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-3198P3HIGHCVSS 8.8fixed in 105.0.5195.125≥ unspecified, < 105.0.5195.1252022-09-26
CVE-2022-3198 [HIGH] CWE-416 CVE-2022-3198: Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentia
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2022-2606P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2606 [HIGH] CWE-416 CVE-2022-2606: Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attac
Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enable a specific Enterprise policy to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-4440P3HIGHCVSS 8.8fixed in 108.0.5359.124≥ unspecified, < 108.0.5359.1242022-12-14
CVE-2022-4440 [HIGH] CWE-416 CVE-2022-4440: Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to pot
Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4176P3HIGHCVSS 8.8fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4176 [HIGH] CWE-787 CVE-2022-4176: Out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros prior to 108.0.5359.
Out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: High)
nvd
CVE-2023-0941P3HIGHCVSS 8.8fixed in 110.0.5481.177≥ 110.0.5481.177, < 110.0.5481.1772023-02-22
CVE-2023-0941 [HIGH] CWE-416 CVE-2023-0941: Use after free in Prompts in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to pote
Use after free in Prompts in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2022-2620P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2620 [HIGH] CWE-665 CVE-2022-2620: Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attack
Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2013-2863P3CRITICALCVSS 10.0≤ 27.0.1453.109v27.0.1453.0+79 more2013-06-05
CVE-2013-2863 [CRITICAL] CWE-119 CVE-2013-2863: Google Chrome before 27.0.1453.110 does not properly handle SSL sockets, which allows remote attacke
Google Chrome before 27.0.1453.110 does not properly handle SSL sockets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2023-1222P3HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1222 [HIGH] CWE-787 CVE-2023-1222: Heap buffer overflow in Web Audio API in Google Chrome prior to 111.0.5563.64 allowed a remote attac
Heap buffer overflow in Web Audio API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd