cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 92 of 292
CVE-2023-0932P3HIGHCVSS 8.8fixed in 110.0.5481.177≥ 110.0.5481.177, < 110.0.5481.1772023-02-22
CVE-2023-0932 [HIGH] CWE-416 CVE-2023-0932: Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attack Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4914P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ 104.0.5112.79, < 104.0.5112.792023-07-29
CVE-2022-4914 [HIGH] CWE-787 CVE-2022-4914: Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1215P3HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1215 [HIGH] CWE-843 CVE-2023-1215: Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potential Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3659P3HIGHCVSS 8.8fixed in 107.0.5304.62≥ unspecified, < 107.0.5304.622022-11-01
CVE-2022-3659 [HIGH] CWE-416 CVE-2022-3659: Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remot Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: Medium)
nvd
CVE-2023-1218P3HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1218 [HIGH] CWE-416 CVE-2023-1218: Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potent Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-2743P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792023-01-02
CVE-2022-2743 [HIGH] CWE-190 CVE-2022-2743: Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 a Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to perform an out of bounds memory write via crafted UI interactions. (Chrome security severity: High)
nvd
CVE-2023-1213P3HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1213 [HIGH] CWE-416 CVE-2023-1213: Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to p Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-0447P3HIGHCVSS 8.8fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0447 [HIGH] CWE-79 CVE-2025-0447: Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-0806P3HIGHCVSS 8.8fixed in 121.0.6167.85≥ 121.0.6167.85, < 121.0.6167.852024-01-24
CVE-2024-0806 [HIGH] CWE-416 CVE-2024-0806: Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to pot Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
nvd
CVE-2022-2742P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792023-01-02
CVE-2022-2742 [HIGH] CWE-362 CVE-2022-2742: Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chrome security severity: High)
nvd
CVE-2023-2457P3HIGHCVSS 8.8fixed in 113.0.5672.114≥ 113.0.5672.114, < 113.0.5672.1142023-05-12
CVE-2023-2457 [HIGH] CWE-787 CVE-2023-2457: Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 al Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)
nvd
CVE-2025-1919P3HIGHCVSS 8.8fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-03-05
CVE-2025-1919 [HIGH] CWE-125 CVE-2025-1919: Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to pot Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-3731P3HIGHCVSS 8.8fixed in 115.0.5790.131≥ 115.0.5790.131, < 115.0.5790.1312023-08-01
CVE-2023-3731 [HIGH] CWE-416 CVE-2023-3731: Use after free in Diagnostics in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed an attack Use after free in Diagnostics in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2024-11115P3HIGHCVSS 8.8fixed in 131.0.6778.69≥ 131.0.6778.69, < 131.0.6778.692024-11-12
CVE-2024-11115 [HIGH] CWE-79 CVE-2024-11115: Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed a remote attacker to perform privilege escalation via a series of UI gestures. (Chromium security severity: Medium)
nvd
CVE-2025-3068P3HIGHCVSS 8.8fixed in 135.0.7049.52≥ 135.0.7049.52, < 135.0.7049.522025-04-02
CVE-2025-3068 [HIGH] CWE-20 CVE-2025-3068: Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-3069P3HIGHCVSS 8.8fixed in 135.0.7049.52≥ 135.0.7049.52, < 135.0.7049.522025-04-02
CVE-2025-3069 [HIGH] CWE-358 CVE-2025-3069: Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-0437P3HIGHCVSS 8.8fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0437 [HIGH] CWE-125 CVE-2025-0437: Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to p Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-1916P3HIGHCVSS 8.8fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-03-05
CVE-2025-1916 [HIGH] CWE-416 CVE-2025-1916: Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-1806P3CRITICALCVSS 10.0fixed in 11.0.696.712011-05-26
CVE-2011-1806 [CRITICAL] CWE-119 CVE-2011-1806: Google Chrome before 11.0.696.71 does not properly implement the GPU command buffer, which allows re Google Chrome before 11.0.696.71 does not properly implement the GPU command buffer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2026-12013P3HIGHCVSS 8.8fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12013 [HIGH] CWE-416 CVE-2026-12013: Use after free in Media in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacke Use after free in Media in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase