Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 92 of 292
CVE-2023-0932P3HIGHCVSS 8.8fixed in 110.0.5481.177≥ 110.0.5481.177, < 110.0.5481.1772023-02-22
CVE-2023-0932 [HIGH] CWE-416 CVE-2023-0932: Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attack
Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4914P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ 104.0.5112.79, < 104.0.5112.792023-07-29
CVE-2022-4914 [HIGH] CWE-787 CVE-2022-4914: Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who
Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1215P3HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1215 [HIGH] CWE-843 CVE-2023-1215: Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potential
Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3659P3HIGHCVSS 8.8fixed in 107.0.5304.62≥ unspecified, < 107.0.5304.622022-11-01
CVE-2022-3659 [HIGH] CWE-416 CVE-2022-3659: Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remot
Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: Medium)
nvd
CVE-2023-1218P3HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1218 [HIGH] CWE-416 CVE-2023-1218: Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potent
Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-2743P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792023-01-02
CVE-2022-2743 [HIGH] CWE-190 CVE-2022-2743: Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 a
Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to perform an out of bounds memory write via crafted UI interactions. (Chrome security severity: High)
nvd
CVE-2023-1213P3HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1213 [HIGH] CWE-416 CVE-2023-1213: Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to p
Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-0447P3HIGHCVSS 8.8fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0447 [HIGH] CWE-79 CVE-2025-0447: Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote
Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-0806P3HIGHCVSS 8.8fixed in 121.0.6167.85≥ 121.0.6167.85, < 121.0.6167.852024-01-24
CVE-2024-0806 [HIGH] CWE-416 CVE-2024-0806: Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to pot
Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
nvd
CVE-2022-2742P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792023-01-02
CVE-2022-2742 [HIGH] CWE-362 CVE-2022-2742: Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed
Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chrome security severity: High)
nvd
CVE-2023-2457P3HIGHCVSS 8.8fixed in 113.0.5672.114≥ 113.0.5672.114, < 113.0.5672.1142023-05-12
CVE-2023-2457 [HIGH] CWE-787 CVE-2023-2457: Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 al
Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)
nvd
CVE-2025-1919P3HIGHCVSS 8.8fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-03-05
CVE-2025-1919 [HIGH] CWE-125 CVE-2025-1919: Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to pot
Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-3731P3HIGHCVSS 8.8fixed in 115.0.5790.131≥ 115.0.5790.131, < 115.0.5790.1312023-08-01
CVE-2023-3731 [HIGH] CWE-416 CVE-2023-3731: Use after free in Diagnostics in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed an attack
Use after free in Diagnostics in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2024-11115P3HIGHCVSS 8.8fixed in 131.0.6778.69≥ 131.0.6778.69, < 131.0.6778.692024-11-12
CVE-2024-11115 [HIGH] CWE-79 CVE-2024-11115: Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed
Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed a remote attacker to perform privilege escalation via a series of UI gestures. (Chromium security severity: Medium)
nvd
CVE-2025-3068P3HIGHCVSS 8.8fixed in 135.0.7049.52≥ 135.0.7049.52, < 135.0.7049.522025-04-02
CVE-2025-3068 [HIGH] CWE-20 CVE-2025-3068: Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a
Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-3069P3HIGHCVSS 8.8fixed in 135.0.7049.52≥ 135.0.7049.52, < 135.0.7049.522025-04-02
CVE-2025-3069 [HIGH] CWE-358 CVE-2025-3069: Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote
Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-0437P3HIGHCVSS 8.8fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0437 [HIGH] CWE-125 CVE-2025-0437: Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to p
Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-1916P3HIGHCVSS 8.8fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-03-05
CVE-2025-1916 [HIGH] CWE-416 CVE-2025-1916: Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced
Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-1806P3CRITICALCVSS 10.0fixed in 11.0.696.712011-05-26
CVE-2011-1806 [CRITICAL] CWE-119 CVE-2011-1806: Google Chrome before 11.0.696.71 does not properly implement the GPU command buffer, which allows re
Google Chrome before 11.0.696.71 does not properly implement the GPU command buffer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2026-12013P3HIGHCVSS 8.8fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12013 [HIGH] CWE-416 CVE-2026-12013: Use after free in Media in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacke
Use after free in Media in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd