Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 97 of 292
CVE-2026-12014P3HIGHCVSS 8.3fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12014 [HIGH] CWE-416 CVE-2026-12014: Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local net
Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2026-10012P3HIGHCVSS 8.3fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-10012 [HIGH] CWE-416 CVE-2026-10012: Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had co
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10001P3HIGHCVSS 8.3fixed in 148.0.7778.215fixed in 148.0.7778.216+1 more2026-05-28
CVE-2026-10001 [HIGH] CWE-416 CVE-2026-10001: Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attac
Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9998P3HIGHCVSS 8.3fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9998 [HIGH] CWE-472 CVE-2026-9998: Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11656P3HIGHCVSS 8.3fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11656 [HIGH] CWE-416 CVE-2026-11656: Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who con
Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2026-12022P3HIGHCVSS 8.3fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12022 [HIGH] CWE-362 CVE-2026-12022: Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who
Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-11677P3HIGHCVSS 8.3fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11677 [HIGH] CWE-362 CVE-2026-11677: Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had co
Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5158P3HIGHCVSS 8.1fixed in 125.0.6422.76≥ 125.0.6422.76, < 125.0.6422.762024-05-22
CVE-2024-5158 [HIGH] CWE-843 CVE-2024-5158: Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2012-4906P4MEDIUMCVSS 5.0PoC≤ 18.0.10253062012-09-13
CVE-2012-4906 [MEDIUM] CVE-2012-4906: Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which
Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining credential data, a different vulnerability than CVE-2012-4903.
nvd
CVE-2025-11458P3HIGHCVSS 8.1fixed in 141.0.7390.65≥ 141.0.7390.65, < 141.0.7390.652025-11-06
CVE-2025-11458 [HIGH] CWE-122 CVE-2025-11458: Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to pe
Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2016-1636P3CRITICALCVSS 9.8≤ 48.0.2564.1162016-03-06
CVE-2016-1636 [CRITICAL] CWE-264 CVE-2016-1636: The PendingScript::notifyFinished function in WebKit/Source/core/dom/PendingScript.cpp in Google Chr
The PendingScript::notifyFinished function in WebKit/Source/core/dom/PendingScript.cpp in Google Chrome before 49.0.2623.75 relies on memory-cache information about integrity-check occurrences instead of integrity-check successes, which allows remote attackers to bypass the Subresource Integrity (aka SRI) protection mechanism by triggering two loads
nvd
CVE-2012-5376P3CRITICALCVSS 9.6fixed in 22.0.1229.942012-10-11
CVE-2012-5376 [CRITICAL] CVE-2012-5376: The Inter-process Communication (IPC) implementation in Google Chrome before 22.0.1229.94 allows rem
The Inter-process Communication (IPC) implementation in Google Chrome before 22.0.1229.94 allows remote attackers to bypass intended sandbox restrictions and write to arbitrary files by leveraging access to a renderer process, a different vulnerability than CVE-2012-5112.
nvd
CVE-2018-17462P3CRITICALCVSS 9.6fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17462 [CRITICAL] CWE-416 CVE-2018-17462: Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker t
Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6471P3CRITICALCVSS 9.6fixed in 83.0.4103.61≥ unspecified, < 83.0.4103.612020-05-21
CVE-2020-6471 [CRITICAL] CWE-276 CVE-2020-6471: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2026-15765P3HIGHCVSS 7.5fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15765 [HIGH] CWE-416 CVE-2026-15765: Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convi
Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2025-11211P3HIGHCVSS 7.5fixed in 141.0.7390.54≥ 141.0.7390.54, < 141.0.7390.542025-11-06
CVE-2025-11211 [HIGH] CWE-125 CVE-2025-11211: Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to pot
Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10906P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10906 [HIGH] CWE-416 CVE-2026-10906: Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacke
Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-21111P3CRITICALCVSS 9.6fixed in 87.0.4280.141≥ unspecified, < 87.0.4280.1412021-01-08
CVE-2021-21111 [CRITICAL] CWE-1021 CVE-2021-21111: Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker
Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2025-12430P3HIGHCVSS 7.5fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12430 [HIGH] CWE-290 CVE-2025-12430: Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to
Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13814P3HIGHCVSS 7.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13814 [HIGH] CWE-416 CVE-2026-13814: Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convin
Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd