cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 98 of 292
CVE-2026-17887P3HIGHCVSS 7.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17887 [HIGH] CWE-416 CVE-2026-17887: Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who con Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11242P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11242 [HIGH] CWE-20 CVE-2026-11242: Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowe Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17816P3HIGHCVSS 7.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17816 [HIGH] CWE-269 CVE-2026-17816: Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9960P3HIGHCVSS 7.5fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9960 [HIGH] CWE-472 CVE-2026-9960: Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who ha Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted font file. (Chromium security severity: High)
nvd
CVE-2026-13283P3HIGHCVSS 7.5fixed in 149.0.7827.201≥ 149.0.7827.201, < 149.0.7827.2012026-06-25
CVE-2026-13283 [HIGH] CWE-416 CVE-2026-13283: Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote atta Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17930P3HIGHCVSS 7.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17930 [HIGH] CWE-20 CVE-2026-17930: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 all Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-10009P3HIGHCVSS 7.5fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-10009 [HIGH] CWE-472 CVE-2026-10009: Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7976P3HIGHCVSS 7.5fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7976 [HIGH] CWE-416 CVE-2026-7976: Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2026-8521P3HIGHCVSS 7.5fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8521 [HIGH] CWE-416 CVE-2026-8521: Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to e Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
nvd
CVE-2026-17774P3HIGHCVSS 7.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17774 [HIGH] CWE-20 CVE-2026-17774: Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 all Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-7349P3HIGHCVSS 7.5fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7349 [HIGH] CWE-416 CVE-2026-7349: Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local net Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2009-0374P4MEDIUMCVSS 4.3PoCv1.0.154.432009-01-30
CVE-2009-0374 [MEDIUM] CVE-2009-0374: Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability. NOTE: a third party disputes the relevance of this issue, stating that "every sufficiently featured browser is and likely will remain suscept
nvd
CVE-2018-6031P3HIGHCVSS 8.8fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6031 [HIGH] CWE-416 CVE-2018-6031: Use after free in PDFium in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potent Use after free in PDFium in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2019-5827P3HIGHCVSS 8.8fixed in 74.0.3729.131≥ unspecified, < 74.0.3729.1312019-06-27
CVE-2019-5827 [HIGH] CWE-190 CVE-2019-5827: Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attac Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6413P3HIGHCVSS 8.8fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6413 [HIGH] CVE-2020-6413: Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attack Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML page.
nvd
CVE-2019-5822P3HIGHCVSS 8.8fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5822 [HIGH] CVE-2019-5822: Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attac Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2019-5757P3HIGHCVSS 8.8fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5757 [HIGH] CWE-704 CVE-2019-5757: An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote a An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
nvd
CVE-2018-6073P3HIGHCVSS 8.8fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6073 [HIGH] CWE-787 CVE-2018-6073: A heap buffer overflow in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to A heap buffer overflow in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2017-5125P3HIGHCVSS 8.8fixed in 62.0.3202.622018-02-07
CVE-2017-5125 [HIGH] CWE-119 CVE-2017-5125: Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to pot Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-18337P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18337 [HIGH] CWE-416 CVE-2018-18337: Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71. Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase