Google Chrome Chrome vulnerabilities

1,139 known vulnerabilities affecting google/chrome_chrome.

Total CVEs
1,139
CISA KEV
47
actively exploited
Public exploits
9
Exploited in wild
36
Severity breakdown
CRITICAL58HIGH621MEDIUM339LOW104UNKNOWN17

Vulnerabilities

Page 34 of 57
CVE-2022-4926MEDIUMCVSS 6.52023-01-24
CVE-2022-4926 [MEDIUM] Stable Channel Update for Desktop: CVE-2022-4926 Stable Channel Update for Desktop CVE-2022-4926: Insufficient policy enforcement in Intents. Reported by Philipp Beer on 2022-06-07 and Axel Chong on 2022-09-26 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel Severity: medium
chrome
CVE-2023-0137HIGHCVSS 8.82023-01-13
CVE-2023-0137 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-0137 Stable Channel Update for ChromeOS / ChromeOS Flex CVE-2023-0137
chrome
CVE-2023-0131MEDIUMCVSS 6.52023-01-10
CVE-2023-0131 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-0131 Stable Channel Update for Desktop CVE-2023-0131: Inappropriate implementation in iframe Sandbox. Reported by NDevTK on 2022-08-28 [$3000][ 1371215 ] Medium CVE-2023-0132: Inappropriate implementation in Permission prompts Reported by Jasper Rebane (popstonia) on 2022-10-05 [$3000][ 1375132 ] Medium CVE-2023-0133: Inappropriate implementation in Permission prompts Severity: medium
chrome
CVE-2023-0134MEDIUMCVSS 8.82023-01-10
CVE-2023-0134 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-0134 Stable Channel Update for Desktop CVE-2023-0134: Use after free in Cart. Reported by Chaoyuan Peng (@ret2happy) on 2022-11-17 [$2500][ 1385831 ] Medium CVE-2023-0135: Use after free in Cart Reported by Chaoyuan Peng (@ret2happy) on 2022-11-18 [$2000][ 1356987 ] Medium CVE-2023-0136: Inappropriate implementation in Fullscreen API Severity: medium
chrome
CVE-2023-0141LOWCVSS 4.32023-01-10
CVE-2023-0141 [LOW] Stable Channel Update for Desktop: CVE-2023-0141 Stable Channel Update for Desktop CVE-2023-0141: Insufficient policy enforcement in CORS. Reported by scarlet on 2022-09-12 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel Severity: low
chrome
CVE-2023-0138LOWCVSS 8.82023-01-10
CVE-2023-0138 [LOW] Stable Channel Update for Desktop: CVE-2023-0138 Stable Channel Update for Desktop CVE-2023-0138: Heap buffer overflow in libphonenumber. Reported by Michael Dau on 2022-07-23 [$2000][ 1367632 ] Low CVE-2023-0139: Insufficient validation of untrusted input in Downloads Reported by Axel Chong on 2022-09-24 [$1000][ 1326788 ] Low CVE-2023-0140: Inappropriate implementation in File System API Severity: low
chrome
CVE-2022-42720HIGHCVSS 7.82023-01-05
CVE-2022-42720 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-42720 Long Term Support Channel Update for ChromeOS CVE-2022-42720
chrome
CVE-2022-4436HIGHCVSS 8.82023-01-05
CVE-2022-4436 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-4436 Long Term Support Channel Update for ChromeOS CVE-2022-4436
chrome
CVE-2022-42719HIGHCVSS 8.82023-01-05
CVE-2022-42719 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-42719 Long Term Support Channel Update for ChromeOS CVE-2022-42719
chrome
CVE-2022-4437HIGHCVSS 8.82023-01-05
CVE-2022-4437 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-4437 Long Term Support Channel Update for ChromeOS CVE-2022-4437
chrome
CVE-2022-41674HIGHCVSS 8.12023-01-05
CVE-2022-41674 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-41674 Long Term Support Channel Update for ChromeOS CVE-2022-41674
chrome
CVE-2022-4135CRITICALCVSS 9.6KEV2022-12-14
CVE-2022-4135 [CRITICAL] Long Term Support Channel Update for ChromeOS: CVE-2022-4135 Long Term Support Channel Update for ChromeOS CVE-2022-4135
chrome
CVE-2022-4178HIGHCVSS 8.82022-12-14
CVE-2022-4178 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-4178 Long Term Support Channel Update for ChromeOS CVE-2022-4178
chrome
CVE-2022-4181HIGHCVSS 8.82022-12-14
CVE-2022-4181 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-4181 Long Term Support Channel Update for ChromeOS CVE-2022-4181
chrome
CVE-2022-4179HIGHCVSS 8.82022-12-14
CVE-2022-4179 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-4179 Long Term Support Channel Update for ChromeOS CVE-2022-4179
chrome
CVE-2022-4439HIGHCVSS 8.82022-12-13
CVE-2022-4439 [HIGH] Stable Channel Update for Desktop: CVE-2022-4439 Stable Channel Update for Desktop CVE-2022-4439: Use after free in Aura. Reported by Anonymous on 2022-11-22 [$3000][ 1382761 ] Medium CVE-2022-4440: Use after free in Profiles Reported by Anonymous on 2022-11-09 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel Severity: high
chrome
CVE-2022-4262HIGHCVSS 8.8KEV2022-12-02
CVE-2022-4262 [HIGH] Stable Channel Update for Desktop: CVE-2022-4262 Stable Channel Update for Desktop CVE-2022-4262: Type Confusion in V8. Reported by Clement Lecigne of Google's Threat Analysis Group on 2022-11-29 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel Severity: high
chrome
CVE-2022-4176HIGHCVSS 8.82022-12-01
CVE-2022-4176 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2022-4176 Stable Channel Update for ChromeOS / ChromeOS Flex CVE-2022-4176
chrome
CVE-2022-3038HIGHCVSS 8.8KEV2022-11-30
CVE-2022-3038 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-3038 Long Term Support Channel Update for ChromeOS CVE-2022-3038
chrome
CVE-2022-4177HIGHCVSS 8.82022-11-29
CVE-2022-4177 [HIGH] Stable Channel Update for Desktop: CVE-2022-4177 Stable Channel Update for Desktop CVE-2022-4177: Use after free in Extensions. Reported by Chaoyuan Peng (@ret2happy) on 2022-10-28 [$NA][ 1376099 ] High CVE-2022-4178: Use after free in Mojo Reported by Sergei Glazunov of Google Project Zero on 2022-10-18 [$NA][ 1377783 ] High CVE-2022-4179: Use after free in Audio Severity: high
chrome