cbcvebase.

Google Chrome Os vulnerabilities

65 known vulnerabilities affecting google/chrome_os.

Total CVEs
65
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH22MEDIUM14LOW1

Vulnerabilities

Page 2 of 4
CVE-2019-16508P4HIGHCVSS 7.8fixed in r74-11895.b≥ r75, < r75.12105.b+1 more2019-10-01
CVE-2019-16508 [HIGH] CWE-190 CVE-2019-16508: The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R7 The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a malicious application. This occurs because of intentional access for the GPU process to /dev/dri/card1 and the PowerVR ioctl handler, as demonstrated by PVR
nvd
CVE-2011-0481P4CRITICALCVSS 9.3fixed in 8.0.552.3442011-01-14
CVE-2011-0481 [CRITICAL] CWE-120 CVE-2011-0481: Buffer overflow in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote a Buffer overflow in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to PDF shading.
nvd
CVE-2011-0473P4CRITICALCVSS 10.0fixed in 8.0.552.3442011-01-14
CVE-2011-0473 [CRITICAL] CVE-2011-0473: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading S Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with CANVAS elements, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1306P4CRITICALCVSS 10.0≤ 0.10.156.36v0.10.142.3+7 more2011-03-08
CVE-2011-1306 [CRITICAL] CVE-2011-1306: Unspecified vulnerability in the Scratchpad application in Google Chrome OS before R10 0.10.156.46 B Unspecified vulnerability in the Scratchpad application in Google Chrome OS before R10 0.10.156.46 Beta has unknown impact and attack vectors.
nvd
CVE-2011-0480P4CRITICALCVSS 9.3fixed in 8.0.552.3442011-01-14
CVE-2011-0480 [CRITICAL] CWE-120 CVE-2011-0480: Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel
nvd
CVE-2025-1704P4MEDIUMCVSS 6.5v15823.23.02025-04-16
CVE-2025-1704 [MEDIUM] CWE-416 CVE-2025-1704: ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks a ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful partition.
nvd
CVE-2011-0474P4CRITICALCVSS 10.0fixed in 8.0.552.3442011-01-14
CVE-2011-0474 [CRITICAL] CVE-2011-0474: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading S Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-0476P4CRITICALCVSS 10.0fixed in 8.0.552.3442011-01-14
CVE-2011-0476 [CRITICAL] CWE-119 CVE-2011-0476: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allow remote attackers to cause a Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allow remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a PDF document that triggers an out-of-memory error.
nvd
CVE-2010-4574P4HIGHCVSS 7.5fixed in 8.0.552.3432010-12-22
CVE-2010-4574 [HIGH] CWE-502 CVE-2010-4574: The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS befo The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to bypass message deserialization validation, and cause a denial of service or possibly have unspecified other impact, via invalid pickle
nvd
CVE-2011-4548P4CRITICALCVSS 10.0≤ 16.0.912.432011-11-24
CVE-2011-4548 [CRITICAL] CVE-2011-4548: Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
nvd
CVE-2012-3290P4CRITICALCVSS 10.0≤ 20.0.1132.21v20.0.1132.0+20 more2012-06-07
CVE-2012-3290 [CRITICAL] CVE-2012-3290: Multiple unspecified vulnerabilities in Google Chrome before 20.0.1132.22 on the Acer AC700; Samsung Multiple unspecified vulnerabilities in Google Chrome before 20.0.1132.22 on the Acer AC700; Samsung Series 5, 5 550, and Chromebox 3; and Cr-48 Chromebook platforms have unknown impact and attack vectors.
nvd
CVE-2011-2171P4CRITICALCVSS 10.0≤ 0.12.433.35v0.9.126.0+29 more2011-05-24
CVE-2011-2171 [CRITICAL] CVE-2011-2171: Unspecified vulnerability in the dbugs package in Google Chrome OS before R12 0.12.433.38 Beta has u Unspecified vulnerability in the dbugs package in Google Chrome OS before R12 0.12.433.38 Beta has unknown impact and attack vectors.
nvd
CVE-2013-0927P4HIGHCVSS 7.5≤ 26.0.1410.56v26.0.1410.0+52 more2013-04-10
CVE-2013-0927 [HIGH] CWE-59 CVE-2013-0927: Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.
nvd
CVE-2011-0471P4CRITICALCVSS 10.0fixed in 8.0.552.3442011-01-14
CVE-2011-0471 [CRITICAL] CWE-20 CVE-2011-0471: The node-iteration implementation in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.3 The node-iteration implementation in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 does not properly handle pointers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-0695P4CRITICALCVSS 10.0≤ 17.0.963.262012-01-12
CVE-2012-0695 [CRITICAL] CVE-2012-0695: Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
nvd
CVE-2011-4719P4CRITICALCVSS 10.0≤ 16.0.912.622011-12-09
CVE-2011-4719 [CRITICAL] CVE-2011-4719: Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.63 on the Acer AC700, Samsung Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.63 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
nvd
CVE-2014-1706P4HIGHCVSS 7.5≤ 33.0.1750.149v33.0.1750.2+9 more2014-03-16
CVE-2014-1706 [HIGH] CVE-2014-1706: crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified v crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors.
nvd
CVE-2011-0475P4CRITICALCVSS 9.3fixed in 8.0.552.3442011-01-14
CVE-2011-0475 [CRITICAL] CWE-416 CVE-2011-0475: Use-after-free vulnerability in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 al Use-after-free vulnerability in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a PDF document.
nvd
CVE-2011-3420P4CRITICALCVSS 10.0≤ 14.0.835.1562011-09-12
CVE-2011-3420 [CRITICAL] CVE-2011-3420: Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
nvd
CVE-2011-3421P4CRITICALCVSS 10.0≤ 14.0.835.1242011-09-12
CVE-2011-3421 [CRITICAL] CVE-2011-3421: Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.125 on the Acer AC700, Samsung Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.125 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
nvd
Google Chrome Os vulnerabilities | cvebase