cbcvebase.

Google Chrome Os vulnerabilities

65 known vulnerabilities affecting google/chrome_os.

Total CVEs
65
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH22MEDIUM14LOW1

Vulnerabilities

Page 3 of 4
CVE-2012-5129P4HIGHCVSS 7.5≤ 21.0.1180.572012-12-04
CVE-2012-5129 [HIGH] CWE-119 CVE-2012-5129: Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows rem Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows remote attackers to cause a denial of service (GPU process crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-1418P4CRITICALCVSS 10.0≤ 17.0.963.592012-02-29
CVE-2012-1418 [CRITICAL] CVE-2012-1418: Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.60 on the Acer AC700, Samsung Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.60 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
nvd
CVE-2014-1707P4HIGHCVSS 7.5≤ 33.0.1750.149v33.0.1750.2+9 more2014-03-16
CVE-2014-1707 [HIGH] CWE-22 CVE-2014-1707: Directory traversal vulnerability in CrosDisks in Google Chrome OS before 33.0.1750.152 has unspecif Directory traversal vulnerability in CrosDisks in Google Chrome OS before 33.0.1750.152 has unspecified impact and attack vectors.
nvd
CVE-2010-4578P4HIGHCVSS 7.5fixed in 8.0.552.3432010-12-22
CVE-2010-4578 [HIGH] CVE-2010-4578: Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor han Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."
nvd
CVE-2011-0479P4HIGHCVSS 7.5fixed in 8.0.552.3442011-01-14
CVE-2011-0479 [HIGH] CWE-824 CVE-2011-0479: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly interact with exte Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly interact with extensions, which allows remote attackers to cause a denial of service via a crafted extension that triggers an uninitialized pointer.
nvd
CVE-2014-1710P4HIGHCVSS 7.5≤ 33.0.1750.149v33.0.1750.2+9 more2014-03-16
CVE-2014-1710 [HIGH] CWE-119 CVE-2014-1710: The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc i The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS before 33.0.1750.152, does not check whether a certain position is within the bounds of a shared-memory segment, which allows remote attackers to cause a denial of service (GPU command-buffer memory corruption)
nvd
CVE-2014-1711P4HIGHCVSS 7.5≤ 33.0.1750.149v33.0.1750.2+9 more2014-03-16
CVE-2014-1711 [HIGH] CWE-119 CVE-2014-1711: The GPU driver in the kernel in Google Chrome OS before 33.0.1750.152 allows remote attackers to cau The GPU driver in the kernel in Google Chrome OS before 33.0.1750.152 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2025-1121P4MEDIUMCVSS 6.8v15786.48.02025-03-07
CVE-2025-1121 [MEDIUM] CWE-269 CVE-2025-1121: Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a specially crafted recovery image.
nvd
CVE-2025-6044P4MEDIUMCVSS 6.1v16238.64.02025-07-07
CVE-2025-6044 [MEDIUM] CWE-287 CVE-2025-6044: An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16 An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and access user files by removing the stylus while the device is closed and using the screen capture feature.
nvd
CVE-2011-0484P4HIGHCVSS 7.5fixed in 8.0.552.3442011-01-14
CVE-2011-0484 [HIGH] CWE-20 CVE-2011-0484: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform DOM node r Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform DOM node removal, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale rendering node."
nvd
CVE-2011-0472P4CRITICALCVSS 9.3fixed in 8.0.552.3442011-01-14
CVE-2011-0472 [CRITICAL] CVE-2011-0472: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle the printin Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle the printing of PDF documents, which allows user-assisted remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a multi-page document.
nvd
CVE-2013-0915P4CRITICALCVSS 10.0≤ 25.0.1364.172v25.0.1364.0+116 more2013-03-18
CVE-2013-0915 [CRITICAL] CWE-119 CVE-2013-0915: The GPU process in Google Chrome OS before 25.0.1364.173 allows attackers to cause a denial of servi The GPU process in Google Chrome OS before 25.0.1364.173 allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an "overflow."
nvd
CVE-2011-2169P4HIGHCVSS 7.2≤ 0.12.433.35v0.9.126.0+29 more2011-05-24
CVE-2011-2169 [HIGH] CWE-264 CVE-2011-2169: Google Chrome OS before R12 0.12.433.38 Beta allows local users to gain privileges by creating a /va Google Chrome OS before R12 0.12.433.38 Beta allows local users to gain privileges by creating a /var/lib/chromeos-aliases.conf file and placing commands in it.
nvd
CVE-2013-2832P4MEDIUMCVSS 5.0≤ 26.0.1410.56v26.0.1410.0+52 more2013-04-16
CVE-2013-2832 [MEDIUM] CWE-119 CVE-2013-2832: The Buffer::Set function in core/cross/buffer.cc in the O3D plug-in in Google Chrome OS before 26.0. The Buffer::Set function in core/cross/buffer.cc in the O3D plug-in in Google Chrome OS before 26.0.1410.57 does not prevent uninitialized data from remaining in a buffer, which might allow remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2013-2834P4MEDIUMCVSS 5.0≤ 26.0.1410.56v26.0.1410.0+52 more2013-04-16
CVE-2013-2834 [MEDIUM] CWE-264 CVE-2013-2834: Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and G Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2835.
nvd
CVE-2013-2835P4MEDIUMCVSS 5.0≤ 26.0.1410.56v26.0.1410.0+52 more2013-04-16
CVE-2013-2835 [MEDIUM] CVE-2013-2835: Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and G Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2834.
nvd
CVE-2011-0483P4MEDIUMCVSS 5.0fixed in 8.0.552.3442011-01-14
CVE-2011-0483 [MEDIUM] CWE-704 CVE-2011-0483: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of an unspecified variable during handling of video, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2866P4MEDIUMCVSS 4.3v27.0.1453.1152013-06-19
CVE-2013-2866 [MEDIUM] CWE-264 CVE-2013-2866: The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.145 The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking
nvd
CVE-2010-4576P4MEDIUMCVSS 5.0fixed in 8.0.552.3432010-12-22
CVE-2010-4576 [MEDIUM] CWE-476 CVE-2010-4576: browser/worker_host/message_port_dispatcher.cc in Google Chrome before 8.0.552.224 and Chrome OS bef browser/worker_host/message_port_dispatcher.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle certain postMessage calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code that creates a web worker.
nvd
CVE-2011-0482P4MEDIUMCVSS 4.3fixed in 8.0.552.3442011-01-14
CVE-2011-0482 [MEDIUM] CWE-704 CVE-2011-0482: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of an unspecified variable during handling of anchors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document.
nvd
Google Chrome Os vulnerabilities | cvebase