Google Chrome

559 known vulnerabilities in Google Chrome, 94 critical, 73 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-87491 CVSS 8.8 high · actively exploited Google Chromium V8 Out of Bounds Write Vulnerability
  • CVE-2026-85046 CVSS 8.8 high · actively exploited Google Chromium V8 Type Confusion Vulnerability
  • CVE-2026-11645 CVSS 8.8 high · actively exploited Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
  • CVE-2026-5281 CVSS 8.8 high · actively exploited Google Dawn Use-After-Free Vulnerability
  • CVE-2026-3910 CVSS 8.8 high · actively exploited Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
  • CVE-2026-3909 CVSS 8.8 high · actively exploited Google Skia Out-of-Bounds Write Vulnerability
  • CVE-2026-2441 CVSS 8.8 high · actively exploited Google Chromium CSS Use-After-Free Vulnerability
  • CVE-2025-14174 CVSS 8.8 high · actively exploited Google Chromium Out of Bounds Memory Access Vulnerability
  • CVE-2025-13223 CVSS 8.8 high · actively exploited Google Chromium V8 Type Confusion Vulnerability
  • CVE-2025-10585 CVSS 9.8 critical · actively exploited Google Chromium V8 Type Confusion Vulnerability

Latest vulnerabilities

  • CVE-2026-103631 not yet scored Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox…
  • CVE-2026-103630 not yet scored Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox…
  • CVE-2026-103629 CVSS 4.3 medium Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML…
  • CVE-2026-103628 CVSS 9.6 critical Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the…
  • CVE-2026-103627 not yet scored Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted…
  • CVE-2026-103626 CVSS 9.6 critical Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social…
  • CVE-2026-103625 CVSS 8.8 high Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a…
  • CVE-2026-103624 CVSS 8.3 high Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the…
  • CVE-2026-103623 not yet scored Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the…
  • CVE-2026-103622 CVSS 8.8 high Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a…
  • CVE-2026-103621 CVSS 4.3 medium Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted…
  • CVE-2026-102331 CVSS 9.6 critical Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary…
  • CVE-2026-102330 CVSS 6.5 medium Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the…
  • CVE-2026-102329 CVSS 6.1 medium Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a…
  • CVE-2026-102328 CVSS 8.8 high Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a…
  • CVE-2026-102327 CVSS 7.5 high Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the…
  • CVE-2026-102326 CVSS 8.8 high Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a…
  • CVE-2026-102325 CVSS 4.3 medium Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted…
  • CVE-2026-102324 CVSS 8.3 high Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer…
  • CVE-2026-102323 CVSS 8.8 high Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a…
  • CVE-2026-102321 CVSS 8.8 high Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a…
  • CVE-2026-102320 CVSS 6.5 medium Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process…
  • CVE-2026-102319 CVSS 3.4 low Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process…
  • CVE-2026-102318 CVSS 4.7 medium Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a…
  • CVE-2026-102317 CVSS 8.6 high Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially…
  • CVE-2026-102316 CVSS 9.6 critical Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute…
  • CVE-2026-102315 CVSS 3.4 low Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the…
  • CVE-2026-102314 CVSS 5.4 medium UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML…
  • CVE-2026-102313 CVSS 4.7 medium Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the…
  • CVE-2026-102312 CVSS 4.3 medium UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a…