Google chrome
This hub aggregates every CVE we track for Google chrome, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
6,323
CVEs tracked
565
Critical
2,962
High
76
In CISA KEV
Severity distribution
HIGH2,962MEDIUM2,678CRITICAL565LOW118
Monthly trend
22
13
7
17
9
16
13
14
10
6
16
12
1
67
19
12
20
74
144
370
965
487
396
38
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Google chrome.
- CVE-2026-85051Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2026-85044Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page....6.5
- CVE-2026-85049Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2026-85047Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafte...9.6
- CVE-2026-85042Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)9.6
- CVE-2026-85053Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security...8.8
- CVE-2026-85048Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted ...8.3
- CVE-2026-85045Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)7.5
- CVE-2026-85050Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium securit...9.6
- CVE-2026-85046Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)KEV8.8
- CVE-2026-85052Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML...3.1
- CVE-2026-85043Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)9.1
- CVE-2026-84331Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chr...3.1
- CVE-2026-84356UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)4.3
- CVE-2026-84350Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromiu...8.8
Product normalization is registry-driven with AI assist and human review. How it works