VYPR

ChromeOS

by Google

CVEs (116)

  • CVE-2025-6179CriJun 16, 2025
    risk 0.64cvss 9.8epss 0.00

    Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and…

  • CVE-2022-2587CriAug 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.

  • CVE-2016-5179CriMar 7, 2018
    risk 0.64cvss 9.8epss 0.02

    Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot.

  • CVE-2022-0977CriJul 21, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38013CriDec 23, 2021
    risk 0.62cvss 9.6epss 0.01

    Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2017-15402CriJan 9, 2019
    risk 0.62cvss 9.6epss 0.01

    Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had compromised the renderer…

  • CVE-2014-3180CriNov 6, 2019
    risk 0.59cvss 9.1epss 0.01

    In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting compat_sys_nanosleep. NOTE: this is disputed because the code path is unreachable

  • CVE-2025-2073HigApr 16, 2025
    risk 0.57cvss 8.8epss 0.00

    Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentially leading to information disclosure

  • CVE-2025-1568HigApr 16, 2025
    risk 0.57cvss 8.8epss 0.00

    Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via…

  • CVE-2023-4369HigAug 15, 2023
    risk 0.57cvss 8.8epss 0.00

    Insufficient data validation in Systems Extensions in Google Chrome on ChromeOS prior to 116.0.5845.120 allowed an attacker who convinced a user to install a malicious extension to bypass file restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-3731HigAug 1, 2023
    risk 0.57cvss 8.8epss 0.00

    Use after free in Diagnostics in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

  • CVE-2023-3729HigAug 1, 2023
    risk 0.57cvss 8.8epss 0.00

    Use after free in Splitscreen in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chromium security severity: High)

  • CVE-2023-2457HigMay 12, 2023
    risk 0.57cvss 8.8epss 0.00

    Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)

  • CVE-2023-2461HigMay 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)

  • CVE-2022-2743HigJan 2, 2023
    risk 0.57cvss 8.8epss 0.01

    Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to perform an out of bounds memory write via crafted UI interactions. (Chrome security…

  • CVE-2022-3659HigNov 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: Medium)

  • CVE-2022-3658HigNov 1, 2022
    risk 0.57cvss 8.8epss 0.00

    Use after free in Feedback service on Chrome OS in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)

  • CVE-2022-3071HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.00

    Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.

  • CVE-2022-3052HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.

  • CVE-2022-3051HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.

Page 1 of 6