VYPR

Chrome

by Google

Source repositories

CVEs (6,979)

  • CVE-2026-13775CriJun 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-5902CriApr 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-3062CriFeb 23, 2026
    risk 0.64cvss 9.8epss 0.00

    Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-0907CriJan 20, 2026
    risk 0.64cvss 9.8epss 0.09

    Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-0906CriJan 20, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-0905CriJan 20, 2026
    risk 0.64cvss 9.8epss 0.00

    Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)

  • CVE-2025-6179CriJun 16, 2025
    risk 0.64cvss 9.8epss 0.00

    Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and…

  • CVE-2025-4052CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2024-1284CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-1283CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.22

    Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-0808CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

  • CVE-2023-1529CriMar 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)

  • CVE-2022-2587CriAug 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.

  • CVE-2022-0306HigFeb 12, 2022
    risk 0.64cvss 8.8epss 0.85

    Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21132CriFeb 9, 2021
    risk 0.64cvss 9.6epss 0.23

    Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2020-15993CriNov 3, 2020
    risk 0.64cvss 9.8epss 0.01

    Use after free in printing in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5866CriNov 25, 2019
    risk 0.64cvss 9.8epss 0.01

    Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2016-9652CriNov 20, 2019
    risk 0.64cvss 9.8epss 0.02

    Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.

  • CVE-2016-5194CriNov 20, 2019
    risk 0.64cvss 9.8epss 0.01

    Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.

  • CVE-2011-2337CriNov 7, 2019
    risk 0.64cvss 9.8epss 0.01

    A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.

Page 5 of 349