VYPR

Chrome

by Google

Source repositories

CVEs (5,933)

  • CVE-2025-6179CriJun 16, 2025
    risk 0.64cvss 9.8epss 0.00

    Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities using the ExtHang3r and…

  • CVE-2025-4052CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2024-1284CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-1283CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.19

    Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-0808CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

  • CVE-2023-1529CriMar 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)

  • CVE-2022-2587CriAug 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.

  • CVE-2022-0306HigFeb 12, 2022
    risk 0.64cvss 8.8epss 0.85

    Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21132CriFeb 9, 2021
    risk 0.64cvss 9.6epss 0.23

    Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2020-15993CriNov 3, 2020
    risk 0.64cvss 9.8epss 0.01

    Use after free in printing in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-5866CriNov 25, 2019
    risk 0.64cvss 9.8epss 0.01

    Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2016-9652CriNov 20, 2019
    risk 0.64cvss 9.8epss 0.02

    Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.

  • CVE-2016-5194CriNov 20, 2019
    risk 0.64cvss 9.8epss 0.01

    Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.

  • CVE-2011-2337CriNov 7, 2019
    risk 0.64cvss 9.8epss 0.01

    A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.

  • CVE-2011-1460CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.01

    WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.

  • CVE-2017-15398CriAug 28, 2018
    risk 0.64cvss 9.8epss 0.04

    A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a malicious server.

  • CVE-2016-5178CriMay 23, 2017
    risk 0.64cvss 9.8epss 0.02

    Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.

  • CVE-2014-9654CriApr 24, 2017
    risk 0.64cvss 9.8epss 0.02

    The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which allows remote attackers to…

  • CVE-2013-6647CriApr 11, 2017
    risk 0.64cvss 9.8epss 0.01

    A use-after-free in AnimationController::endAnimationUpdate in Google Chrome.

  • CVE-2016-5146CriAug 7, 2016
    risk 0.64cvss 9.8epss 0.01

    Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

Page 5 of 297