Google Chrome
6,611 CVEs tracked. 77 of them are in CISA KEV.
This hub aggregates every CVE we track for Google Chrome, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
Google Chrome CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 22 |
| 2024-11 | 13 |
| 2024-12 | 7 |
| 2025-01 | 17 |
| 2025-02 | 9 |
| 2025-03 | 16 |
| 2025-04 | 13 |
| 2025-05 | 14 |
| 2025-06 | 10 |
| 2025-07 | 6 |
| 2025-08 | 16 |
| 2025-09 | 12 |
| 2025-10 | 1 |
| 2025-11 | 67 |
| 2025-12 | 19 |
| 2026-01 | 12 |
| 2026-02 | 20 |
| 2026-03 | 74 |
| 2026-04 | 144 |
| 2026-05 | 370 |
| 2026-06 | 965 |
| 2026-07 | 487 |
| 2026-08 | 396 |
| 2026-09 | 326 |
Severity
How the 6,611 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical609
- High3,040
- Medium2,819
- Low143
Latest CVEs
The 15 most recently published vulnerabilities affecting Google Chrome.
- CVE-2026-93386UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium securi...5.4
- CVE-2026-93385Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)6.5
- CVE-2026-93378Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromiu...3.1
- CVE-2026-93377Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium ...8.8
- CVE-2026-93384Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted...3.7
- CVE-2026-93380Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access rest...3.1
- CVE-2026-93383Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)4.3
- CVE-2026-93376Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium s...6.3
- CVE-2026-93387Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)4.3
- CVE-2026-93381Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via ...8.8
- CVE-2026-93373Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security sever...9.6
- CVE-2026-93379Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)4.3
- CVE-2026-93375Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local progra...8.1
- CVE-2026-93382Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2026-93372Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security se...9.6
Product grouping is registry-driven, with AI assist and human review. How it works