Chrome
First CVE: May 16, 2011Active for: 15 years
5,177
CVEs Published
More CVEs Published than 97% of tracked CNAs
323.6
Avg CVEs / Year
More Avg CVEs / Year than 96% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 61% of tracked CNAs
1.4%
In CISA KEV
Higher KEV Rate than 90% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by Chrome over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2011
15 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by Chrome as a CNA, regardless of affected vendor or product.
5,177 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-6418HIGH Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Feb 27, 2020 | 8.8 | 97 | YES | YES |
CVE-2018-17463HIGH Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | Nov 14, 2018 | 8.8 | 97 | YES | YES |
CVE-2023-4863HIGH Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag | Sep 12, 2023 | 8.8 | 96 | YES | NO |
CVE-2019-13720HIGH Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Nov 25, 2019 | 8.8 | 95 | YES | YES |
CVE-2016-5195HIGH Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature | Nov 10, 2016 | 7.0 | 95 | YES | YES |
CVE-2021-21220HIGH Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Apr 26, 2021 | 8.8 | 94 | YES | YES |
CVE-2019-5786MEDIUM Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | Jun 27, 2019 | 6.5 | 94 | YES | YES |
CVE-2019-5825MEDIUM Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Nov 25, 2019 | 6.5 | 93 | YES | YES |
CVE-2018-6065HIGH Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to pot | Nov 14, 2018 | 8.8 | 93 | YES | YES |
CVE-2022-2294HIGH Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Jul 28, 2022 | 8.8 | 91 | YES | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA5,177 CVEs
39%
53%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local116 (2.2%)
Network4,146 (80.1%)
Unknown877 (16.9%)
Physical15 (0.3%)
Adjacent Network23 (0.4%)
Attack Complexity
Low3,790 (73.2%)
High510 (9.9%)
Unknown877 (16.9%)
User Interaction
None196 (3.8%)
Unknown877 (16.9%)
Required4,104 (79.3%)
Privileges Required
Low34 (0.7%)
High1 (0.0%)
None4,265 (82.4%)
Unknown877 (16.9%)
Exploit Exposure
Signals from CVEs in this cna scope (5177 CVEs).
CISA KEV
74 CVEs
1.4% of CVEs· 90th percentile
Metasploit
8 CVEs
0.2% of CVEs· 79th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
41 CVEs
0.8% of CVEs· 80th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Chrome as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Chrome as a CNA — matched by CVE ID, not by organization name.