Chromium is a modestly represented open-source browser engine that, despite its narrow product scope, sits at the foundation of a wide range of consumer and enterprise browsers and embedded web platforms. Its vulnerability profile centers on memory-safety and use-after-free conditions characteristic of native browser codebases, reflecting the complexity of rendering, scripting, and process isolation that modern browsers demand. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chromium over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1531HIGH Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severi | Mar 21, 2023 | 8.8 | 29 | NO | NO |
CVE-2011-1797HIGH WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted | Jul 21, 2011 | 9.3 | 29 | NO | NO |
CVE-2017-7000HIGH An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote atta | Apr 3, 2018 | 8.8 | 25 | NO | NO |
CVE-2014-7942HIGH The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibl | Jan 22, 2015 | 7.5 | 23 | NO | NO |
CVE-2015-1205HIGH Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | Jan 22, 2015 | 7.5 | 20 | NO | NO |
CVE-2015-1346HIGH Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have oth | Jan 22, 2015 | 7.5 | 19 | NO | NO |
CVE-2014-7943MEDIUM Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | Jan 22, 2015 | 5.0 | 15 | NO | NO |
CVE-2014-7941MEDIUM The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain l | Jan 22, 2015 | 5.0 | 15 | NO | NO |
CVE-2014-7939MEDIUM Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.c | Jan 22, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chromium.
Media articles that mention a CVE ID that affects a product developed by Chromium — matched by CVE ID, not by vendor name.