Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Chromium

First CVE: Jul 21, 2011Active for: 15 yearsTotal CVEs: 9

Chromium is a modestly represented open-source browser engine that, despite its narrow product scope, sits at the foundation of a wide range of consumer and enterprise browsers and embedded web platforms. Its vulnerability profile centers on memory-safety and use-after-free conditions characteristic of native browser codebases, reflecting the complexity of rendering, scripting, and process isolation that modern browsers demand. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 90% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Chromium over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2011
15 years ago
Most Recent CVE
Mar 21, 2023
1,221 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1531HIGH
Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severi
Mar 21, 20238.829NONO
CVE-2011-1797HIGH
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted
Jul 21, 20119.329NONO
CVE-2017-7000HIGH
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote atta
Apr 3, 20188.825NONO
CVE-2014-7942HIGH
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibl
Jan 22, 20157.523NONO
CVE-2015-1205HIGH
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Jan 22, 20157.520NONO
CVE-2015-1346HIGH
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have oth
Jan 22, 20157.519NONO
CVE-2014-7943MEDIUM
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Jan 22, 20155.015NONO
CVE-2014-7941MEDIUM
The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain l
Jan 22, 20155.015NONO
CVE-2014-7939MEDIUM
Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.c
Jan 22, 20154.314NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (22.2%)
Unknown7 (77.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (22.2%)
High0 (0.0%)
Unknown7 (77.8%)
User Interaction
None0 (0.0%)
Unknown7 (77.8%)
Required2 (22.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (22.2%)
Unknown7 (77.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Chromium.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Chromium — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Chromium's Products

View all 3 CNAs →

Top CWEs