Chrome
Vendor:
First CVE: Sep 30, 2008 · Active for 17 years
5,475
Total CVEs
More Total CVEs than 100% of tracked products
288.2
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Chrome over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2008
17 years ago
Most Recent CVE
Jul 21, 2026
2 days ago
CVE Severity & Scoring
Chrome5,475 CVEs
41%
52%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local113 (2.1%)
Network4,140 (75.6%)
Unknown1,185 (21.6%)
Physical14 (0.3%)
Adjacent Network23 (0.4%)
Attack Complexity
Low3,777 (69.0%)
High513 (9.4%)
Unknown1,185 (21.6%)
User Interaction
None199 (3.6%)
Unknown1,185 (21.6%)
Required4,091 (74.7%)
Privileges Required
Low31 (0.6%)
High3 (0.1%)
None4,256 (77.7%)
Unknown1,185 (21.6%)
Top CVEs
Signals from CVEs in this product scope (5475 CVEs).
5,475 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0497CRITICAL Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta | Feb 5, 2014 | 9.8 | 98 | YES | YES |
CVE-2011-0611HIGH Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib | Apr 13, 2011 | 8.8 | 98 | YES | YES |
CVE-2020-6418HIGH Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Feb 27, 2020 | 8.8 | 97 | YES | YES |
CVE-2018-17463HIGH Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | Nov 14, 2018 | 8.8 | 97 | YES | YES |
CVE-2023-4863HIGH Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag | Sep 12, 2023 | 8.8 | 96 | YES | NO |
CVE-2019-13720HIGH Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Nov 25, 2019 | 8.8 | 95 | YES | YES |
CVE-2011-0609HIGH Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; a | Mar 15, 2011 | 7.8 | 95 | YES | YES |
CVE-2021-21220HIGH Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Apr 26, 2021 | 8.8 | 94 | YES | YES |
CVE-2019-5786MEDIUM Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | Jun 27, 2019 | 6.5 | 94 | YES | YES |
CVE-2019-5825MEDIUM Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Nov 25, 2019 | 6.5 | 93 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (5475 CVEs).
CISA KEV
75 CVEs
1.4% of CVEs· 96th percentile
Metasploit
11 CVEs
0.2% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
61 CVEs
1.1% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (5475 CVEs).
Media Mentions
Signals from CVEs in this product scope (5475 CVEs).
Top CNAs Publishing CVEs For Chrome
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0.517.9 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.8 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.7 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.6 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.5 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.4 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.39 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.38 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.37 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.36 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.35 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.34 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.33 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.32 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.31 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.30 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.29 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.28 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.27 | 5 | 6.9 | 1.6% | 0 | 0 |
| 7.0.517.26 | 5 | 6.9 | 1.6% | 0 | 0 |