Chrome

Vendor:

First CVE: Sep 30, 2008 · Active for 17 years

5,475
Total CVEs
More Total CVEs than 100% of tracked products
288.2
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Chrome over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2008
17 years ago
Most Recent CVE
Jul 21, 2026
2 days ago

CVE Severity & Scoring

Chrome5,475 CVEs
All CVEs352,101 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local113 (2.1%)
Network4,140 (75.6%)
Unknown1,185 (21.6%)
Physical14 (0.3%)
Adjacent Network23 (0.4%)
Attack Complexity
Low3,777 (69.0%)
High513 (9.4%)
Unknown1,185 (21.6%)
User Interaction
None199 (3.6%)
Unknown1,185 (21.6%)
Required4,091 (74.7%)
Privileges Required
Low31 (0.6%)
High3 (0.1%)
None4,256 (77.7%)
Unknown1,185 (21.6%)

Top CVEs

Signals from CVEs in this product scope (5475 CVEs).

5,475 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta
Feb 5, 20149.898YESYES
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib
Apr 13, 20118.898YESYES
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Feb 27, 20208.897YESYES
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Nov 14, 20188.897YESYES
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag
Sep 12, 20238.896YESNO
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Nov 25, 20198.895YESYES
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; a
Mar 15, 20117.895YESYES
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Apr 26, 20218.894YESYES
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Jun 27, 20196.594YESYES
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Nov 25, 20196.593YESYES

Exploit Exposure

Signals from CVEs in this product scope (5475 CVEs).

CISA KEV
75 CVEs
1.4% of CVEs· 96th percentile
Metasploit
11 CVEs
0.2% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
61 CVEs
1.1% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (5475 CVEs).

Media Mentions

Signals from CVEs in this product scope (5475 CVEs).

Top CNAs Publishing CVEs For Chrome

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.0.517.956.91.6%00
7.0.517.856.91.6%00
7.0.517.756.91.6%00
7.0.517.656.91.6%00
7.0.517.556.91.6%00
7.0.517.456.91.6%00
7.0.517.3956.91.6%00
7.0.517.3856.91.6%00
7.0.517.3756.91.6%00
7.0.517.3656.91.6%00
7.0.517.3556.91.6%00
7.0.517.3456.91.6%00
7.0.517.3356.91.6%00
7.0.517.3256.91.6%00
7.0.517.3156.91.6%00
7.0.517.3056.91.6%00
7.0.517.2956.91.6%00
7.0.517.2856.91.6%00
7.0.517.2756.91.6%00
7.0.517.2656.91.6%00