Vulnerabilities > Google > Chrome

DATE CVE VULNERABILITY TITLE RISK
2024-07-16 CVE-2024-3170 Use After Free vulnerability in Google Chrome
Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2024-07-16 CVE-2024-3171 Use After Free vulnerability in Google Chrome
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures.
network
low complexity
google CWE-416
8.8
2024-07-16 CVE-2024-3172 Unspecified vulnerability in Google Chrome
Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page.
network
low complexity
google
8.8
2024-07-16 CVE-2024-3173 Insufficient Verification of Data Authenticity vulnerability in Google Chrome
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file.
network
low complexity
google CWE-345
8.8
2024-07-16 CVE-2024-3174 Unspecified vulnerability in Google Chrome
Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
network
low complexity
google
8.8
2024-07-16 CVE-2024-3175 Unspecified vulnerability in Google Chrome
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension.
network
low complexity
google
6.3
2024-07-16 CVE-2024-3176 Out-of-bounds Write vulnerability in Google Chrome
Out of bounds write in SwiftShader in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
network
low complexity
google CWE-787
8.8
2024-07-16 CVE-2024-5500 Unspecified vulnerability in Google Chrome
Inappropriate implementation in Sign-In in Google Chrome prior to 1.3.36.351 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google
6.5
2024-06-20 CVE-2024-6100 Type Confusion vulnerability in Google Chrome
Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
network
low complexity
google CWE-843
8.8
2024-06-20 CVE-2024-6101 Unspecified vulnerability in Google Chrome
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
network
low complexity
google
8.8