Google Chrome: vulnerabilidades y CVE
Google Chrome tiene 6690 vulnerabilidades publicadas, 3014 de ellas en los últimos 12 meses. 490 son críticas y 77 figuran en el catálogo de explotación activa de CISA.
CVE6690
Últimos 12 meses3014
Críticas490
Explotadas activamente77
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-87491 | Alta (8.8) | 3.1% | ⚠ Explotación activa | 9 sept 2026 | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-85046 | Alta (8.8) | 49% | ⚠ Explotación activa | 3 sept 2026 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-11645 | Alta (8.8) | 2.2% | ⚠ Explotación activa | 9 jun 2026 | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-5281 | Alta (8.8) | 0.70% | ⚠ Explotación activa | 1 abr 2026 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-3909 | Alta (8.8) | 0.70% | ⚠ Explotación activa | 13 mar 2026 | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-3910 | Alta (8.8) | 1.0% | ⚠ Explotación activa | 13 mar 2026 | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-2441 | Alta (8.8) | 55% | ⚠ Explotación activa | 13 feb 2026 | Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2025-14174 | Alta (8.8) | 22% | ⚠ Explotación activa | 12 dic 2025 | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) |
| CVE-2025-13223 | Alta (8.8) | 5.0% | ⚠ Explotación activa | 17 nov 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2025-10585 | Crítica (9.8) | 5.4% | ⚠ Explotación activa | 24 sept 2025 | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2025-6558 | Alta (8.8) | 9.6% | ⚠ Explotación activa | 15 jul 2025 | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security… |
| CVE-2025-6554 | Alta (8.1) | 13% | ⚠ Explotación activa | 30 jun 2025 | Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) |
| CVE-2025-5419 | Alta (8.8) | 7.8% | ⚠ Explotación activa | 3 jun 2025 | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2025-2783 | Alta (8.3) | 9.2% | ⚠ Explotación activa | 26 mar 2025 | Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity:… |
| CVE-2014-0497 | Crítica (9.8) | 100% | ⚠ Explotación activa | 5 feb 2014 | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via… |
| CVE-2024-7965 | Alta (8.8) | 19% | ⚠ Explotación activa | 21 ago 2024 | Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-7971 | Crítica (9.6) | 21% | ⚠ Explotación activa | 21 ago 2024 | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-5274 | Crítica (9.6) | 7.5% | ⚠ Explotación activa | 28 may 2024 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-4947 | Crítica (9.6) | 15% | ⚠ Explotación activa | 15 may 2024 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-4761 | Alta (8.8) | 11% | ⚠ Explotación activa | 14 may 2024 | Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-102331 | Crítica (9.6) | 0.43% | — | 29 sept 2026 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity:… |
| CVE-2026-102330 | Media (6.5) | 0.23% | — | 29 sept 2026 | Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security… |
| CVE-2026-102329 | Media (6.1) | 0.18% | — | 29 sept 2026 | Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102328 | Alta (8.8) | 0.33% | — | 29 sept 2026 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102327 | Alta (7.5) | 0.27% | — | 29 sept 2026 | Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a… |
| CVE-2026-102326 | Alta (8.8) | 0.33% | — | 29 sept 2026 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102325 | Media (4.3) | 0.23% | — | 29 sept 2026 | Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102324 | Alta (8.3) | 0.27% | — | 29 sept 2026 | Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML… |
| CVE-2026-102323 | Alta (8.8) | 0.41% | — | 29 sept 2026 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102321 | Alta (8.8) | 0.34% | — | 29 sept 2026 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102320 | Media (6.5) | 0.23% | — | 29 sept 2026 | Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity:… |
| CVE-2026-102319 | Baja (3.4) | 0.21% | — | 29 sept 2026 | Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security… |
| CVE-2026-102318 | Media (4.7) | 0.21% | — | 29 sept 2026 | Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102317 | Alta (8.6) | 0.11% | — | 29 sept 2026 | Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security… |
| CVE-2026-102316 | Crítica (9.6) | 0.31% | — | 29 sept 2026 | Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity:… |
| CVE-2026-102315 | Baja (3.4) | 0.21% | — | 29 sept 2026 | Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page.… |
| CVE-2026-102314 | Media (5.4) | 0.21% | — | 29 sept 2026 | UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) |
| CVE-2026-102313 | Media (4.7) | 0.28% | — | 29 sept 2026 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102312 | Media (4.3) | 0.24% | — | 29 sept 2026 | UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102311 | Baja (3.4) | 0.25% | — | 29 sept 2026 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page.… |
| CVE-2026-102310 | Media (6.5) | 0.24% | — | 29 sept 2026 | Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security… |
| CVE-2026-102309 | Crítica (9.6) | 0.31% | — | 29 sept 2026 | Use after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102308 | Crítica (9.6) | 0.31% | — | 29 sept 2026 | Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity:… |
| CVE-2026-102307 | Media (4.7) | 0.28% | — | 29 sept 2026 | Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102306 | Crítica (9.6) | 0.37% | — | 29 sept 2026 | Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102305 | Media (5.4) | 0.21% | — | 29 sept 2026 | UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) |
| CVE-2026-102304 | Crítica (9.6) | 0.31% | — | 29 sept 2026 | Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-102303 | Media (4.3) | 0.28% | — | 29 sept 2026 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-95385 | Sin puntuar | 0.23% | — | 29 sept 2026 | Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML… |
| CVE-2026-95381 | Alta (8.3) | 0.40% | — | 29 sept 2026 | Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.