Technology · Google
Google Chromium vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 36 vulnerabilities in Google Chromium: 0 in the last 7 days and 2 in the last 90 days, 11 of them critical and 11 exploited in the wild. The most recent, CVE-2026-87491, was published on 9 September 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 11
- Exploited in the wild
- 11
Latest Google Chromium vulnerabilities
- CVE-2026-87491: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code…criticalexploited in the wildCVSS 8.8EPSS 3.1%
- CVE-2026-85046: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside…criticalexploited in the wildCVSS 8.8EPSS 48.9%
- CVE-2026-2441: Google Chromium use-after-free in CSScriticalexploited in the wildCVSS 8.8EPSS 23.1%
- CVE-2025-14174: Google Chromium out of bounds memory access in ANGLEcriticalexploited in the wildCVSS 8.8EPSS 0.3%
- CVE-2025-6558: Google Chromium improper input validation in ANGLE and GPUcriticalexploited in the wildCVSS 8.8EPSS 0.3%
- CVE-2025-6554: Google Chromium V8 type confusion in JavaScript enginecriticalexploited in the wildCVSS 8.1EPSS 1.6%
- CVE-2024-4671: Google Chromium Visuals Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 9.6
- CVE-2022-3723: Google Chromium V8 Type Confusion Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2021-37973: Google Chromium Portals Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 9.6
- CVE-2021-21166: Google Chromium Race Condition Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2021-37976: Google Chromium Information Disclosure Vulnerabilitycriticalexploited in the wildCVSS 6.5
- CVE-2016-9650: Google Chrome Blink no-referrer policy bypass in iframesmediumCVSS 4.3
- CVE-2016-5226: Google Chrome XSS via drag and drop in BlinkmediumCVSS 6.1
- CVE-2016-5225: Google Chrome CSP bypass in Blink form actionsmediumCVSS 4.3
- CVE-2016-5224: Google Chrome Same Origin Policy bypass in SVG filtersmediumCVSS 4.3
- CVE-2016-5223: Google Chrome integer overflow in PDFiummediumCVSS 6.5
- CVE-2016-5222: Google Chrome address spoofing in OmniboxmediumCVSS 6.5
- CVE-2016-5221: Google Chrome type confusion in ANGLE libGLESv2mediumCVSS 6.3
- CVE-2016-5220: Google Chrome local file disclosure in PDFiummediumCVSS 6.5
- CVE-2016-5219: Google Chrome V8 use after free in heapmediumCVSS 6.3
- CVE-2016-5218: Google Chrome address spoofing in Omnibox via PDF navigationmediumCVSS 6.5
- CVE-2016-5217: Google Chrome site isolation bypass in extensions API and PDFiummediumCVSS 6.5
- CVE-2016-5215: Google Chrome use after free in WebAudiomediumCVSS 6.3
- CVE-2016-5214: Google Chrome Mark of the Web bypass in file downloadsmediumCVSS 4.3
- CVE-2016-5213: Google Chrome use after free in V8 enginehighCVSS 8.8
Most severe Google Chromium vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-4671: Google Chromium Visuals Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 9.6
- CVE-2021-37973: Google Chromium Portals Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 9.6
- CVE-2026-85046: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside…criticalexploited in the wildCVSS 8.8EPSS 48.9%
- CVE-2026-2441: Google Chromium use-after-free in CSScriticalexploited in the wildCVSS 8.8EPSS 23.1%
- CVE-2026-87491: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code…criticalexploited in the wildCVSS 8.8EPSS 3.1%
- CVE-2025-6558: Google Chromium improper input validation in ANGLE and GPUcriticalexploited in the wildCVSS 8.8EPSS 0.3%
- CVE-2025-14174: Google Chromium out of bounds memory access in ANGLEcriticalexploited in the wildCVSS 8.8EPSS 0.3%
- CVE-2022-3723: Google Chromium V8 Type Confusion Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2021-21166: Google Chromium Race Condition Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2025-6554: Google Chromium V8 type confusion in JavaScript enginecriticalexploited in the wildCVSS 8.1EPSS 1.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 1 | 1 | |
| 7 Sep 2026 | 1 | 1 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/chromium.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Google Chromium vulnerabilities", https://junglewise.ai/threats/technologies/chromium, 26 September 2026.