Google / Chrome OS
67 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-6044 | An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical at… | MEDIUM | 6.1 | Jul 7, 2025 |
| CVE-2025-6179 | ChromeOS Extension Disablement and Developer Mode Bypass via ExtHang3r and ExtPrint3r Exploits | CRITICAL | 9.8 | Jun 16, 2025 |
| CVE-2025-6177 | ChromeOS MiniOS Root Code Execution Bypass While Dev Mode Blocked | HIGH | 7.4 | Jun 16, 2025 |
| CVE-2025-2509 | Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process,… | HIGH | 7.8 | May 6, 2025 |
| CVE-2025-1290 | A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and… | HIGH | 8.1 | Apr 17, 2025 |
| CVE-2025-1568 | Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to in… | HIGH | 8.8 | Apr 16, 2025 |
| CVE-2025-2073 | Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bo… | HIGH | 8.8 | Apr 16, 2025 |
| CVE-2025-1704 | ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices… | MEDIUM | 6.5 | Apr 16, 2025 |
| CVE-2025-1566 | DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose plaintext DNS queries via failure to pro… | HIGH | 7.5 | Apr 16, 2025 |
| CVE-2025-1121 | Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain r… | MEDIUM | 6.8 | Mar 6, 2025 |
| CVE-2022-2743 | Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in… | HIGH | 8.8 | Jan 2, 2023 |
| CVE-2014-3180 | kernel: out-of-bounds read in kernel/compact.c | CRITICAL | 9.1 | Nov 6, 2019 |
| CVE-2019-16508 | The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integ… | HIGH | 7.8 | Oct 1, 2019 |
| CVE-2016-5179 | Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot. | CRITICAL | 9.8 | Mar 6, 2018 |
| CVE-2017-15400 | cups: Insufficient restriction of IPP filters allows a remote attacker to execute commands with the privilege level of cups daemon | HIGH | 7.8 | Feb 7, 2018 |
| CVE-2017-15397 | Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or ta… | HIGH | 7.4 | Feb 7, 2018 |
| CVE-2017-5084 | Inappropriate implementation in image-burner in Google Chrome OS prior to 59.0.3071.92 allowed a local attacker to read local files via dbus-send commands to a… | LOW | 3.3 | Oct 27, 2017 |
| CVE-2016-5169 | Format string vulnerability in Google Chrome OS before 53.0.2785.103 allows remote attackers to cause a denial of service or possibly have unspecified other im… | HIGH | 8.8 | Sep 25, 2016 |
| CVE-2014-3188 | v8: IPC and v8 issue fixed in Google Chrome 38.0.2125.101 | HIGH | 10.0 | Oct 8, 2014 |
| CVE-2014-1711 | The GPU driver in the kernel in Google Chrome OS before 33.0.1750.152 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly ha… | HIGH | 7.5 | Mar 16, 2014 |
| CVE-2014-1710 | The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS before 33.0.17… | HIGH | 7.5 | Mar 16, 2014 |
| CVE-2014-1708 | The boot implementation in Google Chrome OS before 33.0.1750.152 does not properly consider file persistence, which allows remote attackers to execute arbitrar… | HIGH | 10.0 | Mar 16, 2014 |
| CVE-2014-1707 | Directory traversal vulnerability in CrosDisks in Google Chrome OS before 33.0.1750.152 has unspecified impact and attack vectors. | HIGH | 7.5 | Mar 16, 2014 |
| CVE-2014-1706 | crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors. | HIGH | 7.5 | Mar 16, 2014 |
| CVE-2013-2866 | The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a… | MEDIUM | 4.3 | Jun 19, 2013 |
Showing 1 to 25 of 67 CVEs