Skip to content
COOEY

FAIL › dossier

Chromium

PRODUCT

· dossier confidence 33%

Google Chrome, a widely used web browser, has a history of significant security vulnerabilities, including multiple remote code execution flaws and information disclosure issues. The frequent occurrence of high-severity vulnerabilities suggests ongoing challenges in secure development practices and code maintenance.

PROFILE
CategoryWeb BrowserWhat they doGoogle Chrome is a widely used web browser developed by Google. It is known for its features and integration with Google's services. Websitehttps://chromereleases.googleblog.com/ ↗
SECURITY POSTURE

Chromium exhibits a recurring pattern of high-severity remote code execution (RCE) vulnerabilities, indicating a significant challenge in maintaining secure code.

Notable failures
  • CVE-2026-2441: Chrome rce due to CSS use-after-free
  • CVE-2025-14174: Out-of-bounds memory access flaw exploited
  • CVE-2025-6558: ANGLE and GPU input validation flaw exploited remotely
  • CVE-2024-4671: Use-after-free vulnerability leading to heap corruption
  • CVE-2021-21166: Race condition vulnerability leading to heap corruption
  • CVE-2021-37976: Information disclosure vulnerability in core memory component
Patterns: Recurring RCE vulnerabilities; Use-after-free vulnerabilities; Heap corruption exploitation; GPU related vulnerabilities
FAILURE HISTORY · 6
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-21166 high A race condition in Google Chromium allows remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers.
2026-02-17 CVE-2026-2441 high Chrome rce due to CSS use-after-free
2025-12-12 CVE-2025-14174 high Google Chromium out-of-bounds memory access flaw exploited
2025-07-22 CVE-2025-6558 high Google Chromium ANGLE and GPU input validation flaw exploited remotely
2021-11-03 CVE-2021-37976 high A remote attacker could extract sensitive data from Chromium browser processes via a crafted HTML page due to an unpatched memory disclosure flaw.
2024-05-13 CVE-2024-4671 high Google Chromium's use-after-free vulnerability (CVE-2024-4671) allows remote attackers to exploit heap corruption via crafted HTML pages.
Open questions: What is the current patching cadence for Chromium? · What is the extent of Chromium's use within the DIB environment?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-28 12:38:07.743432+00:00