FAIL › dossier
Chromium
PRODUCT· dossier confidence 33%
Google Chrome, a widely used web browser, has a history of significant security vulnerabilities, including multiple remote code execution flaws and information disclosure issues. The frequent occurrence of high-severity vulnerabilities suggests ongoing challenges in secure development practices and code maintenance.
PROFILE
CategoryWeb BrowserWhat they doGoogle Chrome is a widely used web browser developed by Google. It is known for its features and integration with Google's services.
Websitehttps://chromereleases.googleblog.com/ ↗
SECURITY POSTURE
Chromium exhibits a recurring pattern of high-severity remote code execution (RCE) vulnerabilities, indicating a significant challenge in maintaining secure code.
Notable failures
- CVE-2026-2441: Chrome rce due to CSS use-after-free
- CVE-2025-14174: Out-of-bounds memory access flaw exploited
- CVE-2025-6558: ANGLE and GPU input validation flaw exploited remotely
- CVE-2024-4671: Use-after-free vulnerability leading to heap corruption
- CVE-2021-21166: Race condition vulnerability leading to heap corruption
- CVE-2021-37976: Information disclosure vulnerability in core memory component
Patterns: Recurring RCE vulnerabilities; Use-after-free vulnerabilities; Heap corruption exploitation; GPU related vulnerabilities
FAILURE HISTORY · 6
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2021-21166 | high | A race condition in Google Chromium allows remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers. |
| 2026-02-17 | CVE-2026-2441 | high | Chrome rce due to CSS use-after-free |
| 2025-12-12 | CVE-2025-14174 | high | Google Chromium out-of-bounds memory access flaw exploited |
| 2025-07-22 | CVE-2025-6558 | high | Google Chromium ANGLE and GPU input validation flaw exploited remotely |
| 2021-11-03 | CVE-2021-37976 | high | A remote attacker could extract sensitive data from Chromium browser processes via a crafted HTML page due to an unpatched memory disclosure flaw. |
| 2024-05-13 | CVE-2024-4671 | high | Google Chromium's use-after-free vulnerability (CVE-2024-4671) allows remote attackers to exploit heap corruption via crafted HTML pages. |
DOSSIER SOURCES
- Chrome Releases · chromereleases.googleblog.com
- Releases · release-monitoring-project/chromium-release-tracker - GitHub · github.com
- CVE-2026-16804: Chrome 150.0.7871.186 Fixes Sandbox Escape Risk · windowsforum.com
Open questions: What is the current patching cadence for Chromium? · What is the extent of Chromium's use within the DIB environment?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-28 12:38:07.743432+00:00