basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / Google Chrome
Product security contributor

Google Chrome

cited as evidence in 36 · CNA assigner on 76 of 76 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

chromereleases.googleblog.com ↗ · home of the cited advisories

76
records cited in
deterministic count
0
finder / reporter credits
CVE.org credits
76
CVE records catalogued (CNA)
assigner
28%
avg modeled exploit prob.
FIRST EPSS, 76/76
1%
ransomware-associated
1 of 76 · CISA flag
R

Roles across the work

— find / fix / exploit / catalog, computed per record from credit type, the vendor-self-CNA gate, and the linked public exploit catalog
0
Find
record(s)
76
Fix
record(s)
0
Exploit
record(s)
0
Catalog
record(s)

Part of the Google family — a hard rollup: this sub-unit’s work aggregates under Google.

Each dimension is a count of the listed records where this contributor did that job. A CNA row is fix only when the affected product is the assigner’s own; registries, coordinators, platforms, intel and research houses read as catalog, never fix. Exploit counts records where this contributor is credited as author of a public exploit / detection template in a linked catalog — we link the catalog, never host a payload.

01

Known for

— recomputed from this contributor’s own records
SurfacesBrowser (71), Application / other (3), Operating system / kernel (2)
WeaknessMemory safety (64), Authorization / access control (3)
PortfolioGoogle (73), Linux (2), WebRTC (1)
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
73reach this stage
→
2Keys to the kingdom
73reach this stage
→
3Lateral reach
67reach this stage
→
4Data at risk
2reach this stage
→
5Lights out
0reach this stage

Furthest any of these records carries an attacker: 4 · Data at risk. 2 of 73 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 76, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

CVE-2022-2294WebRTC70%RWKEVCVE-2023-4863Google100%KEVCVE-2018-17463Google85%KEVCVE-2021-21224Google84%KEVCVE-2016-5195Linux84%KEVCVE-2020-6418Google79%KEVCVE-2021-21220Google70%KEVCVE-2021-30551Google65%KEVCVE-2021-30632Google63%KEVCVE-2019-5786Google62%KEVCVE-2018-6065Google60%KEVCVE-2019-5825Google56%KEVCVE-2026-2441Google55%KEVCVE-2019-13720Google49%KEVCVE-2023-5217Google49%KEVCVE-2026-85046Google49%KEVCVE-2020-16009Google48%KEVCVE-2016-1646Google48%KEVCVE-2020-15999Google44%KEVCVE-2023-4762Google41%KEVCVE-2023-2033Google41%KEVCVE-2017-5030Google41%KEVCVE-2021-38003Google39%KEVCVE-2014-3153Linux37%KEVCVE-2018-17480Google36%KEVCVE-2021-37975Google35%KEVCVE-2016-5198Google34%KEVCVE-2021-30633Google33%KEVCVE-2023-3079Google32%KEVCVE-2017-5070Google32%KEVCVE-2022-4135Google32%KEVCVE-2022-3038Google25%KEVCVE-2022-1096Google24%KEVCVE-2021-21166Google24%KEVCVE-2022-0609Google23%KEVCVE-2025-14174Google22%KEVCVE-2024-7971Google21%KEVCVE-2021-21148Google20%KEVCVE-2021-37976Google20%KEVCVE-2024-7965Google19%KEVCVE-2021-30533Google17%KEVCVE-2023-6345Google16%KEVCVE-2022-4262Google16%KEVCVE-2024-4947Google15%KEVCVE-2022-1364Google14%KEVCVE-2025-6554Google13%KEVCVE-2021-37973Google12%KEVCVE-2024-4761Google11%KEVCVE-2020-6572Google11%KEVCVE-2021-21193Google10%KEVCVE-2025-6558Google10%KEVCVE-2021-21206Google9%KEVCVE-2025-2783Google9%KEVCVE-2021-30563Google9%KEVCVE-2024-4671Google8%KEVCVE-2022-3723Google8%KEVCVE-2021-4102Google8%KEVCVE-2025-5419Google8%KEVCVE-2024-5274Google7%KEVCVE-2021-30554Google7%KEVCVE-2023-7024Google7%KEVCVE-2020-16010Google6%KEVCVE-2022-3075Google6%KEVCVE-2023-2136Google6%KEVCVE-2025-10585Google5%KEVCVE-2025-13223Google5%KEVCVE-2021-38000Google5%KEVCVE-2022-2856Google5%KEVCVE-2024-0519Google4%KEVCVE-2026-87491Google3%KEVCVE-2020-16013Google3%KEVCVE-2020-16017Google3%KEVCVE-2026-11645Google2%KEVCVE-2026-3910Google1%KEVCVE-2026-3909Google1%KEVCVE-2026-5281Google1%KEV
05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 76 known-exploited records — the list below; every one links to its public source.
  • Catalogued 76 CVE record(s) as the CNA assigner (from CVE.org).
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.