Product of Google

Chromium

As of , 6 Google Chromium vulnerabilities are on CISA's list of exploited vulnerabilities; 1 was added in 2026. Patch first: CVE-2026-2441.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-2441CSS Use-After-FreeGoogle ChromiumPatch this weekEPSS 0.550.55
2CVE-2025-14174Out of Bounds Memory AccessGoogle ChromiumPatch soon0.22
3CVE-2021-21166Race ConditionGoogle ChromiumPatch soon0.24
4CVE-2021-37976Information DisclosureGoogle ChromiumPatch soon0.20
5CVE-2025-6558ANGLE and GPU Improper Input ValidationGoogle ChromiumPatch soon0.09
6CVE-2024-4671Visuals Use-After-FreeGoogle ChromiumPatch soon0.08

Added each year

1232021: 2220212022: nonenone20222023: nonenone20232024: 1120242025: 3320252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20212
2022none
2023none
20241
20253
20261

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-4664 Google ChromiumRemoved from CISA's list.

Every change we recorded

Removed from CISA's list

Removed from CISA's list
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-4664Loader Insufficient Policy EnforcementGoogle ChromiumRemoved from CISA's list0.06