CyberMax
Home › Exploited CVEs › Google

Google Chromium V8 known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 41 Google Chromium V8 CVEs as exploited in the wild. 5 were added in the last 12 months and 0 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 41 Google Chromium V8 CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2018-17463Chromium V8 Remote Code Execution84.6%–2022-06-082022-06-22
2CVE-2021-21224Chromium V8 Type Confusion84.2%–2021-11-032021-11-17
3CVE-2020-6418Chromium V8 Type Confusion78.8%–2021-11-032022-05-03
4CVE-2021-21220Chromium V8 Improper Input Validation70.4%–2021-11-032021-11-17
5CVE-2021-30551Chromium V8 Type Confusion64.7%–2021-11-032021-11-17
6CVE-2021-30632Chromium V8 Out-of-Bounds Write63.2%–2021-11-032021-11-17
7CVE-2018-6065Chromium V8 Integer Overflow60.3%–2022-06-082022-06-22
8CVE-2019-5825Chromium V8 Out-of-Bounds Write55.9%–2022-06-082022-06-22
9CVE-2026-85046Chromium V8 Type Confusion48.9%–2026-09-042026-09-18
10CVE-2020-16009Chromium V8 Type Confusion48.3%–2021-11-032022-05-03
11CVE-2016-1646Chromium V8 Out-of-Bounds Read48.1%–2022-06-082022-06-22
12CVE-2023-4762Chromium V8 Type Confusion41.4%–2024-02-062024-02-27
13CVE-2023-2033Chromium V8 Type Confusion40.8%–2023-04-172023-05-08
14CVE-2017-5030Chromium V8 Memory Corruption40.6%–2022-06-082022-06-22
15CVE-2021-38003Chromium V8 Memory Corruption38.6%–2021-11-032021-11-17
16CVE-2018-17480Chromium V8 Out-of-Bounds Write35.6%–2022-06-082022-06-22
17CVE-2021-37975Chromium V8 Use-After-Free34.9%–2021-11-032021-11-17
18CVE-2016-5198Chromium V8 Out-of-Bounds Memory34.2%–2022-06-082022-06-22
19CVE-2023-3079Chromium V8 Type Confusion32.1%–2023-06-072023-06-28
20CVE-2017-5070Chromium V8 Type Confusion32.1%–2022-06-082022-06-22
21CVE-2022-1096Chromium V8 Type Confusion24.2%–2022-03-282022-04-18
22CVE-2022-4262Chromium V8 Type Confusion23.5%–2022-12-052022-12-26
23CVE-2024-7971Chromium V8 Type Confusion21.1%–2024-08-262024-09-16
24CVE-2021-21148Chromium V8 Heap Buffer Overflow20.0%–2021-11-032021-11-17
25CVE-2024-7965Chromium V8 Inappropriate Implementation18.5%–2024-08-282024-09-18
26CVE-2024-4947Chromium V8 Type Confusion15.2%–2024-05-202024-06-10
27CVE-2025-6554Chromium V8 Type Confusion14.1%–2025-07-022025-07-23
28CVE-2022-1364Chromium V8 Type Confusion13.7%–2022-04-152022-05-06
29CVE-2024-4761Chromium V8 Out-of-Bounds Memory Write11.0%–2024-05-162024-06-06
30CVE-2021-30563Chromium V8 Type Confusion9.0%–2021-11-032021-11-17
31CVE-2022-3723Chromium V8 Type Confusion7.9%–2022-10-282022-11-18
32CVE-2021-4102Chromium V8 Use-After-Free7.8%–2021-12-152021-12-29
33CVE-2025-5419Chromium V8 Out-of-Bounds Read and Write7.8%–2025-06-052025-06-26
34CVE-2024-5274Chromium V8 Type Confusion7.5%–2024-05-282024-06-18
35CVE-2025-10585Chromium V8 Type Confusion5.4%–2025-09-232025-10-14
36CVE-2025-13223Chromium V8 Type Confusion5.0%–2025-11-192025-12-10
37CVE-2024-0519Chromium V8 Out-of-Bounds Memory Access3.8%–2024-01-172024-02-07
38CVE-2026-87491Chromium V8 Out of Bounds Write3.1%–2026-09-092026-09-23
39CVE-2020-16013Chromium V8 Incorrect Implementation Vulnerabililty2.8%–2021-11-032022-05-03
40CVE-2026-11645Chromium V8 Out-of-Bounds Read and Write2.2%–2026-06-092026-06-23
41CVE-2026-3910Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer1.0%–2026-03-132026-03-27
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Google KEV CVEs · other Google products: Chromium · free KEV badge for Google · all vendors