Google Chromium V8 known exploited vulnerabilities, ranked
CISA lists 41 Google Chromium V8 CVEs as exploited in the wild. 5 were added in the last 12 months and 0 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2018-17463: EPSS 84.6%, added 2022-06-08
- CVE-2021-21224: EPSS 84.2%, added 2021-11-03
- CVE-2020-6418: EPSS 78.8%, added 2021-11-03
- CVE-2021-21220: EPSS 70.4%, added 2021-11-03
- CVE-2021-30551: EPSS 64.7%, added 2021-11-03
All 41 Google Chromium V8 CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2018-17463 | Chromium V8 Remote Code Execution | 84.6% | – | 2022-06-08 | 2022-06-22 |
| 2 | CVE-2021-21224 | Chromium V8 Type Confusion | 84.2% | – | 2021-11-03 | 2021-11-17 |
| 3 | CVE-2020-6418 | Chromium V8 Type Confusion | 78.8% | – | 2021-11-03 | 2022-05-03 |
| 4 | CVE-2021-21220 | Chromium V8 Improper Input Validation | 70.4% | – | 2021-11-03 | 2021-11-17 |
| 5 | CVE-2021-30551 | Chromium V8 Type Confusion | 64.7% | – | 2021-11-03 | 2021-11-17 |
| 6 | CVE-2021-30632 | Chromium V8 Out-of-Bounds Write | 63.2% | – | 2021-11-03 | 2021-11-17 |
| 7 | CVE-2018-6065 | Chromium V8 Integer Overflow | 60.3% | – | 2022-06-08 | 2022-06-22 |
| 8 | CVE-2019-5825 | Chromium V8 Out-of-Bounds Write | 55.9% | – | 2022-06-08 | 2022-06-22 |
| 9 | CVE-2026-85046 | Chromium V8 Type Confusion | 48.9% | – | 2026-09-04 | 2026-09-18 |
| 10 | CVE-2020-16009 | Chromium V8 Type Confusion | 48.3% | – | 2021-11-03 | 2022-05-03 |
| 11 | CVE-2016-1646 | Chromium V8 Out-of-Bounds Read | 48.1% | – | 2022-06-08 | 2022-06-22 |
| 12 | CVE-2023-4762 | Chromium V8 Type Confusion | 41.4% | – | 2024-02-06 | 2024-02-27 |
| 13 | CVE-2023-2033 | Chromium V8 Type Confusion | 40.8% | – | 2023-04-17 | 2023-05-08 |
| 14 | CVE-2017-5030 | Chromium V8 Memory Corruption | 40.6% | – | 2022-06-08 | 2022-06-22 |
| 15 | CVE-2021-38003 | Chromium V8 Memory Corruption | 38.6% | – | 2021-11-03 | 2021-11-17 |
| 16 | CVE-2018-17480 | Chromium V8 Out-of-Bounds Write | 35.6% | – | 2022-06-08 | 2022-06-22 |
| 17 | CVE-2021-37975 | Chromium V8 Use-After-Free | 34.9% | – | 2021-11-03 | 2021-11-17 |
| 18 | CVE-2016-5198 | Chromium V8 Out-of-Bounds Memory | 34.2% | – | 2022-06-08 | 2022-06-22 |
| 19 | CVE-2023-3079 | Chromium V8 Type Confusion | 32.1% | – | 2023-06-07 | 2023-06-28 |
| 20 | CVE-2017-5070 | Chromium V8 Type Confusion | 32.1% | – | 2022-06-08 | 2022-06-22 |
| 21 | CVE-2022-1096 | Chromium V8 Type Confusion | 24.2% | – | 2022-03-28 | 2022-04-18 |
| 22 | CVE-2022-4262 | Chromium V8 Type Confusion | 23.5% | – | 2022-12-05 | 2022-12-26 |
| 23 | CVE-2024-7971 | Chromium V8 Type Confusion | 21.1% | – | 2024-08-26 | 2024-09-16 |
| 24 | CVE-2021-21148 | Chromium V8 Heap Buffer Overflow | 20.0% | – | 2021-11-03 | 2021-11-17 |
| 25 | CVE-2024-7965 | Chromium V8 Inappropriate Implementation | 18.5% | – | 2024-08-28 | 2024-09-18 |
| 26 | CVE-2024-4947 | Chromium V8 Type Confusion | 15.2% | – | 2024-05-20 | 2024-06-10 |
| 27 | CVE-2025-6554 | Chromium V8 Type Confusion | 14.1% | – | 2025-07-02 | 2025-07-23 |
| 28 | CVE-2022-1364 | Chromium V8 Type Confusion | 13.7% | – | 2022-04-15 | 2022-05-06 |
| 29 | CVE-2024-4761 | Chromium V8 Out-of-Bounds Memory Write | 11.0% | – | 2024-05-16 | 2024-06-06 |
| 30 | CVE-2021-30563 | Chromium V8 Type Confusion | 9.0% | – | 2021-11-03 | 2021-11-17 |
| 31 | CVE-2022-3723 | Chromium V8 Type Confusion | 7.9% | – | 2022-10-28 | 2022-11-18 |
| 32 | CVE-2021-4102 | Chromium V8 Use-After-Free | 7.8% | – | 2021-12-15 | 2021-12-29 |
| 33 | CVE-2025-5419 | Chromium V8 Out-of-Bounds Read and Write | 7.8% | – | 2025-06-05 | 2025-06-26 |
| 34 | CVE-2024-5274 | Chromium V8 Type Confusion | 7.5% | – | 2024-05-28 | 2024-06-18 |
| 35 | CVE-2025-10585 | Chromium V8 Type Confusion | 5.4% | – | 2025-09-23 | 2025-10-14 |
| 36 | CVE-2025-13223 | Chromium V8 Type Confusion | 5.0% | – | 2025-11-19 | 2025-12-10 |
| 37 | CVE-2024-0519 | Chromium V8 Out-of-Bounds Memory Access | 3.8% | – | 2024-01-17 | 2024-02-07 |
| 38 | CVE-2026-87491 | Chromium V8 Out of Bounds Write | 3.1% | – | 2026-09-09 | 2026-09-23 |
| 39 | CVE-2020-16013 | Chromium V8 Incorrect Implementation Vulnerabililty | 2.8% | – | 2021-11-03 | 2022-05-03 |
| 40 | CVE-2026-11645 | Chromium V8 Out-of-Bounds Read and Write | 2.2% | – | 2026-06-09 | 2026-06-23 |
| 41 | CVE-2026-3910 | Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer | 1.0% | – | 2026-03-13 | 2026-03-27 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Google KEV CVEs · other Google products: Chromium · free KEV badge for Google · all vendors