Chrome CVEs per year
Hover over the bars for more details
Not exploited in the wildExploited in the wild
Disclosed Chrome CVEs per year. The red section is the share exploited in the wild before a patch shipped. Average severity sat in the High band (CVSS 7.0 to 8.9) most years, dipping just below in 2025.
Totals: NVD via stack.watch. Exploited: CISA KEV and Google TAG; counts vary by source and method. The series ends at 2025 because a re-import inflates 2026; by mid-2026 Chrome had seen five more exploited zero-days.