Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 1 of 107
CVE-2023-4863P1LOWCVSS 8.8KEVPoCfixed in chromium 117.0.5938.62-1 (bookworm)2023
CVE-2023-4863 [HIGH] CVE-2023-4863: chromium - Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and lib...
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1)
bullseye: resolved (fixed in 117.0.5938.62-1)
forky: resolved (fixed in 117.0.5938.62-1)
debian
CVE-2020-6418P1HIGHCVSS 8.8KEVPoCfixed in chromium 80.0.3987.122-1 (bookworm)2020
CVE-2020-6418 [HIGH] CVE-2020-6418: chromium - Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote at...
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.122-1)
bullseye: resolved (fixed in 80.0.3987.122-1)
forky: resolved (fixed in 80.0.3987.122-1)
sid: resolved (fixed in 80.0.3987.122-1)
trixie: resolved (fixed in 80
debian
CVE-2021-21220P1HIGHCVSS 8.8KEVPoCfixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21220 [HIGH] CVE-2021-21220: chromium - Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0....
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1)
tri
debian
CVE-2021-30632P1HIGHCVSS 8.8KEVPoCfixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30632 [HIGH] CVE-2021-30632: chromium - Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remot...
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in
debian
CVE-2021-30551P1HIGHCVSS 8.8KEVPoCfixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30551 [HIGH] CVE-2021-30551: chromium - Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote at...
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in 93.0
debian
CVE-2023-5217P1HIGHCVSS 8.8KEVPoCfixed in chromium 117.0.5938.132-1~deb12u1 (bookworm)2023
CVE-2023-5217 [HIGH] CVE-2023-5217: chromium - Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5...
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 117.0.5938.132-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.132-1~deb11u1)
forky: resolved
debian
CVE-2019-13720P1HIGHCVSS 8.8KEVPoCfixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13720 [HIGH] CVE-2019-13720: chromium - Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remo...
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in
debian
CVE-2021-21224P1HIGHCVSS 8.8KEVPoCfixed in chromium 90.0.4430.85-1 (bookworm)2021
CVE-2021-21224 [HIGH] CVE-2021-21224: chromium - Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote att...
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.85-1)
bullseye: resolved (fixed in 90.0.4430.85-1)
forky: resolved (fixed in 90.0.4430.85-1)
sid: resolved (fixed in 90.0.4430.85-1)
trixie: resolved (fixed in 9
debian
CVE-2023-2033P1HIGHCVSS 8.8KEVPoCfixed in chromium 112.0.5615.121-1 (bookworm)2023
CVE-2023-2033 [HIGH] CVE-2023-2033: chromium - Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote a...
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 112.0.5615.121-1)
bullseye: resolved (fixed in 112.0.5615.121-1~deb11u1)
forky: resolved (fixed in 112.0.5615.121-1)
sid: resolved (fixed in
debian
CVE-2026-2441P1HIGHCVSS 8.8KEVPoCfixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2441 [HIGH] CVE-2026-2441: chromium - Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote a...
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.75-1)
sid: resolved (fixed in 145.0.7632.75-1)
trixie: reso
debian
CVE-2025-14174P1LOWCVSS 8.8KEVPoCfixed in webkit2gtk 2.50.4-1~deb12u1 (bookworm)2025
CVE-2025-14174 [HIGH] CVE-2025-14174: chromium - Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499...
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2023-3079P1HIGHCVSS 8.8KEVPoCfixed in chromium 114.0.5735.106-1~deb12u1 (bookworm)2023
CVE-2023-3079 [HIGH] CVE-2023-3079: chromium - Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote a...
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 114.0.5735.106-1~deb12u1)
bullseye: resolved (fixed in 114.0.5735.106-1~deb11u1)
forky: resolved (fixed in 114.0.5735.106-1)
sid: resolved (
debian
CVE-2025-24201P1CRITICALCVSS 10.0KEVPoCfixed in chromium 134.0.6998.88-1~deb12u1 (bookworm)2025
CVE-2025-24201 [CRITICAL] CVE-2025-24201: chromium - An out-of-bounds write issue was addressed with improved checks to prevent unaut...
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Conte
debian
CVE-2024-7971P1CRITICALCVSS 9.6KEVPoCfixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7971 [CRITICAL] CVE-2024-7971: chromium - Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote at...
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.84-1)
trixie: resolved (fixed i
debian
CVE-2021-38003P1HIGHCVSS 8.8KEVPoCfixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38003 [HIGH] CVE-2021-38003: chromium - Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowe...
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
tr
debian
CVE-2023-4762P1HIGHCVSS 8.8KEVPoCfixed in chromium 116.0.5845.180-1~deb12u1 (bookworm)2023
CVE-2023-4762 [HIGH] CVE-2023-4762: chromium - Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote a...
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 116.0.5845.180-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.180-1~deb11u1)
forky: resolved (fixed in 116.0.5845.180-1)
sid: resolved (fixed in 116.
debian
CVE-2024-4947P1CRITICALCVSS 9.6KEVPoCfixed in chromium 125.0.6422.60-1~deb12u1 (bookworm)2024
CVE-2024-4947 [CRITICAL] CVE-2024-4947: chromium - Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 125.0.6422.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 125.0.6422.60-1)
sid: resolved (fixed in 125.0.6422.60-1)
trixie: r
debian
CVE-2019-5786P1MEDIUMCVSS 6.5KEVPoCfixed in chromium 72.0.3626.121-1 (bookworm)2019
CVE-2019-5786 [MEDIUM] CVE-2019-5786: chromium - Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a...
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 72.0.3626.121-1)
bullseye: resolved (fixed in 72.0.3626.121-1)
forky: resolved (fixed in 72.0.3626.121-1)
sid: resolved (fixed in 72.0.3626.121-1)
trixi
debian
CVE-2024-5274P1CRITICALCVSS 9.6KEVPoCfixed in chromium 125.0.6422.112-1~deb12u1 (bookworm)2024
CVE-2024-5274 [CRITICAL] CVE-2024-5274: chromium - Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote a...
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 125.0.6422.112-1~deb12u1)
bullseye: open
forky: resolved (fixed in 125.0.6422.112-1)
sid: resolved (fixed in 125.0.6422.112-1)
trixi
debian
CVE-2024-7965P1HIGHCVSS 8.8KEVPoCfixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7965 [HIGH] CVE-2024-7965: chromium - Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allow...
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.84-1)
tri
debian
1 / 107Next →