cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 10 of 107
CVE-2026-5873P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5873 [HIGH] CVE-2026-5873: chromium - Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allow... Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-4447P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4447 [HIGH] CVE-2026-4447: chromium - Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allo... Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.15
debian
CVE-2026-5279P3HIGHCVSS 8.8fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5279 [HIGH] CVE-2026-5279: chromium - Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remot... Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1) sid: resolved (fixed in 146.0.7680.177-1) trixie
debian
CVE-2026-5871P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5871 [HIGH] CVE-2026-5871: chromium - Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5862P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5862 [HIGH] CVE-2026-5862: chromium - Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allow... Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5877P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5877 [HIGH] CVE-2026-5877: chromium - Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a r... Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5863P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5863 [HIGH] CVE-2026-5863: chromium - Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allow... Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5884P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5884 [HIGH] CVE-2026-5884: chromium - Insufficient validation of untrusted input in Media in Google Chrome prior to 14... Insufficient validation of untrusted input in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: o
debian
CVE-2021-30599P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30599 [HIGH] CVE-2021-30599: chromium - Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote at... Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in
debian
CVE-2022-0290P3CRITICALCVSS 9.6fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0290 [CRITICAL] CVE-2022-0290: chromium - Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed ... Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.99-1) bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2) forky: resolved (fixed in 97.0.4692.99-1) sid: resolved (fixed in 97.0.4692.99-1) trixie: r
debian
CVE-2023-1529P3CRITICALCVSS 9.8fixed in chromium 111.0.5563.110-1 (bookworm)2023
CVE-2023-1529 [CRITICAL] CVE-2023-1529: chromium - Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 a... Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 111.0.5563.110-1) bullseye: resolved (fixed in 111.0.5563.110-1~deb11u1) forky: resolved (fixed in 111.0.5563.110-1)
debian
CVE-2024-4558P3CRITICALCVSS 9.6fixed in chromium 124.0.6367.155-1~deb12u1 (bookworm)2024
CVE-2024-4558 [CRITICAL] CVE-2024-4558: chromium - Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remot... Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 124.0.6367.155-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.155-1) sid: resolved (fixed in 124.0.6367.155-1) trixie
debian
CVE-2024-2883P3HIGHCVSS 8.8fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2883 [HIGH] CVE-2024-2883: chromium - Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote... Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) Scope: local bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1) bullseye: open forky: resolved (fixed in 123.0.6312.86-1) sid: resolved (fixed in 123.0.6312.86-1) trixie: re
debian
CVE-2023-4428P3HIGHCVSS 8.1fixed in chromium 116.0.5845.110-1~deb12u1 (bookworm)2023
CVE-2023-4428 [HIGH] CVE-2023-4428: chromium - Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allo... Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.110-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.110-1~deb11u1) forky: resolved (fixed in 116.0.5845.110-1)
debian
CVE-2024-1939P3HIGHCVSS 8.8fixed in chromium 122.0.6261.94-1~deb12u1 (bookworm)2024
CVE-2024-1939 [HIGH] CVE-2024-1939: chromium - Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 122.0.6261.94-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.94-1) sid: resolved (fixed in 122.0.6261.94-1) trixie: resolved
debian
CVE-2025-5280P3HIGHCVSS 8.8fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5280 [HIGH] CVE-2025-5280: chromium - Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remo... Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1) bullseye: open forky: resolved (fixed in 137.0.7151.55-1) sid: resolved (fixed in 137.0.7151.55-1) trixie: reso
debian
CVE-2026-3545P3CRITICALCVSS 9.6fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3545 [CRITICAL] CVE-2026-3545: chromium - Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.... Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632.159-1) sid: resolved (fixed in 145.
debian
CVE-2026-5290P3CRITICALCVSS 9.6fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5290 [CRITICAL] CVE-2026-5290: chromium - Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a... Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1)
debian
CVE-2024-3159P3HIGHCVSS 8.8fixed in chromium 123.0.6312.105-1~deb12u1 (bookworm)2024
CVE-2024-3159 [HIGH] CVE-2024-3159: chromium - Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allow... Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 123.0.6312.105-1~deb12u1) bullseye: open forky: resolved (fixed in 123.0.6312.105-1) sid: resolved (fixed in 123.0.6312.105-1) trixie:
debian
CVE-2025-10890P3CRITICALCVSS 9.1fixed in chromium 140.0.7339.207-1~deb12u1 (bookworm)2025
CVE-2025-10890 [CRITICAL] CVE-2025-10890: chromium - Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 ... Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 140.0.7339.207-1~deb12u1) bullseye: open forky: resolved (fixed in 140.0.7339.207-1) sid: resolved (fixed in 140.0.7339.207-1) tr
debian
Debian Chromium vulnerabilities | cvebase