Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 100 of 107
CVE-2024-9963P4MEDIUMCVSS 4.3fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9963 [MEDIUM] CVE-2024-9963: chromium - Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.5...
Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.
debian
CVE-2024-9964P4MEDIUMCVSS 4.3fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9964 [MEDIUM] CVE-2024-9964: chromium - Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58...
Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.67
debian
CVE-2025-11215P4MEDIUMCVSS 4.3fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11215 [MEDIUM] CVE-2025-11215: chromium - Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote ...
Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1)
bullseye: open
forky: resolved (fixed in 141.0.7390.54-1)
sid: resolved (fixed in 141.0.7390.54-1)
trixie:
debian
CVE-2025-8577P4MEDIUMCVSS 4.3fixed in chromium 139.0.7258.66-1~deb12u1 (bookworm)2025
CVE-2025-8577 [MEDIUM] CVE-2025-8577: chromium - Inappropriate implementation in Picture In Picture in Google Chrome prior to 139...
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 139.0.7258.66-1~deb12u1)
bullseye: open
forky: resolved (fixed in 13
debian
CVE-2025-8579P4MEDIUMCVSS 4.3fixed in chromium 139.0.7258.66-1~deb12u1 (bookworm)2025
CVE-2025-8579 [MEDIUM] CVE-2025-8579: chromium - Inappropriate implementation in Picture In Picture in Google Chrome prior to 139...
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 139.0.7258.66-1~deb12u1)
bullseye: open
forky: resolved (fixed in 139.0
debian
CVE-2025-8582P4MEDIUMCVSS 4.3fixed in chromium 139.0.7258.66-1~deb12u1 (bookworm)2025
CVE-2025-8582 [MEDIUM] CVE-2025-8582: chromium - Insufficient validation of untrusted input in Core in Google Chrome prior to 139...
Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 139.0.7258.66-1~deb12u1)
bullseye: open
forky: resolved (fixed in 139.0.7258.66-1)
sid: resolved (fixe
debian
CVE-2023-7282P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-7282 [MEDIUM] CVE-2023-7282: chromium - Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672....
Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 113.0.5672.63-1)
bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1)
fork
debian
CVE-2026-2323P4MEDIUMCVSS 4.3fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2323 [MEDIUM] CVE-2026-2323: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.4...
Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.45-1)
sid: resolved (fixed in 145.0.7632.45-1)
trixie: res
debian
CVE-2025-12443P4MEDIUMCVSS 4.3fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12443 [MEDIUM] CVE-2025-12443: chromium - Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a re...
Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
tri
debian
CVE-2026-5891P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5891 [MEDIUM] CVE-2026-5891: chromium - Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.77...
Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2025-1923P4MEDIUMCVSS 4.3fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1923 [MEDIUM] CVE-2025-1923: chromium - Inappropriate implementation in Permission Prompts in Google Chrome prior to 134...
Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1)
bullseye: open
forky: resolved (fixed in 134.0
debian
CVE-2024-13178P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-13178 [MEDIUM] CVE-2024-13178: chromium - Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613....
Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.84-1)
trixi
debian
CVE-2025-12441P4MEDIUMCVSS 4.3fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12441 [MEDIUM] CVE-2025-12441: chromium - Out of bounds read in V8 in Google Chrome prior to 142.0.7444.59 allowed a remot...
Out of bounds read in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
trixie
debian
CVE-2026-5878P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5878 [MEDIUM] CVE-2026-5878: chromium - Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a...
Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5882P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5882 [MEDIUM] CVE-2026-5882: chromium - Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allo...
Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2025-9479P4MEDIUMCVSS 4.3fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-9479 [MEDIUM] CVE-2025-9479: chromium - Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remo...
Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1)
bullseye: open
forky: resolved (fixed in 133.0.6943.141-1)
sid: resolved (fixed in 133.0.6943.141-1)
trixie
debian
CVE-2025-13636P4MEDIUMCVSS 4.3fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13636 [MEDIUM] CVE-2025-13636: chromium - Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499....
Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted domain name. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.0.749
debian
CVE-2026-5875P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5875 [MEDIUM] CVE-2026-5875: chromium - Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote ...
Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-3942P4MEDIUMCVSS 4.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3942 [MEDIUM] CVE-2026-3942: chromium - Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.7...
Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie: res
debian
CVE-2026-3927P4MEDIUMCVSS 4.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3927 [MEDIUM] CVE-2026-3927: chromium - Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.7...
Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie:
debian