cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 100 of 107
CVE-2024-9963P4MEDIUMCVSS 4.3fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9963 [MEDIUM] CVE-2024-9963: chromium - Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.5... Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1) bullseye: open forky: resolved (fixed in 130.0.6723.
debian
CVE-2024-9964P4MEDIUMCVSS 4.3fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9964 [MEDIUM] CVE-2024-9964: chromium - Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58... Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1) bullseye: open forky: resolved (fixed in 130.0.67
debian
CVE-2025-11215P4MEDIUMCVSS 4.3fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11215 [MEDIUM] CVE-2025-11215: chromium - Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote ... Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1) bullseye: open forky: resolved (fixed in 141.0.7390.54-1) sid: resolved (fixed in 141.0.7390.54-1) trixie:
debian
CVE-2025-8577P4MEDIUMCVSS 4.3fixed in chromium 139.0.7258.66-1~deb12u1 (bookworm)2025
CVE-2025-8577 [MEDIUM] CVE-2025-8577: chromium - Inappropriate implementation in Picture In Picture in Google Chrome prior to 139... Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 139.0.7258.66-1~deb12u1) bullseye: open forky: resolved (fixed in 13
debian
CVE-2025-8579P4MEDIUMCVSS 4.3fixed in chromium 139.0.7258.66-1~deb12u1 (bookworm)2025
CVE-2025-8579 [MEDIUM] CVE-2025-8579: chromium - Inappropriate implementation in Picture In Picture in Google Chrome prior to 139... Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 139.0.7258.66-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0
debian
CVE-2025-8582P4MEDIUMCVSS 4.3fixed in chromium 139.0.7258.66-1~deb12u1 (bookworm)2025
CVE-2025-8582 [MEDIUM] CVE-2025-8582: chromium - Insufficient validation of untrusted input in Core in Google Chrome prior to 139... Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 139.0.7258.66-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0.7258.66-1) sid: resolved (fixe
debian
CVE-2023-7282P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-7282 [MEDIUM] CVE-2023-7282: chromium - Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.... Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 113.0.5672.63-1) bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1) fork
debian
CVE-2026-2323P4MEDIUMCVSS 4.3fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2323 [MEDIUM] CVE-2026-2323: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.4... Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632.45-1) sid: resolved (fixed in 145.0.7632.45-1) trixie: res
debian
CVE-2025-12443P4MEDIUMCVSS 4.3fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12443 [MEDIUM] CVE-2025-12443: chromium - Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a re... Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) tri
debian
CVE-2026-5891P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5891 [MEDIUM] CVE-2026-5891: chromium - Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.77... Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2025-1923P4MEDIUMCVSS 4.3fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1923 [MEDIUM] CVE-2025-1923: chromium - Inappropriate implementation in Permission Prompts in Google Chrome prior to 134... Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1) bullseye: open forky: resolved (fixed in 134.0
debian
CVE-2024-13178P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-13178 [MEDIUM] CVE-2024-13178: chromium - Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.... Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.6613.84-1) trixi
debian
CVE-2025-12441P4MEDIUMCVSS 4.3fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12441 [MEDIUM] CVE-2025-12441: chromium - Out of bounds read in V8 in Google Chrome prior to 142.0.7444.59 allowed a remot... Out of bounds read in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) trixie
debian
CVE-2026-5878P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5878 [MEDIUM] CVE-2026-5878: chromium - Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a... Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5882P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5882 [MEDIUM] CVE-2026-5882: chromium - Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allo... Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2025-9479P4MEDIUMCVSS 4.3fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-9479 [MEDIUM] CVE-2025-9479: chromium - Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remo... Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1) bullseye: open forky: resolved (fixed in 133.0.6943.141-1) sid: resolved (fixed in 133.0.6943.141-1) trixie
debian
CVE-2025-13636P4MEDIUMCVSS 4.3fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13636 [MEDIUM] CVE-2025-13636: chromium - Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.... Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted domain name. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1) bullseye: open forky: resolved (fixed in 143.0.749
debian
CVE-2026-5875P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5875 [MEDIUM] CVE-2026-5875: chromium - Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote ... Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-3942P4MEDIUMCVSS 4.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3942 [MEDIUM] CVE-2026-3942: chromium - Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.7... Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: resolved (fixed in 146.0.7680.71-1) trixie: res
debian
CVE-2026-3927P4MEDIUMCVSS 4.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3927 [MEDIUM] CVE-2026-3927: chromium - Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.7... Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: resolved (fixed in 146.0.7680.71-1) trixie:
debian
Debian Chromium vulnerabilities | cvebase