Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 101 of 107
CVE-2026-3938P4MEDIUMCVSS 4.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3938 [MEDIUM] CVE-2026-3938: chromium - Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.768...
Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid:
debian
CVE-2026-5918P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5918 [MEDIUM] CVE-2026-5918: chromium - Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727....
Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-3925P4MEDIUMCVSS 4.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3925 [MEDIUM] CVE-2026-3925: chromium - Incorrect security UI in LookalikeChecks in Google Chrome on Android prior to 14...
Incorrect security UI in LookalikeChecks in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1
debian
CVE-2026-5889P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5889 [MEDIUM] CVE-2026-5889: chromium - Cryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an ...
Cryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an attacker to read potentially sensitive information from encrypted PDFs via a brute-force attack. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5864P4MEDIUMCVSS 4.2fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5864 [MEDIUM] CVE-2026-5864: chromium - Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed...
Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2025-12729P4MEDIUMCVSS 4.2fixed in chromium 142.0.7444.134-1~deb12u1 (bookworm)2025
CVE-2025-12729 [MEDIUM] CVE-2025-12729: chromium - Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142...
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 142.0.7444.134-1~deb12u1)
bullseye: open
forky: resolved (fixed i
debian
CVE-2019-5868P4MEDIUMCVSS 5.5fixed in chromium 76.0.3809.100-1 (bookworm)2019
CVE-2019-5868 [MEDIUM] CVE-2019-5868: chromium - Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remot...
Use after free in PDFium in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 76.0.3809.100-1)
bullseye: resolved (fixed in 76.0.3809.100-1)
forky: resolved (fixed in 76.0.3809.100-1)
sid: resolved (fixed in 76.0.3809.100-1)
trixie: resolved (fixed
debian
CVE-2026-5869P4LOWCVSS 3.1fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5869 [LOW] CVE-2026-5869: chromium - Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a ...
Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5894P4UNKNOWNfixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5894 CVE-2026-5894: chromium - Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allo...
Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2020-6438P4MEDIUMCVSS 4.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6438 [MEDIUM] CVE-2020-6438: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.404...
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: re
debian
CVE-2020-15959P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15959 [MEDIUM] CVE-2020-15959: chromium - Insufficient policy enforcement in networking in Google Chrome prior to 85.0.418...
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed
debian
CVE-2019-13763P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13763 [MEDIUM] CVE-2019-13763: chromium - Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945....
Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixe
debian
CVE-2020-6570P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6570 [MEDIUM] CVE-2020-6570: chromium - Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a r...
Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
t
debian
CVE-2020-6440P4MEDIUMCVSS 4.3fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6440 [MEDIUM] CVE-2020-6440: chromium - Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.9...
Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4
debian
CVE-2022-0118P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0118 [MEDIUM] CVE-2022-0118: chromium - Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 ...
Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixe
debian
CVE-2021-37965P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37965 [MEDIUM] CVE-2021-37965: chromium - Inappropriate implementation in Background Fetch API in Google Chrome prior to 9...
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-
debian
CVE-2022-0110P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0110 [MEDIUM] CVE-2022-0110: chromium - Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed...
Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-
debian
CVE-2021-37963P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37963 [MEDIUM] CVE-2021-37963: chromium - Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606...
Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trix
debian
CVE-2019-13717P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13717 [MEDIUM] CVE-2019-13717: chromium - Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70...
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 7
debian
CVE-2023-2465P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2465 [MEDIUM] CVE-2023-2465: chromium - Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 all...
Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 113.0.5672.63-1)
bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1)
forky: resolved (fixed in 113.0.5672.63-1)
sid: resolved (fixed
debian