Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 103 of 107
CVE-2019-13659P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13659 [MEDIUM] CVE-2019-13659: chromium - IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote ...
IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (
debian
CVE-2019-13663P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13663 [MEDIUM] CVE-2019-13663: chromium - IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote ...
IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (
debian
CVE-2019-13681P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13681 [MEDIUM] CVE-2019-13681: chromium - Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75...
Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved
debian
CVE-2022-3447P4MEDIUMCVSS 4.3fixed in chromium 106.0.5249.119-1 (bookworm)2022
CVE-2022-3447 [MEDIUM] CVE-2022-3447: chromium - Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to...
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 106.0.5249.119-1)
bullseye: resolved (fixed in 106.0.5249.119-1~deb11u1)
forky: resolved (fixed
debian
CVE-2019-5875P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-5875 [MEDIUM] CVE-2019-5875: chromium - Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75...
Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
tri
debian
CVE-2019-13691P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13691 [MEDIUM] CVE-2019-13691: chromium - Insufficient validation of untrusted input in navigation in Google Chrome prior ...
Insufficient validation of untrusted input in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78
debian
CVE-2023-0141P4MEDIUMCVSS 4.3fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0141 [MEDIUM] CVE-2023-0141: chromium - Insufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 ...
Insufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 109.0.5414.74-1)
bullseye: resolved (fixed in 109.0.5414.74-2~deb11u1)
forky: resolved (fixed in 109.0.5414.74-1)
sid: resolved (fixed
debian
CVE-2023-3737P4MEDIUMCVSS 4.3fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3737 [MEDIUM] CVE-2023-3737: chromium - Inappropriate implementation in Notifications in Google Chrome prior to 115.0.57...
Inappropriate implementation in Notifications in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to spoof the contents of media notifications via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1)
bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1)
forky: resolved (fixed in 1
debian
CVE-2022-4182P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4182 [MEDIUM] CVE-2022-4182: chromium - Inappropriate implementation in Fenced Frames in Google Chrome prior to 108.0.53...
Inappropriate implementation in Fenced Frames in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass fenced frame restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
forky: resolved (fixed in 108.0.5359.71-1)
s
debian
CVE-2022-2611P4MEDIUMCVSS 4.3fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2611 [MEDIUM] CVE-2022-2611: chromium - Inappropriate implementation in Fullscreen API in Google Chrome on Android prior...
Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky: resolved (fixed in 104.0.5112.79-1)
sid: resolved (
debian
CVE-2020-6504P4MEDIUMCVSS 4.3fixed in chromium 74.0.3729.108-1 (bookworm)2020
CVE-2020-6504 [MEDIUM] CVE-2020-6504: chromium - Insufficient policy enforcement in notifications in Google Chrome prior to 74.0....
Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74.0.3729.108-1)
tr
debian
CVE-2022-3053P4MEDIUMCVSS 4.3fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3053 [MEDIUM] CVE-2022-3053: chromium - Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 10...
Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: resolved (fixed in 105.0.5195.52-1)
sid: resolved (fixed in 105.0.5195.52-1)
debian
CVE-2021-4316P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4316 [MEDIUM] CVE-2021-4316: chromium - Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 a...
Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in
debian
CVE-2023-1236P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1236 [MEDIUM] CVE-2023-1236: chromium - Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.6...
Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-1)
sid: resolv
debian
CVE-2024-7978P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7978 [MEDIUM] CVE-2024-7978: chromium - Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0...
Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 1
debian
CVE-2024-7975P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7975 [MEDIUM] CVE-2024-7975: chromium - Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613...
Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.84-1)
trixie
debian
CVE-2022-4186P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4186 [MEDIUM] CVE-2022-4186: chromium - Insufficient validation of untrusted input in Downloads in Google Chrome prior t...
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-
debian
CVE-2024-7981P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7981 [MEDIUM] CVE-2024-7981: chromium - Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 al...
Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.84-1)
trixie: resolve
debian
CVE-2025-13634P4MEDIUMCVSS 4.4fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13634 [MEDIUM] CVE-2025-13634: chromium - Inappropriate implementation in Downloads in Google Chrome on Windows prior to 1...
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the web via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.0.7499.40-1)
sid: resolved (fixed in 143.0.7499
debian
CVE-2022-4189P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4189 [MEDIUM] CVE-2022-4189: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359...
Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~de
debian