cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 105 of 107
CVE-2025-12728P4MEDIUMCVSS 4.2fixed in chromium 142.0.7444.134-1~deb12u1 (bookworm)2025
CVE-2025-12728 [MEDIUM] CVE-2025-12728: chromium - Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142... Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 142.0.7444.134-1~deb12u1) bullseye: open forky: resolved (fixed i
debian
CVE-2025-12447P4MEDIUMCVSS 4.2fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12447 [MEDIUM] CVE-2025-12447: chromium - Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444... Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444
debian
CVE-2025-12444P4MEDIUMCVSS 4.2fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12444 [MEDIUM] CVE-2025-12444: chromium - Incorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 a... Incorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1
debian
CVE-2025-12446P4MEDIUMCVSS 4.2fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12446 [MEDIUM] CVE-2025-12446: chromium - Incorrect security UI in SplitView in Google Chrome prior to 142.0.7444.59 allow... Incorrect security UI in SplitView in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted domain name. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1)
debian
CVE-2018-18348P4MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18348 [MEDIUM] CVE-2018-18348: chromium - Incorrect handling of bidirectional domain names with RTL characters in Omnibox ... Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) s
debian
CVE-2021-21184P4MEDIUMCVSS 4.3fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21184 [MEDIUM] CVE-2021-21184: chromium - Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.... Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 89.0.4389.82-1) bullseye: resolved (fixed in 89.0.4389.82-1) forky: resolved (fixed in 89.0.4389.82-1) sid: resolved (fixed in 89.0.4389.82-1) trixie: resolve
debian
CVE-2021-21183P4MEDIUMCVSS 4.3fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21183 [MEDIUM] CVE-2021-21183: chromium - Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.... Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 89.0.4389.82-1) bullseye: resolved (fixed in 89.0.4389.82-1) forky: resolved (fixed in 89.0.4389.82-1) sid: resolved (fixed in 89.0.4389.82-1) trixie: resolve
debian
CVE-2019-5833P4MEDIUMCVSS 4.3fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5833 [MEDIUM] CVE-2019-5833: chromium - Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.... Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page. Scope: local bookworm: resolved (fixed in 75.0.3770.80-1) bullseye: resolved (fixed in 75.0.3770.80-1) forky: resolved (fixed in 75.0.3770.80-1) sid: resolved (fixed in 75.0.3770.80-1) trixie:
debian
CVE-2019-13716P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13716 [MEDIUM] CVE-2019-13716: chromium - Insufficient policy enforcement in service workers in Google Chrome prior to 78.... Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixi
debian
CVE-2019-13703P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13703 [MEDIUM] CVE-2019-13703: chromium - Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior... Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 7
debian
CVE-2019-13701P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13701 [MEDIUM] CVE-2019-13701: chromium - Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 al... Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trix
debian
CVE-2021-21147P4MEDIUMCVSS 4.3fixed in chromium 88.0.4324.146-1 (bookworm)2021
CVE-2021-21147 [MEDIUM] CVE-2021-21147: chromium - Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 all... Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.146-1) bullseye: resolved (fixed in 88.0.4324.146-1) forky: resolved (fixed in 88.0.4324.146-1) sid: resolved (fixed in 88.0.4324.146-1) tr
debian
CVE-2021-38004P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38004 [MEDIUM] CVE-2021-38004: chromium - Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.... Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved (fixed in 97.0.4692.71-0.1) trix
debian
CVE-2022-1498P4MEDIUMCVSS 4.3fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1498 [MEDIUM] CVE-2022-1498: chromium - Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951... Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 101.0.4951.41-1) bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1) forky: resolved (fixed in 101.0.4951.41-1) sid: resolved (fixed in 101.0.4951.41-1) trixie: r
debian
CVE-2022-2479P4MEDIUMCVSS 4.3fixed in chromium 103.0.5060.134-1 (bookworm)2022
CVE-2022-2479 [MEDIUM] CVE-2022-2479: chromium - Insufficient validation of untrusted input in File in Google Chrome on Android p... Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file directories via a crafted HTML page. Scope: local bookworm: resolved (fixed in 103.0.5060.134-1) bullseye: resolved (fixed in 103.0.5
debian
CVE-2022-1637P4MEDIUMCVSS 4.3fixed in chromium 101.0.4951.64-1 (bookworm)2022
CVE-2022-1637 [MEDIUM] CVE-2022-1637: chromium - Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.495... Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 101.0.4951.64-1) bullseye: resolved (fixed in 101.0.4951.64-1~deb11u1) forky: resolved (fixed in 101.0.4951.64-1) sid: resolved (fixed in 101.0.4951.64-1) trixie:
debian
CVE-2021-30630P4MEDIUMCVSS 4.3fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30630 [MEDIUM] CVE-2021-30630: chromium - Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 all... Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 9
debian
CVE-2019-13667P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13667 [MEDIUM] CVE-2019-13667: chromium - Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.38... Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87
debian
CVE-2019-13661P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13661 [MEDIUM] CVE-2019-13661: chromium - UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote ... UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (fixed in 78.0.3904.87-1)
debian
CVE-2019-13669P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13669 [MEDIUM] CVE-2019-13669: chromium - Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 a... Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) tri
debian
Debian Chromium vulnerabilities | cvebase