Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 106 of 107
CVE-2019-13676P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13676 [MEDIUM] CVE-2019-13676: chromium - Insufficient policy enforcement in Chromium in Google Chrome prior to 77.0.3865....
Insufficient policy enforcement in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (f
debian
CVE-2019-13671P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13671 [MEDIUM] CVE-2019-13671: chromium - UI spoofing in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote att...
UI spoofing in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 78.0.3904.87-1)
debian
CVE-2019-13705P4MEDIUMCVSS 4.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13705 [MEDIUM] CVE-2019-13705: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.390...
Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid
debian
CVE-2022-3660P4MEDIUMCVSS 4.3fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3660 [MEDIUM] CVE-2022-3660: chromium - Inappropriate implementation in Full screen mode in Google Chrome on Android pri...
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 107.0.5304.62 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 107.0.5304.68-1)
bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1)
forky: resolved (fix
debian
CVE-2023-1231P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1231 [MEDIUM] CVE-2023-1231: chromium - Inappropriate implementation in Autofill in Google Chrome on Android prior to 11...
Inappropriate implementation in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to potentially spoof the contents of the omnibox via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in
debian
CVE-2020-16034P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16034 [MEDIUM] CVE-2020-16034: chromium - Inappropriate implementation in WebRTC in Google Chrome prior to 87.0.4280.66 al...
Inappropriate implementation in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a local attacker to bypass policy restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolv
debian
CVE-2023-1232P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1232 [MEDIUM] CVE-2023-1232: chromium - Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111...
Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to obtain potentially sensitive information from API via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in
debian
CVE-2018-20067P4MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-20067 [MEDIUM] CVE-2018-20067: chromium - A renderer initiated back navigation was incorrectly allowed to cancel a browser...
A renderer initiated back navigation was incorrectly allowed to cancel a browser initiated one in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky:
debian
CVE-2018-20068P4MEDIUMCVSS 4.3fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-20068 [MEDIUM] CVE-2018-20068: chromium - Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 7...
Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed
debian
CVE-2022-4025P4MEDIUMCVSS 4.3fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-4025 [MEDIUM] CVE-2022-4025: chromium - Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 all...
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: resol
debian
CVE-2023-1228P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1228 [MEDIUM] CVE-2023-1228: chromium - Insufficient policy enforcement in Intents in Google Chrome on Android prior to ...
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.6
debian
CVE-2023-1223P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1223 [MEDIUM] CVE-2023-1223: chromium - Insufficient policy enforcement in Autofill in Google Chrome on Android prior to...
Insufficient policy enforcement in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-1)
si
debian
CVE-2023-1230P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1230 [MEDIUM] CVE-2023-1230: chromium - Inappropriate implementation in WebApp Installs in Google Chrome on Android prio...
Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious WebApp to spoof the contents of the PWA installer via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.
debian
CVE-2025-12434P4MEDIUMCVSS 4.2fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12434 [MEDIUM] CVE-2025-12434: chromium - Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a rem...
Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: re
debian
CVE-2022-3312P4MEDIUMCVSS 4.6fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3312 [MEDIUM] CVE-2022-3312: chromium - Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS p...
Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restrictions via physical access to the device. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
forky: resolved (
debian
CVE-2025-13635P4MEDIUMCVSS 4.4fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13635 [MEDIUM] CVE-2025-13635: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.4...
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.0.7499.40-1)
sid: resolved (fixed in 143.0.7499.40-1)
trixie: re
debian
CVE-2025-13640P4LOWCVSS 3.5fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13640 [LOW] CVE-2025-13640: chromium - Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.4...
Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass authentication via physical access to the device. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.0.7499.40-1)
sid: resolved (fixed in 143.0.7499.40-1)
t
debian
CVE-2025-11219P4LOWCVSS 3.1fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11219 [LOW] CVE-2025-11219: chromium - Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote at...
Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1)
bullseye: open
forky: resolved (fixed in 141.0.7390.54-1)
sid: resolved (fixed in 141.0.7390.54-1)
trixi
debian
CVE-2021-37964P4LOWCVSS 3.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37964 [LOW] CVE-2021-37964: chromium - Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS...
Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireless access point to to potentially carryout a wifi impersonation attack via a crafted ONC file.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved
debian
CVE-2019-13762P4LOWCVSS 3.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13762 [LOW] CVE-2019-13762: chromium - Insufficient policy enforcement in downloads in Google Chrome on Windows prior t...
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (fix
debian