cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 11 of 107
CVE-2021-21225P3HIGHCVSS 8.8fixed in chromium 90.0.4430.85-1 (bookworm)2021
CVE-2021-21225 [HIGH] CVE-2021-21225: chromium - Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed... Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 90.0.4430.85-1) bullseye: resolved (fixed in 90.0.4430.85-1) forky: resolved (fixed in 90.0.4430.85-1) sid: resolved (fixed in 90.0.4430.85-1) trixie: resolved (f
debian
CVE-2026-1862P3HIGHCVSS 8.8fixed in chromium 144.0.7559.109-2~deb12u1 (bookworm)2026
CVE-2026-1862 [HIGH] CVE-2026-1862: chromium - Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 144.0.7559.109-2~deb12u1) bullseye: open forky: resolved (fixed in 144.0.7559.109-2) sid: resolved (fixed in 144.0.7559.109-2) trixie: resol
debian
CVE-2026-5272P3HIGHCVSS 8.8fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5272 [HIGH] CVE-2026-5272: chromium - Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a r... Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1) sid: resolved (fixed in 146.0.7680.177-1) trixie: resolved (f
debian
CVE-2020-6468P3HIGHCVSS 8.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6468 [HIGH] CVE-2020-6468: chromium - Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote att... Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 83.0.4103.83-1) bullseye: resolved (fixed in 83.0.4103.83-1) forky: resolved (fixed in 83.0.4103.83-1) sid: resolved (fixed in 83.0.4103.83-1) trixie: resolved (fixed in 83.0.41
debian
CVE-2025-11460P3HIGHCVSS 8.8fixed in chromium 141.0.7390.65-1~deb12u1 (bookworm)2025
CVE-2025-11460 [HIGH] CVE-2025-11460: chromium - Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remo... Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 141.0.7390.65-1~deb12u1) bullseye: open forky: resolved (fixed in 141.0.7390.65-1) sid: resolved (fixed in 141.0.7390.65-1) trixie: resolved (fixe
debian
CVE-2026-5286P3HIGHCVSS 8.8fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5286 [HIGH] CVE-2026-5286: chromium - Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote... Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1) sid: resolved (fixed in 146.0.7680.177-1) trixie: resolved (fixed
debian
CVE-2026-5879P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5879 [HIGH] CVE-2026-5879: chromium - Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prio... Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5866P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5866 [HIGH] CVE-2026-5866: chromium - Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote... Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5872P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5872 [HIGH] CVE-2026-5872: chromium - Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote... Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5861P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5861 [HIGH] CVE-2026-5861: chromium - Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote at... Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2021-30573P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30573 [HIGH] CVE-2021-30573: chromium - Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote a... Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.
debian
CVE-2025-12907P3HIGHCVSS 8.8fixed in chromium 140.0.7339.80-1~deb12u1 (bookworm)2025
CVE-2025-12907 [HIGH] CVE-2025-12907: chromium - Insufficient validation of untrusted input in Devtools in Google Chrome prior to... Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 140.0.7339.80-1~deb12u1) bullseye: open forky: resolved (fixed in 140.0.7339.80-1) sid: resolved (fixed in 140.0.73
debian
CVE-2021-30561P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30561 [HIGH] CVE-2021-30561: chromium - Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.0
debian
CVE-2021-21106P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21106 [CRITICAL] CVE-2021-21106: chromium - Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a rem... Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.141-0.1) bullseye: resolved (fixed in 87.0.4280.141-0.1) forky: resolved (fixed in 87.0.4280.141-0.1) sid: resol
debian
CVE-2023-1531P3HIGHCVSS 8.8fixed in chromium 111.0.5563.110-1 (bookworm)2023
CVE-2023-1531 [HIGH] CVE-2023-1531: chromium - Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remot... Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 111.0.5563.110-1) bullseye: resolved (fixed in 111.0.5563.110-1~deb11u1) forky: resolved (fixed in 111.0.5563.110-1) sid: resolved (fixed
debian
CVE-2024-0808P3CRITICALCVSS 9.8fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-0808 [CRITICAL] CVE-2024-0808: chromium - Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a rem... Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.85-1) sid: resolved (fixed in 121.0.6167.85-1) trixie: re
debian
CVE-2026-5902P3CRITICALCVSS 9.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5902 [CRITICAL] CVE-2026-5902: chromium - Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remot... Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2025-4609P3CRITICALCVSS 9.6fixed in chromium 136.0.7103.113-1~deb12u1 (bookworm)2025
CVE-2025-4609 [CRITICAL] CVE-2025-4609: chromium - Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome ... Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 136.0.7103.113-1~deb12u1) bullseye: open forky: resolved (fixed in 136.0.7103.113-1)
debian
CVE-2023-5996P3HIGHCVSS 8.8fixed in chromium 119.0.6045.123-1~deb12u1 (bookworm)2023
CVE-2023-5996 [HIGH] CVE-2023-5996: chromium - Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a re... Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 119.0.6045.123-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.123-1~deb11u1) forky: resolved (fixed in 119.0.6045.123-1) sid: reso
debian
CVE-2024-5499P3HIGHCVSS 8.8fixed in chromium 125.0.6422.141-1~deb12u1 (bookworm)2024
CVE-2024-5499 [HIGH] CVE-2024-5499: chromium - Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allo... Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 125.0.6422.141-1~deb12u1) bullseye: open forky: resolved (fixed in 125.0.6422.141-1) sid: resolved (fixed in 125.0.6422.14
debian
Debian Chromium vulnerabilities | cvebase