Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 12 of 107
CVE-2026-2650P3HIGHCVSS 8.8fixed in chromium 145.0.7632.109-1~deb12u3 (bookworm)2026
CVE-2026-2650 [HIGH] CVE-2026-2650: chromium - Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a...
Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 145.0.7632.109-1~deb12u3)
bullseye: open
forky: resolved (fixed in 145.0.7632.109-1)
sid: resolved (fixed in 145.0.7632.109-1)
tr
debian
CVE-2025-13224P3HIGHCVSS 8.8fixed in chromium 142.0.7444.175-1~deb12u1 (bookworm)2025
CVE-2025-13224 [HIGH] CVE-2025-13224: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote a...
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.175-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.175-1)
sid: resolved (fixed in 142.0.7444.175-1)
trixie: res
debian
CVE-2019-13764P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13764 [HIGH] CVE-2019-13764: chromium - Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a re...
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (fixed
debian
CVE-2026-4443P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4443 [HIGH] CVE-2026-4443: chromium - Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.153 allowe...
Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-
debian
CVE-2026-5278P3HIGHCVSS 8.8fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5278 [HIGH] CVE-2026-5278: chromium - Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 a...
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177-1)
sid: resolved (fixed in 146.0.7680.177-1)
trixie: r
debian
CVE-2020-6383P3HIGHCVSS 8.8fixed in chromium 80.0.3987.116-1 (bookworm)2020
CVE-2020-6383 [HIGH] CVE-2020-6383: chromium - Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote at...
Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.116-1)
bullseye: resolved (fixed in 80.0.3987.116-1)
forky: resolved (fixed in 80.0.3987.116-1)
sid: resolved (fixed in 80.0.3987.116-1)
trixie: resolved (fixed in 80
debian
CVE-2026-5275P3HIGHCVSS 8.8fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5275 [HIGH] CVE-2026-5275: chromium - Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 al...
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177-1)
sid: resolved (fixed in 146.0.7680.177-1)
trixie: re
debian
CVE-2026-5868P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5868 [HIGH] CVE-2026-5868: chromium - Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 all...
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5274P3HIGHCVSS 8.8fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5274 [HIGH] CVE-2026-5274: chromium - Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a re...
Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177-1)
sid: resolved (fixed in 146.0.7680.177-1)
trixie: resolv
debian
CVE-2026-4440P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4440 [HIGH] CVE-2026-4440: chromium - Out of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 a...
Out of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
debian
CVE-2026-5870P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5870 [HIGH] CVE-2026-5870: chromium - Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remot...
Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2025-12429P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12429 [HIGH] CVE-2025-12429: chromium - Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allow...
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
trixie:
debian
CVE-2021-21127P3HIGHCVSS 8.8fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21127 [HIGH] CVE-2021-21127: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.432...
Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.
debian
CVE-2020-16025P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16025 [CRITICAL] CVE-2020-16025: chromium - Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed...
Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: re
debian
CVE-2020-16024P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16024 [CRITICAL] CVE-2020-16024: chromium - Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remo...
Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved
debian
CVE-2021-21201P3CRITICALCVSS 9.6fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21201 [CRITICAL] CVE-2021-21201: chromium - Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a r...
Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fi
debian
CVE-2021-30547P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30547 [HIGH] CVE-2021-30547: chromium - Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a r...
Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: res
debian
CVE-2024-3157P3CRITICALCVSS 9.6fixed in chromium 123.0.6312.122-1~deb12u1 (bookworm)2024
CVE-2024-3157 [CRITICAL] CVE-2024-3157: chromium - Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312....
Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 123.0.6312.122-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.631
debian
CVE-2026-3916P3CRITICALCVSS 9.6fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3916 [CRITICAL] CVE-2026-3916: chromium - Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed...
Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
debian
CVE-2026-5288P3CRITICALCVSS 9.6fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5288 [CRITICAL] CVE-2026-5288: chromium - Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 al...
Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.
debian