Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 13 of 107
CVE-2023-4352P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4352 [HIGH] CVE-2023-4352: chromium - Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote at...
Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky: resolved (fixed in 116.0.5845.96-1)
sid: resolved (fixe
debian
CVE-2023-5346P3HIGHCVSS 8.8fixed in chromium 117.0.5938.149-1~deb12u1 (bookworm)2023
CVE-2023-5346 [HIGH] CVE-2023-5346: chromium - Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote a...
Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 117.0.5938.149-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.149-1~deb11u1)
forky: resolved (fixed in 117.0.5938.149-1)
sid: resolved (
debian
CVE-2026-3061P3CRITICALCVSS 9.1fixed in chromium 145.0.7632.116-1~deb12u1 (bookworm)2026
CVE-2026-3061 [CRITICAL] CVE-2026-3061: chromium - Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a r...
Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 145.0.7632.116-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.116-1)
sid: resolved (fixed in 145.0.7632.116-1)
t
debian
CVE-2026-2649P3HIGHCVSS 8.8fixed in chromium 145.0.7632.109-1~deb12u3 (bookworm)2026
CVE-2026-2649 [HIGH] CVE-2026-2649: chromium - Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote...
Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 145.0.7632.109-1~deb12u3)
bullseye: open
forky: resolved (fixed in 145.0.7632.109-1)
sid: resolved (fixed in 145.0.7632.109-1)
trixie: res
debian
CVE-2026-4673P3HIGHCVSS 8.8fixed in chromium 146.0.7680.164-1~deb12u1 (bookworm)2026
CVE-2026-4673 [HIGH] CVE-2026-4673: chromium - Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowe...
Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.164-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.164-1)
sid: resolved (fixed in 146.0.7680.164-1)
debian
CVE-2026-3538P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3538 [HIGH] CVE-2026-3538: chromium - Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remo...
Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.159-1)
sid: resolved (fixed in 145.0.7632.
debian
CVE-2026-2648P3HIGHCVSS 8.8fixed in chromium 145.0.7632.109-1~deb12u3 (bookworm)2026
CVE-2026-2648 [HIGH] CVE-2026-2648: chromium - Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed ...
Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 145.0.7632.109-1~deb12u3)
bullseye: open
forky: resolved (fixed in 145.0.7632.109-1)
sid: resolved (fixed in 145.0.7632.109-1)
tr
debian
CVE-2026-3536P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3536 [HIGH] CVE-2026-3536: chromium - Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a rem...
Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.159-1)
sid: resolved (fixed in 145.0.7632
debian
CVE-2026-4674P3HIGHCVSS 8.8fixed in chromium 146.0.7680.164-1~deb12u1 (bookworm)2026
CVE-2026-4674 [HIGH] CVE-2026-4674: chromium - Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a rem...
Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.164-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.164-1)
sid: resolved (fixed in 146.0.7680.164-1)
trixie:
debian
CVE-2025-11756P3HIGHCVSS 8.8fixed in chromium 141.0.7390.107-1~deb12u1 (bookworm)2025
CVE-2025-11756 [HIGH] CVE-2025-11756: chromium - Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed...
Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 141.0.7390.107-1~deb12u1)
bullseye: open
forky: resolved (fixed in 141.0.7
debian
CVE-2026-3913P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3913 [HIGH] CVE-2026-3913: chromium - Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a ...
Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trix
debian
CVE-2026-1861P3HIGHCVSS 8.8fixed in chromium 144.0.7559.109-2~deb12u1 (bookworm)2026
CVE-2026-1861 [HIGH] CVE-2026-1861: chromium - Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed ...
Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 144.0.7559.109-2~deb12u1)
bullseye: open
forky: resolved (fixed in 144.0.7559.109-2)
sid: resolved (fixed in 144.0.7559.109-2)
tri
debian
CVE-2025-13633P3HIGHCVSS 8.8fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13633 [HIGH] CVE-2025-13633: chromium - Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 al...
Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.0.7499.40-1
debian
CVE-2025-13630P3HIGHCVSS 8.8fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13630 [HIGH] CVE-2025-13630: chromium - Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.0.7499.40-1)
sid: resolved (fixed in 143.0.7499.40-1)
trixie: resolve
debian
CVE-2026-0899P3HIGHCVSS 8.8fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0899 [HIGH] CVE-2026-0899: chromium - Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowe...
Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 144.0.7559.59-1)
sid: resolved (fixed in 144.0.7559.59-1)
tr
debian
CVE-2026-3917P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3917 [HIGH] CVE-2026-3917: chromium - Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remot...
Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie: resol
debian
CVE-2021-21125P3HIGHCVSS 8.1fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21125 [HIGH] CVE-2021-21125: chromium - Insufficient policy enforcement in File System API in Google Chrome on Windows p...
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4
debian
CVE-2026-3918P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3918 [HIGH] CVE-2026-3918: chromium - Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remot...
Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie: resol
debian
CVE-2026-3544P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3544 [HIGH] CVE-2026-3544: chromium - Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allow...
Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.159-1)
sid: resolved (fixed in 145.0.7632.159-1
debian
CVE-2025-11205P3HIGHCVSS 8.8fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11205 [HIGH] CVE-2025-11205: chromium - Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a...
Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1)
bullseye: open
forky: resolved (fixed in 141.0.7390.54-1)
sid:
debian