cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 14 of 107
CVE-2026-3542P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3542 [HIGH] CVE-2026-3542: chromium - Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632... Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632.159-1) sid: resolved (fixed in 145.0.76
debian
CVE-2026-4457P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4457 [HIGH] CVE-2026-4457: chromium - Type Confusion in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) trixie: resol
debian
CVE-2026-4463P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4463 [HIGH] CVE-2026-4463: chromium - Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed ... Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) tri
debian
CVE-2026-4444P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4444 [HIGH] CVE-2026-4444: chromium - Stack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed... Stack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) t
debian
CVE-2026-3540P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3540 [HIGH] CVE-2026-3540: chromium - Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.15... Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632.159-1) sid: resolved (fixed in 145.0.7632.
debian
CVE-2026-3920P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3920 [HIGH] CVE-2026-3920: chromium - Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 all... Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: resolved (fixed in 146.0.7680.71-1) t
debian
CVE-2026-4446P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4446 [HIGH] CVE-2026-4446: chromium - Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remo... Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) trixie: r
debian
CVE-2026-3921P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3921 [HIGH] CVE-2026-3921: chromium - Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a... Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: resolved (fixed in 146.0.7680.71-1) trixie:
debian
CVE-2026-3923P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3923 [HIGH] CVE-2026-3923: chromium - Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remo... Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: resolved (fixed in 146.0.7680.71-1) trixie: reso
debian
CVE-2026-3922P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3922 [HIGH] CVE-2026-3922: chromium - Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a ... Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: resolved (fixed in 146.0.7680.71-1) trixie:
debian
CVE-2026-3931P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3931 [HIGH] CVE-2026-3931: chromium - Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a r... Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: resolved (fixed in 146.0.7680.71-1) trixie:
debian
CVE-2025-8880P3HIGHCVSS 8.8fixed in chromium 139.0.7258.127-1~deb12u1 (bookworm)2025
CVE-2025-8880 [HIGH] CVE-2025-8880: chromium - Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to... Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 139.0.7258.127-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0.7258.127-1) sid: resolved (fixed in 139.0.7258.127-1) trixie: resolved (f
debian
CVE-2026-4454P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4454 [HIGH] CVE-2026-4454: chromium - Use after free in Network in Google Chrome prior to 146.0.7680.153 allowed a rem... Use after free in Network in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) trixie:
debian
CVE-2021-21215P3MEDIUMCVSS 6.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21215 [MEDIUM] CVE-2021-21215: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 ... Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page. Scope: local bookworm: resolved (fixed in 90.0.4430.72-1) bullseye: resolved (fixed in 90.0.4430.72-1) forky: resolved (fixed in 90.0.4430.72-1) sid: resolved (fixed in 90.0.4430.72-1) trixie: resolved (fixed in 9
debian
CVE-2019-13734P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13734 [HIGH] CVE-2019-13734: chromium - Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a r... Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fixed
debian
CVE-2026-0905P3CRITICALCVSS 9.8fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0905 [CRITICAL] CVE-2026-0905: chromium - Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.... Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1) bullseye: open forky: resolved (fixed in 144.0.7
debian
CVE-2020-6402P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6402 [HIGH] CVE-2020-6402: chromium - Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 8... Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-
debian
CVE-2024-9369P3CRITICALCVSS 9.6fixed in chromium 129.0.6668.89-1~deb12u1 (bookworm)2024
CVE-2024-9369 [CRITICAL] CVE-2024-9369: chromium - Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 all... Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 129.0.6668.89-1~deb12u1) bullseye: open forky: resolved (fixed in 129.0.6668.8
debian
CVE-2022-3199P3HIGHCVSS 8.8fixed in chromium 105.0.5195.125-1 (bookworm)2022
CVE-2022-3199 [HIGH] CVE-2022-3199: chromium - Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remo... Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 105.0.5195.125-1) bullseye: resolved (fixed in 105.0.5195.125-1~deb11u1) forky: resolved (fixed in 105.0.5195.125-1) sid: resolved (fixe
debian
CVE-2024-4331P3HIGHCVSS 8.8fixed in chromium 124.0.6367.118-1~deb12u1 (bookworm)2024
CVE-2024-4331 [HIGH] CVE-2024-4331: chromium - Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 al... Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 124.0.6367.118-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.118-1) sid: resolved (fixed in 124.0.6367.118-
debian
Debian Chromium vulnerabilities | cvebase