Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 14 of 107
CVE-2026-3542P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3542 [HIGH] CVE-2026-3542: chromium - Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632...
Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.159-1)
sid: resolved (fixed in 145.0.76
debian
CVE-2026-4457P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4457 [HIGH] CVE-2026-4457: chromium - Type Confusion in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote a...
Type Confusion in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixie: resol
debian
CVE-2026-4463P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4463 [HIGH] CVE-2026-4463: chromium - Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed ...
Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
tri
debian
CVE-2026-4444P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4444 [HIGH] CVE-2026-4444: chromium - Stack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed...
Stack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
t
debian
CVE-2026-3540P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3540 [HIGH] CVE-2026-3540: chromium - Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.15...
Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.159-1)
sid: resolved (fixed in 145.0.7632.
debian
CVE-2026-3920P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3920 [HIGH] CVE-2026-3920: chromium - Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 all...
Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
t
debian
CVE-2026-4446P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4446 [HIGH] CVE-2026-4446: chromium - Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remo...
Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixie: r
debian
CVE-2026-3921P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3921 [HIGH] CVE-2026-3921: chromium - Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a...
Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie:
debian
CVE-2026-3923P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3923 [HIGH] CVE-2026-3923: chromium - Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remo...
Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie: reso
debian
CVE-2026-3922P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3922 [HIGH] CVE-2026-3922: chromium - Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a ...
Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie:
debian
CVE-2026-3931P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3931 [HIGH] CVE-2026-3931: chromium - Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a r...
Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie:
debian
CVE-2025-8880P3HIGHCVSS 8.8fixed in chromium 139.0.7258.127-1~deb12u1 (bookworm)2025
CVE-2025-8880 [HIGH] CVE-2025-8880: chromium - Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to...
Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 139.0.7258.127-1~deb12u1)
bullseye: open
forky: resolved (fixed in 139.0.7258.127-1)
sid: resolved (fixed in 139.0.7258.127-1)
trixie: resolved (f
debian
CVE-2026-4454P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4454 [HIGH] CVE-2026-4454: chromium - Use after free in Network in Google Chrome prior to 146.0.7680.153 allowed a rem...
Use after free in Network in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixie:
debian
CVE-2021-21215P3MEDIUMCVSS 6.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21215 [MEDIUM] CVE-2021-21215: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 ...
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1)
trixie: resolved (fixed in 9
debian
CVE-2019-13734P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13734 [HIGH] CVE-2019-13734: chromium - Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a r...
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (fixed
debian
CVE-2026-0905P3CRITICALCVSS 9.8fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0905 [CRITICAL] CVE-2026-0905: chromium - Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559....
Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 144.0.7
debian
CVE-2020-6402P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6402 [HIGH] CVE-2020-6402: chromium - Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 8...
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-
debian
CVE-2024-9369P3CRITICALCVSS 9.6fixed in chromium 129.0.6668.89-1~deb12u1 (bookworm)2024
CVE-2024-9369 [CRITICAL] CVE-2024-9369: chromium - Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 all...
Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 129.0.6668.89-1~deb12u1)
bullseye: open
forky: resolved (fixed in 129.0.6668.8
debian
CVE-2022-3199P3HIGHCVSS 8.8fixed in chromium 105.0.5195.125-1 (bookworm)2022
CVE-2022-3199 [HIGH] CVE-2022-3199: chromium - Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remo...
Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 105.0.5195.125-1)
bullseye: resolved (fixed in 105.0.5195.125-1~deb11u1)
forky: resolved (fixed in 105.0.5195.125-1)
sid: resolved (fixe
debian
CVE-2024-4331P3HIGHCVSS 8.8fixed in chromium 124.0.6367.118-1~deb12u1 (bookworm)2024
CVE-2024-4331 [HIGH] CVE-2024-4331: chromium - Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 al...
Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 124.0.6367.118-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.118-1)
sid: resolved (fixed in 124.0.6367.118-
debian