Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 15 of 107
CVE-2024-5496P3HIGHCVSS 8.8fixed in chromium 125.0.6422.141-1~deb12u1 (bookworm)2024
CVE-2024-5496 [HIGH] CVE-2024-5496: chromium - Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed...
Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 125.0.6422.141-1~deb12u1)
bullseye: open
forky: resolved (fixed in 125.0.6422.141-1)
sid: resolved (fixed in 125.0.6422.141-1
debian
CVE-2024-5157P3HIGHCVSS 8.8fixed in chromium 125.0.6422.76-1~deb12u1 (bookworm)2024
CVE-2024-5157 [HIGH] CVE-2024-5157: chromium - Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a r...
Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 125.0.6422.76-1~deb12u1)
bullseye: open
forky: resolved (fixed in 125.0.6422.76-1)
sid: resolved (fixed in 125.0.6422.76-1)
trixi
debian
CVE-2024-7256P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-7256 [HIGH] CVE-2024-7256: chromium - Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0....
Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1)
sid: resolved (fixed in 127.0.6533.88-1)
tri
debian
CVE-2024-5836P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5836 [HIGH] CVE-2024-5836: chromium - Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54...
Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.56
debian
CVE-2026-4677P3HIGHCVSS 8.8fixed in chromium 146.0.7680.164-1~deb12u1 (bookworm)2026
CVE-2026-4677 [HIGH] CVE-2026-4677: chromium - Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.16...
Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.164-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.164-1)
sid: resolved (fixed in 146.0.7680
debian
CVE-2026-4675P3HIGHCVSS 8.8fixed in chromium 146.0.7680.164-1~deb12u1 (bookworm)2026
CVE-2026-4675 [HIGH] CVE-2026-4675: chromium - Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a...
Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.164-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.164-1)
sid: resolved (fixed in 146.0.7680.164-1)
tri
debian
CVE-2024-12695P3HIGHCVSS 8.8fixed in chromium 131.0.6778.204-1~deb12u1 (bookworm)2024
CVE-2024-12695 [HIGH] CVE-2024-12695: chromium - Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a rem...
Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 131.0.6778.204-1~deb12u1)
bullseye: open
forky: resolved (fixed in 131.0.6778.204-1)
sid: resolved (fixed in 131.0.6778.204-1)
tr
debian
CVE-2026-3915P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3915 [HIGH] CVE-2026-3915: chromium - Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a ...
Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie:
debian
CVE-2026-3537P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3537 [HIGH] CVE-2026-3537: chromium - Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.763...
Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.159-1)
sid: resolved (fixed in 145
debian
CVE-2026-4676P3HIGHCVSS 8.8fixed in chromium 146.0.7680.164-1~deb12u1 (bookworm)2026
CVE-2026-4676 [HIGH] CVE-2026-4676: chromium - Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote...
Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.164-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.164-1)
sid: resolved (fixed in 146.0.7680.164-1)
trixie: re
debian
CVE-2026-3914P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3914 [HIGH] CVE-2026-3914: chromium - Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remo...
Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie: reso
debian
CVE-2026-4439P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4439 [HIGH] CVE-2026-4439: chromium - Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0....
Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in
debian
CVE-2026-4679P3HIGHCVSS 8.8fixed in chromium 146.0.7680.164-1~deb12u1 (bookworm)2026
CVE-2026-4679 [HIGH] CVE-2026-4679: chromium - Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a rem...
Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.164-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.164-1)
sid: resolved (fixed in 146.0.7680.164-1)
trixie
debian
CVE-2026-0900P3HIGHCVSS 8.8fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0900 [HIGH] CVE-2026-0900: chromium - Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allow...
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 144.0.7559.59-1)
sid: resolved (fixed in 144.0.7559.59-1)
t
debian
CVE-2026-4441P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4441 [HIGH] CVE-2026-4441: chromium - Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote...
Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixie:
debian
CVE-2026-0908P3HIGHCVSS 8.8fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0908 [HIGH] CVE-2026-0908: chromium - Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote...
Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 144.0.7559.59-1)
sid: resolved (fixed in 144.0.7559.59-1)
trixie: resolve
debian
CVE-2026-3543P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3543 [HIGH] CVE-2026-3543: chromium - Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allo...
Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.159-1)
sid: resolved (fixed in 145.0
debian
CVE-2026-4450P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4450 [HIGH] CVE-2026-4450: chromium - Out of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a rem...
Out of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixie:
debian
CVE-2026-4461P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4461 [HIGH] CVE-2026-4461: chromium - Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allo...
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
debian
CVE-2026-4448P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4448 [HIGH] CVE-2026-4448: chromium - Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a...
Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trix
debian