Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 16 of 107
CVE-2026-4442P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4442 [HIGH] CVE-2026-4442: chromium - Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a r...
Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixie
debian
CVE-2025-10501P3HIGHCVSS 8.8fixed in chromium 140.0.7339.185-1~deb12u1 (bookworm)2025
CVE-2025-10501 [HIGH] CVE-2025-10501: chromium - Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remo...
Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 140.0.7339.185-1~deb12u1)
bullseye: open
forky: resolved (fixed in 140.0.7339.185-1)
sid: resolved (fixed in 140.0.7339.185-1)
trixie:
debian
CVE-2025-10500P3HIGHCVSS 8.8fixed in chromium 140.0.7339.185-1~deb12u1 (bookworm)2025
CVE-2025-10500 [HIGH] CVE-2025-10500: chromium - Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote...
Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 140.0.7339.185-1~deb12u1)
bullseye: open
forky: resolved (fixed in 140.0.7339.185-1)
sid: resolved (fixed in 140.0.7339.185-1)
trixie: r
debian
CVE-2026-4449P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4449 [HIGH] CVE-2026-4449: chromium - Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remot...
Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixie: re
debian
CVE-2026-4445P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4445 [HIGH] CVE-2026-4445: chromium - Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remo...
Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixie: r
debian
CVE-2026-4456P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4456 [HIGH] CVE-2026-4456: chromium - Use after free in Digital Credentials API in Google Chrome prior to 146.0.7680.1...
Use after free in Digital Credentials API in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680
debian
CVE-2026-4455P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4455 [HIGH] CVE-2026-4455: chromium - Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed ...
Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trix
debian
CVE-2025-13229P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-13229 [HIGH] CVE-2025-13229: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
trixie: resolve
debian
CVE-2025-13227P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-13227 [HIGH] CVE-2025-13227: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
trixie: resolve
debian
CVE-2025-13228P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-13228 [HIGH] CVE-2025-13228: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
trixie: resolve
debian
CVE-2025-13230P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-13230 [HIGH] CVE-2025-13230: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
trixie: resolve
debian
CVE-2025-13226P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-13226 [HIGH] CVE-2025-13226: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
trixie: resolve
debian
CVE-2020-6573P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6573 [CRITICAL] CVE-2020-6573: chromium - Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allow...
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: re
debian
CVE-2020-6493P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6493 [CRITICAL] CVE-2020-6493: chromium - Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allow...
Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.106-1)
bullseye: resolved (fixed in 83.0.4103.106-1)
forky: resolved (fixed in 83.0.4103.106-1)
sid: resol
debian
CVE-2021-21226P3CRITICALCVSS 9.6fixed in chromium 90.0.4430.85-1 (bookworm)2021
CVE-2021-21226 [CRITICAL] CVE-2021-21226: chromium - Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a re...
Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.85-1)
bullseye: resolved (fixed in 90.0.4430.85-1)
forky: resolved (fixed in 90.0.4430.85-1)
sid: resolved (fix
debian
CVE-2021-21108P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21108 [CRITICAL] CVE-2021-21108: chromium - Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote...
Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 87.0.4280.141-0.1)
sid: resolved
debian
CVE-2021-21109P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21109 [CRITICAL] CVE-2021-21109: chromium - Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a rem...
Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 87.0.4280.141-0.1)
sid: resol
debian
CVE-2020-6556P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6556 [HIGH] CVE-2020-6556: chromium - Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allo...
Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: re
debian
CVE-2022-1853P3CRITICALCVSS 9.6fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1853 [CRITICAL] CVE-2022-1853: chromium - Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a r...
Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolved (fixed in 102.0.5005.61-1)
sid: resolved (fixed in 102.0.5005.61-1)
trixie:
debian
CVE-2020-15965P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15965 [HIGH] CVE-2020-15965: chromium - Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote at...
Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: res
debian