cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 16 of 107
CVE-2026-4442P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4442 [HIGH] CVE-2026-4442: chromium - Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a r... Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) trixie
debian
CVE-2025-10501P3HIGHCVSS 8.8fixed in chromium 140.0.7339.185-1~deb12u1 (bookworm)2025
CVE-2025-10501 [HIGH] CVE-2025-10501: chromium - Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remo... Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 140.0.7339.185-1~deb12u1) bullseye: open forky: resolved (fixed in 140.0.7339.185-1) sid: resolved (fixed in 140.0.7339.185-1) trixie:
debian
CVE-2025-10500P3HIGHCVSS 8.8fixed in chromium 140.0.7339.185-1~deb12u1 (bookworm)2025
CVE-2025-10500 [HIGH] CVE-2025-10500: chromium - Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote... Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 140.0.7339.185-1~deb12u1) bullseye: open forky: resolved (fixed in 140.0.7339.185-1) sid: resolved (fixed in 140.0.7339.185-1) trixie: r
debian
CVE-2026-4449P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4449 [HIGH] CVE-2026-4449: chromium - Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remot... Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) trixie: re
debian
CVE-2026-4445P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4445 [HIGH] CVE-2026-4445: chromium - Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remo... Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) trixie: r
debian
CVE-2026-4456P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4456 [HIGH] CVE-2026-4456: chromium - Use after free in Digital Credentials API in Google Chrome prior to 146.0.7680.1... Use after free in Digital Credentials API in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680
debian
CVE-2026-4455P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4455 [HIGH] CVE-2026-4455: chromium - Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed ... Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) trix
debian
CVE-2025-13229P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-13229 [HIGH] CVE-2025-13229: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) trixie: resolve
debian
CVE-2025-13227P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-13227 [HIGH] CVE-2025-13227: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) trixie: resolve
debian
CVE-2025-13228P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-13228 [HIGH] CVE-2025-13228: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) trixie: resolve
debian
CVE-2025-13230P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-13230 [HIGH] CVE-2025-13230: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) trixie: resolve
debian
CVE-2025-13226P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-13226 [HIGH] CVE-2025-13226: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) trixie: resolve
debian
CVE-2020-6573P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6573 [CRITICAL] CVE-2020-6573: chromium - Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allow... Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: re
debian
CVE-2020-6493P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6493 [CRITICAL] CVE-2020-6493: chromium - Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allow... Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 83.0.4103.106-1) bullseye: resolved (fixed in 83.0.4103.106-1) forky: resolved (fixed in 83.0.4103.106-1) sid: resol
debian
CVE-2021-21226P3CRITICALCVSS 9.6fixed in chromium 90.0.4430.85-1 (bookworm)2021
CVE-2021-21226 [CRITICAL] CVE-2021-21226: chromium - Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a re... Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 90.0.4430.85-1) bullseye: resolved (fixed in 90.0.4430.85-1) forky: resolved (fixed in 90.0.4430.85-1) sid: resolved (fix
debian
CVE-2021-21108P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21108 [CRITICAL] CVE-2021-21108: chromium - Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote... Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.141-0.1) bullseye: resolved (fixed in 87.0.4280.141-0.1) forky: resolved (fixed in 87.0.4280.141-0.1) sid: resolved
debian
CVE-2021-21109P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21109 [CRITICAL] CVE-2021-21109: chromium - Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a rem... Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.141-0.1) bullseye: resolved (fixed in 87.0.4280.141-0.1) forky: resolved (fixed in 87.0.4280.141-0.1) sid: resol
debian
CVE-2020-6556P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6556 [HIGH] CVE-2020-6556: chromium - Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allo... Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: re
debian
CVE-2022-1853P3CRITICALCVSS 9.6fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1853 [CRITICAL] CVE-2022-1853: chromium - Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a r... Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.5005.61-1) sid: resolved (fixed in 102.0.5005.61-1) trixie:
debian
CVE-2020-15965P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15965 [HIGH] CVE-2020-15965: chromium - Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote at... Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: res
debian
Debian Chromium vulnerabilities | cvebase