Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 18 of 107
CVE-2025-10200P3HIGHCVSS 8.8fixed in chromium 140.0.7339.127-1~deb12u1 (bookworm)2025
CVE-2025-10200 [HIGH] CVE-2025-10200: chromium - Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339....
Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 140.0.7339.127-1~deb12u1)
bullseye: open
forky: resolved (fixed in 140.0.7339.127-1)
sid: resolved (fixed in 140
debian
CVE-2025-7657P3HIGHCVSS 8.8fixed in chromium 138.0.7204.157-1~deb12u1 (bookworm)2025
CVE-2025-7657 [HIGH] CVE-2025-7657: chromium - Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remo...
Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 138.0.7204.157-1~deb12u1)
bullseye: open
forky: resolved (fixed in 138.0.7204.157-1)
sid: resolved (fixed in 138.0.7204.157-1)
trixie: r
debian
CVE-2025-6192P3HIGHCVSS 8.8fixed in chromium 137.0.7151.119-1~deb12u1 (bookworm)2025
CVE-2025-6192 [HIGH] CVE-2025-6192: chromium - Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a rem...
Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 137.0.7151.119-1~deb12u1)
bullseye: open
forky: resolved (fixed in 137.0.7151.119-1)
sid: resolved (fixed in 137.0.7151.119-1)
trixie:
debian
CVE-2024-3172P3HIGHCVSS 8.8fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-3172 [HIGH] CVE-2024-3172: chromium - Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85...
Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 121.0.6167.85
debian
CVE-2024-9965P3HIGHCVSS 8.8fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9965 [HIGH] CVE-2024-9965: chromium - Insufficient data validation in DevTools in Google Chrome on Windows prior to 13...
Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130
debian
CVE-2024-12693P3HIGHCVSS 8.8fixed in chromium 131.0.6778.204-1~deb12u1 (bookworm)2024
CVE-2024-12693 [HIGH] CVE-2024-12693: chromium - Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allow...
Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 131.0.6778.204-1~deb12u1)
bullseye: open
forky: resolved (fixed in 131.0.6778.204-1)
sid: resolved (fixed in 131.0.6778.2
debian
CVE-2026-5859P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5859 [HIGH] CVE-2026-5859: chromium - Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remo...
Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2025-13631P3HIGHCVSS 8.8fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13631 [HIGH] CVE-2025-13631: chromium - Inappropriate implementation in Google Updater in Google Chrome on Mac prior to ...
Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.0.7499.40-1)
sid: resolved (fixed in 143.0.7499.
debian
CVE-2026-4459P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4459 [HIGH] CVE-2026-4459: chromium - Out of bounds read and write in WebAudio in Google Chrome prior to 146.0.7680.15...
Out of bounds read and write in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.
debian
CVE-2026-3936P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3936 [HIGH] CVE-2026-3936: chromium - Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 all...
Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
debian
CVE-2025-10502P3HIGHCVSS 8.8fixed in chromium 140.0.7339.185-1~deb12u1 (bookworm)2025
CVE-2025-10502 [HIGH] CVE-2025-10502: chromium - Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a...
Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 140.0.7339.185-1~deb12u1)
bullseye: open
forky: resolved (fixed in 140.0.7339.185-1)
sid: resolved (fixed in 140.0.7339.185
debian
CVE-2026-3541P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3541 [HIGH] CVE-2026-3541: chromium - Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 all...
Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.159-1)
sid: resolved (fixed in 145.0.7632.159-
debian
CVE-2025-13042P3HIGHCVSS 8.8fixed in chromium 142.0.7444.162-1~deb12u1 (bookworm)2025
CVE-2025-13042 [HIGH] CVE-2025-13042: chromium - Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allo...
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.162-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.162-1)
sid: resolved (fixed in 142.0.7444.162-
debian
CVE-2025-12727P3HIGHCVSS 8.8fixed in chromium 142.0.7444.134-1~deb12u1 (bookworm)2025
CVE-2025-12727 [HIGH] CVE-2025-12727: chromium - Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allo...
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.134-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.134-1)
sid: resolved (fixed in 142.0.7444.134-
debian
CVE-2026-4452P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4452 [HIGH] CVE-2026-4452: chromium - Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 al...
Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-
debian
CVE-2026-4464P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4464 [HIGH] CVE-2026-4464: chromium - Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a rem...
Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixie
debian
CVE-2026-4451P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4451 [HIGH] CVE-2026-4451: chromium - Insufficient validation of untrusted input in Navigation in Google Chrome prior ...
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixe
debian
CVE-2026-2321P3HIGHCVSS 8.8fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2321 [HIGH] CVE-2026-2321: chromium - Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote...
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.45-1
debian
CVE-2025-12438P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12438 [HIGH] CVE-2025-12438: chromium - Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.74...
Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142
debian
CVE-2025-12432P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12432 [HIGH] CVE-2025-12432: chromium - Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to ...
Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
trixie: resolved (fixed i
debian