Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 19 of 107
CVE-2025-13638P3HIGHCVSS 8.8fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13638 [HIGH] CVE-2025-13638: chromium - Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a...
Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.0.7499.40-1)
sid: resolved (fixed in 143.0.7499.40-1)
trixie
debian
CVE-2026-3926P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3926 [HIGH] CVE-2026-3926: chromium - Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remot...
Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie: res
debian
CVE-2026-5912P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5912 [HIGH] CVE-2026-5912: chromium - Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a rem...
Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-4458P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4458 [HIGH] CVE-2026-4458: chromium - Use after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an...
Use after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680
debian
CVE-2021-30614P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30614 [HIGH] CVE-2021-30614: chromium - Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2018-18335P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18335 [HIGH] CVE-2018-18335: chromium - Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a re...
Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie: resolved (fixed
debian
CVE-2020-6466P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6466 [CRITICAL] CVE-2020-6466: chromium - Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote ...
Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 8
debian
CVE-2020-6424P3HIGHCVSS 8.8fixed in chromium 80.0.3987.149-1 (bookworm)2020
CVE-2020-6424 [HIGH] CVE-2020-6424: chromium - Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote...
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.149-1)
bullseye: resolved (fixed in 80.0.3987.149-1)
forky: resolved (fixed in 80.0.3987.149-1)
sid: resolved (fixed in 80.0.3987.149-1)
trixie: resolved (fixed in
debian
CVE-2021-21223P3CRITICALCVSS 9.6fixed in chromium 90.0.4430.85-1 (bookworm)2021
CVE-2021-21223 [CRITICAL] CVE-2021-21223: chromium - Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote...
Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.85-1)
bullseye: resolved (fixed in 90.0.4430.85-1)
forky: resolved (fixed in 90.0.4430.85-1)
sid: resolved (fixed i
debian
CVE-2021-21154P3CRITICALCVSS 9.6fixed in chromium 88.0.4324.182-1 (bookworm)2021
CVE-2021-21154 [CRITICAL] CVE-2021-21154: chromium - Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowe...
Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.182-1)
bullseye: resolved (fixed in 88.0.4324.182-1)
forky: resolved (fixed in 88.0.4324.182-1)
sid: reso
debian
CVE-2021-21115P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21115 [CRITICAL] CVE-2021-21115: chromium - User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed...
User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 87.0.4280.141-0.1)
sid:
debian
CVE-2021-21155P3CRITICALCVSS 9.6fixed in chromium 88.0.4324.182-1 (bookworm)2021
CVE-2021-21155 [CRITICAL] CVE-2021-21155: chromium - Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324...
Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.182-1)
bullseye: resolved (fixed in 88.0.4324.182-1)
forky: resolved (fixed in 88.0.4324.182-1
debian
CVE-2021-21150P3CRITICALCVSS 9.6fixed in chromium 88.0.4324.182-1 (bookworm)2021
CVE-2021-21150 [CRITICAL] CVE-2021-21150: chromium - Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 a...
Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.182-1)
bullseye: resolved (fixed in 88.0.4324.182-1)
forky: resolved (fixed in 88.0.4324.182-1)
sid:
debian
CVE-2021-21151P3CRITICALCVSS 9.6fixed in chromium 88.0.4324.182-1 (bookworm)2021
CVE-2021-21151 [CRITICAL] CVE-2021-21151: chromium - Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a rem...
Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.182-1)
bullseye: resolved (fixed in 88.0.4324.182-1)
forky: resolved (fixed in 88.0.4324.182-1)
sid: resolved (fixed in 88.0.4324.182-1)
trixie: resolved
debian
CVE-2021-21146P3CRITICALCVSS 9.6fixed in chromium 88.0.4324.146-1 (bookworm)2021
CVE-2021-21146 [CRITICAL] CVE-2021-21146: chromium - Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a r...
Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.146-1)
bullseye: resolved (fixed in 88.0.4324.146-1)
forky: resolved (fixed in 88.0.4324.146-1)
sid: resolved
debian
CVE-2021-38002P3CRITICALCVSS 9.6fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38002 [CRITICAL] CVE-2021-38002: chromium - Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a...
Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
debian
CVE-2020-6512P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6512 [HIGH] CVE-2020-6512: chromium - Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote att...
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixed in
debian
CVE-2022-0790P3CRITICALCVSS 9.6fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0790 [CRITICAL] CVE-2022-0790: chromium - Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remot...
Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 99.0.4844.51-1)
bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1)
forky: resolved (fixed in 99.0.4844.51
debian
CVE-2020-6463P3HIGHCVSS 8.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6463 [HIGH] CVE-2020-6463: chromium - Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote...
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolved (fixed in 83.
debian
CVE-2020-6524P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6524 [HIGH] CVE-2020-6524: chromium - Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed ...
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolv
debian