Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 22 of 107
CVE-2024-3837P3HIGHCVSS 8.8fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3837 [HIGH] CVE-2024-3837: chromium - Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote ...
Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.60-1)
sid: resolved
debian
CVE-2023-6351P3HIGHCVSS 8.8fixed in chromium 119.0.6045.199-1~deb12u1 (bookworm)2023
CVE-2023-6351 [HIGH] CVE-2023-6351: chromium - Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a rem...
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 119.0.6045.199-1~deb12u1)
bullseye: resolved (fixed in 119.0.6045.199-1~deb11u1)
forky: resolved (fixed in 119.0.6045.199-1)
sid: resol
debian
CVE-2024-1060P3HIGHCVSS 8.8fixed in chromium 121.0.6167.139-1~deb12u1 (bookworm)2024
CVE-2024-1060 [HIGH] CVE-2024-1060: chromium - Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remo...
Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 121.0.6167.139-1~deb12u1)
bullseye: open
forky: resolved (fixed in 121.0.6167.139-1)
sid: resolved (fixed in 121.0.6167.139-1)
trixie: r
debian
CVE-2024-12053P3HIGHCVSS 8.8fixed in chromium 131.0.6778.108-1~deb12u1 (bookworm)2024
CVE-2024-12053 [HIGH] CVE-2024-12053: chromium - Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote a...
Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 131.0.6778.108-1~deb12u1)
bullseye: open
forky: resolved (fixed in 131.0.6778.108-1)
sid: resolved (fixed in 131.0.6778.108-1)
trixie: r
debian
CVE-2025-2476P3HIGHCVSS 8.8fixed in chromium 134.0.6998.117-1~deb12u1 (bookworm)2025
CVE-2025-2476 [HIGH] CVE-2025-2476: chromium - Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote...
Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 134.0.6998.117-1~deb12u1)
bullseye: open
forky: resolved (fixed in 134.0.6998.117-1)
sid: resolved (fixed in 134.0.6998.117-1)
trixie:
debian
CVE-2024-7532P3HIGHCVSS 8.8fixed in chromium 127.0.6533.99-1~deb12u1 (bookworm)2024
CVE-2024-7532 [HIGH] CVE-2024-7532: chromium - Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 all...
Out of bounds memory access in ANGLE in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 127.0.6533.99-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.99-1)
sid: resolved (fixed in 127.0.6533.99-
debian
CVE-2024-6101P3HIGHCVSS 8.8fixed in chromium 126.0.6478.114-1~deb12u1 (bookworm)2024
CVE-2024-6101 [HIGH] CVE-2024-6101: chromium - Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allo...
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.114-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.114-1)
sid: resolved (fixed in 126.0.6478.114-1)
debian
CVE-2024-2627P3HIGHCVSS 8.8fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2627 [HIGH] CVE-2024-2627: chromium - Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remot...
Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.58-1)
sid: resolved (fixed in 123.0.6312.58-1)
trixie: res
debian
CVE-2024-3158P3HIGHCVSS 8.8fixed in chromium 123.0.6312.105-1~deb12u1 (bookworm)2024
CVE-2024-3158 [HIGH] CVE-2024-3158: chromium - Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a r...
Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 123.0.6312.105-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.105-1)
sid: resolved (fixed in 123.0.6312.105-1)
trixie
debian
CVE-2024-9955P3HIGHCVSS 8.8fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9955 [HIGH] CVE-2024-9955: chromium - Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allo...
Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.58-1)
sid: resolved (fixed in 130.0.6723.58-1)
debian
CVE-2024-5497P3HIGHCVSS 8.8fixed in chromium 125.0.6422.141-1~deb12u1 (bookworm)2024
CVE-2024-5497 [HIGH] CVE-2024-5497: chromium - Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.1...
Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 125.0.6422.141-1~deb12u1)
bullseye: open
forky: resolved (fixed
debian
CVE-2024-2400P3HIGHCVSS 8.8fixed in chromium 122.0.6261.128-1~deb12u1 (bookworm)2024
CVE-2024-2400 [HIGH] CVE-2024-2400: chromium - Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 a...
Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 122.0.6261.128-1~deb12u1)
bullseye: open
forky: resolved (fixed in 122.0.6261.128-1)
sid: resolved (fixed in 122.0.6261.128
debian
CVE-2024-6102P3HIGHCVSS 8.8fixed in chromium 126.0.6478.114-1~deb12u1 (bookworm)2024
CVE-2024-6102 [HIGH] CVE-2024-6102: chromium - Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 all...
Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.114-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.114-1)
sid: resolved (fixed in 126.0.6478.114-1
debian
CVE-2024-5495P3HIGHCVSS 8.8fixed in chromium 125.0.6422.141-1~deb12u1 (bookworm)2024
CVE-2024-5495 [HIGH] CVE-2024-5495: chromium - Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote...
Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 125.0.6422.141-1~deb12u1)
bullseye: open
forky: resolved (fixed in 125.0.6422.141-1)
sid: resolved (fixed in 125.0.6422.141-1)
trixie: res
debian
CVE-2022-4918P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-4918 [HIGH] CVE-2022-4918: chromium - Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote at...
Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolved (fixed in 102.0.5005.61-1)
sid: resolved (fixed in 102.0.50
debian
CVE-2022-4919P3HIGHCVSS 8.8fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-4919 [HIGH] CVE-2022-4919: chromium - Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed...
Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed i
debian
CVE-2022-4916P3HIGHCVSS 8.8fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-4916 [HIGH] CVE-2022-4916: chromium - Use after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote...
Use after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 103.0.5060.53-1)
bullseye: resolved (fixed in 103.0.5060.53-1~deb11u1)
forky: resolved (fixed in 103.0.5060.53-1)
sid: resolved (fixed in 103.0.5
debian
CVE-2024-5494P3HIGHCVSS 8.8fixed in chromium 125.0.6422.141-1~deb12u1 (bookworm)2024
CVE-2024-5494 [HIGH] CVE-2024-5494: chromium - Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote...
Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 125.0.6422.141-1~deb12u1)
bullseye: open
forky: resolved (fixed in 125.0.6422.141-1)
sid: resolved (fixed in 125.0.6422.141-1)
trixie: res
debian
CVE-2022-4921P3HIGHCVSS 8.8fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-4921 [HIGH] CVE-2022-4921: chromium - Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a...
Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 99.0.4844.51-1)
bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1)
forky: resolved
debian
CVE-2021-4317P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4317 [HIGH] CVE-2021-4317: chromium - Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote ...
Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.
debian