Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 23 of 107
CVE-2023-6704P3HIGHCVSS 8.8fixed in chromium 120.0.6099.109-1~deb12u1 (bookworm)2023
CVE-2023-6704 [HIGH] CVE-2023-6704: chromium - Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a rem...
Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted image file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 120.0.6099.109-1~deb12u1)
bullseye: resolved (fixed in 120.0.6099.109-1~deb11u1)
forky: resolved (fixed in 120.0.6099.109-1)
sid: reso
debian
CVE-2024-10827P3HIGHCVSS 8.8fixed in chromium 130.0.6723.116-1~deb12u1 (bookworm)2024
CVE-2024-10827 [HIGH] CVE-2024-10827: chromium - Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remo...
Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 130.0.6723.116-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.116-1)
sid: resolved (fixed in 130.0.6723.116-1)
trixie:
debian
CVE-2024-10230P3HIGHCVSS 8.8fixed in chromium 130.0.6723.69-1~deb12u1 (bookworm)2024
CVE-2024-10230 [HIGH] CVE-2024-10230: chromium - Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 130.0.6723.69-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.69-1)
sid: resolved (fixed in 130.0.6723.69-1)
trixie: resolve
debian
CVE-2024-6103P3HIGHCVSS 8.8fixed in chromium 126.0.6478.114-1~deb12u1 (bookworm)2024
CVE-2024-6103 [HIGH] CVE-2024-6103: chromium - Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote...
Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.114-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.114-1)
sid: resolved (fixed in 126.0.6478.114-1)
trixie: res
debian
CVE-2024-7966P3HIGHCVSS 8.8fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7966 [HIGH] CVE-2024-7966: chromium - Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allo...
Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
si
debian
CVE-2024-7550P3HIGHCVSS 8.8fixed in chromium 127.0.6533.99-1~deb12u1 (bookworm)2024
CVE-2024-7550 [HIGH] CVE-2024-7550: chromium - Type Confusion in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 127.0.6533.99-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.99-1)
sid: resolved (fixed in 127.0.6533.99-1)
trixie: resolved
debian
CVE-2025-0999P3HIGHCVSS 8.8fixed in chromium 133.0.6943.126-1~deb12u1 (bookworm)2025
CVE-2025-0999 [HIGH] CVE-2025-0999: chromium - Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a re...
Heap buffer overflow in V8 in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 133.0.6943.126-1~deb12u1)
bullseye: open
forky: resolved (fixed in 133.0.6943.126-1)
sid: resolved (fixed in 133.0.6943.126-1)
trixie:
debian
CVE-2024-7536P3HIGHCVSS 8.8fixed in chromium 127.0.6533.99-1~deb12u1 (bookworm)2024
CVE-2024-7536 [HIGH] CVE-2024-7536: chromium - Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a rem...
Use after free in WebAudio in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 127.0.6533.99-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.99-1)
sid: resolved (fixed in 127.0.6533.99-1)
trixie: res
debian
CVE-2024-6989P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-6989 [HIGH] CVE-2024-6989: chromium - Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remot...
Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1)
sid: resolved (fixed in 127.0.6533.88-1)
trixie: resol
debian
CVE-2024-6991P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-6991 [HIGH] CVE-2024-6991: chromium - Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote ...
Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1)
sid: resolved (fixed in 127.0.6533.88-1)
trixie: resolve
debian
CVE-2024-5834P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5834 [HIGH] CVE-2024-5834: chromium - Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 all...
Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.56-1)
sid: resolved (fixed in 126.0.6478.56-1)
trixie: resolv
debian
CVE-2021-4319P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4319 [HIGH] CVE-2021-4319: chromium - Use after free in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote ...
Use after free in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.
debian
CVE-2024-6291P3HIGHCVSS 8.8fixed in chromium 126.0.6478.126-1~deb12u1 (bookworm)2024
CVE-2024-6291 [HIGH] CVE-2024-6291: chromium - Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a...
Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.126-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.126-1)
sid: resolved (fixed in 126.0.6478.126-1)
trix
debian
CVE-2021-4320P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4320 [HIGH] CVE-2021-4320: chromium - Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote...
Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.
debian
CVE-2024-7968P3HIGHCVSS 8.8fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7968 [HIGH] CVE-2024-7968: chromium - Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a rem...
Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.
debian
CVE-2024-6772P3HIGHCVSS 8.8fixed in chromium 126.0.6478.182-1~deb12u1 (bookworm)2024
CVE-2024-6772 [HIGH] CVE-2024-6772: chromium - Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allo...
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.182-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.182-1)
sid: resolved (fixed in 126.0.6478.182-1)
debian
CVE-2024-8362P3HIGHCVSS 8.8fixed in chromium 128.0.6613.119-1~deb12u1 (bookworm)2024
CVE-2024-8362 [HIGH] CVE-2024-8362: chromium - Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a re...
Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.119-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.119-1)
sid: resolved (fixed in 128.0.6613.119-1)
trixie:
debian
CVE-2024-5838P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5838 [HIGH] CVE-2024-5838: chromium - Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.56-1)
sid: resolved (fixed in 126.0.6478.56-1)
trixie: resolved
debian
CVE-2024-10488P3HIGHCVSS 8.8fixed in chromium 130.0.6723.91-1~deb12u1 (bookworm)2024
CVE-2024-10488 [HIGH] CVE-2024-10488: chromium - Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remot...
Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 130.0.6723.91-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.91-1)
sid: resolved (fixed in 130.0.6723.91-1)
trixie: res
debian
CVE-2024-6290P3HIGHCVSS 8.8fixed in chromium 126.0.6478.126-1~deb12u1 (bookworm)2024
CVE-2024-6290 [HIGH] CVE-2024-6290: chromium - Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote...
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.126-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.126-1)
sid: resolved (fixed in 126.0.6478.126-1)
trixie: res
debian