cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 24 of 107
CVE-2024-6293P3HIGHCVSS 8.8fixed in chromium 126.0.6478.126-1~deb12u1 (bookworm)2024
CVE-2024-6293 [HIGH] CVE-2024-6293: chromium - Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote... Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.126-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.126-1) sid: resolved (fixed in 126.0.6478.126-1) trixie: res
debian
CVE-2024-6292P3HIGHCVSS 8.8fixed in chromium 126.0.6478.126-1~deb12u1 (bookworm)2024
CVE-2024-6292 [HIGH] CVE-2024-6292: chromium - Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote... Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.126-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.126-1) sid: resolved (fixed in 126.0.6478.126-1) trixie: res
debian
CVE-2024-10231P3HIGHCVSS 8.8fixed in chromium 130.0.6723.69-1~deb12u1 (bookworm)2024
CVE-2024-10231 [HIGH] CVE-2024-10231: chromium - Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 130.0.6723.69-1~deb12u1) bullseye: open forky: resolved (fixed in 130.0.6723.69-1) sid: resolved (fixed in 130.0.6723.69-1) trixie: resolve
debian
CVE-2025-4372P3HIGHCVSS 8.8fixed in chromium 136.0.7103.92-1~deb12u1 (bookworm)2025
CVE-2025-4372 [HIGH] CVE-2025-4372: chromium - Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a rem... Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 136.0.7103.92-1~deb12u1) bullseye: open forky: resolved (fixed in 136.0.7103.92-1) sid: resolved (fixed in 136.0.7103.92-1) trixie: r
debian
CVE-2024-5831P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5831 [HIGH] CVE-2024-5831: chromium - Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote ... Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixie: resolve
debian
CVE-2025-4096P3HIGHCVSS 8.8fixed in chromium 136.0.7103.59-2~deb12u2 (bookworm)2025
CVE-2025-4096 [HIGH] CVE-2025-4096: chromium - Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a r... Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 136.0.7103.59-2~deb12u2) bullseye: open forky: resolved (fixed in 136.0.7103.59-2) sid: resolved (fixed in 136.0.7103.59-2) trixie: r
debian
CVE-2024-5832P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5832 [HIGH] CVE-2024-5832: chromium - Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote ... Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixie: resolve
debian
CVE-2024-7969P3HIGHCVSS 8.8fixed in chromium 128.0.6613.113-1~deb12u1 (bookworm)2024
CVE-2024-7969 [HIGH] CVE-2024-7969: chromium - Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 128.0.6613.113-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.113-1) sid: resolved (fixed in 128.0.6613.113-1) trixie: resol
debian
CVE-2024-8904P3HIGHCVSS 8.8fixed in chromium 129.0.6668.58-1~deb12u1 (bookworm)2024
CVE-2024-8904 [HIGH] CVE-2024-8904: chromium - Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 129.0.6668.58-1~deb12u1) bullseye: open forky: resolved (fixed in 129.0.6668.58-1) sid: resolved (fixed in 129.0.6668.58-1) trixie: resolved
debian
CVE-2024-6776P3HIGHCVSS 8.8fixed in chromium 126.0.6478.182-1~deb12u1 (bookworm)2024
CVE-2024-6776 [HIGH] CVE-2024-6776: chromium - Use after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remot... Use after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.182-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.182-1) sid: resolved (fixed in 126.0.6478.182-1) trixie: re
debian
CVE-2025-0438P3HIGHCVSS 8.8fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0438 [HIGH] CVE-2025-0438: chromium - Stack buffer overflow in Tracing in Google Chrome prior to 132.0.6834.83 allowed... Stack buffer overflow in Tracing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1) bullseye: open forky: resolved (fixed in 132.0.6834.83-1) sid: resolved (fixed in 132.0.6834.83-1) trix
debian
CVE-2024-7974P3HIGHCVSS 8.8fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7974 [HIGH] CVE-2024-7974: chromium - Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 a... Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.84-1) sid: resolved (fixed in 128.0.6
debian
CVE-2025-0995P3HIGHCVSS 8.8fixed in chromium 133.0.6943.98-1~deb12u1 (bookworm)2025
CVE-2025-0995 [HIGH] CVE-2025-0995: chromium - Use after free in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote at... Use after free in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 133.0.6943.98-1~deb12u1) bullseye: open forky: resolved (fixed in 133.0.6943.98-1) sid: resolved (fixed in 133.0.6943.98-1) trixie: resolved
debian
CVE-2024-9859P3HIGHCVSS 8.8fixed in chromium 126.0.6478.126-1~deb12u1 (bookworm)2024
CVE-2024-9859 [HIGH] CVE-2024-9859: chromium - Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a... Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.126-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.126-1) sid: resolved (fixed in 126.0.6478.126-1) trixie: resolved
debian
CVE-2025-5958P3HIGHCVSS 8.8fixed in chromium 137.0.7151.103-1~deb12u1 (bookworm)2025
CVE-2025-5958 [HIGH] CVE-2025-5958: chromium - Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remot... Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 137.0.7151.103-1~deb12u1) bullseye: open forky: resolved (fixed in 137.0.7151.103-1) sid: resolved (fixed in 137.0.7151.103-1) trixie: re
debian
CVE-2025-3619P3HIGHCVSS 8.8fixed in chromium 135.0.7049.95-1~deb12u1 (bookworm)2025
CVE-2025-3619 [HIGH] CVE-2025-3619: chromium - Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.9... Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) Scope: local bookworm: resolved (fixed in 135.0.7049.95-1~deb12u1) bullseye: open forky: resolved (fixed in 135.0.7049.95-1) sid: resolved (fixed in 135.0.704
debian
CVE-2025-8578P3HIGHCVSS 8.8fixed in chromium 139.0.7258.66-1~deb12u1 (bookworm)2025
CVE-2025-8578 [HIGH] CVE-2025-8578: chromium - Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote ... Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 139.0.7258.66-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0.7258.66-1) sid: resolved (fixed in 139.0.7258.66-1) trixie: resol
debian
CVE-2025-8292P3HIGHCVSS 8.8fixed in chromium 138.0.7204.183-1~deb12u1 (bookworm)2025
CVE-2025-8292 [HIGH] CVE-2025-8292: chromium - Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed ... Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 138.0.7204.183-1~deb12u1) bullseye: open forky: resolved (fixed in 138.0.7204.183-1) sid: resolved (fixed in 138.0.7204.183-1) tri
debian
CVE-2025-8576P3HIGHCVSS 8.8fixed in chromium 139.0.7258.66-1~deb12u1 (bookworm)2025
CVE-2025-8576 [HIGH] CVE-2025-8576: chromium - Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a r... Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 139.0.7258.66-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0.7258.66-1) sid: resolved (fixed in 139.0.7258.66-1)
debian
CVE-2025-8901P3HIGHCVSS 8.8fixed in chromium 139.0.7258.127-1~deb12u1 (bookworm)2025
CVE-2025-8901 [HIGH] CVE-2025-8901: chromium - Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a ... Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 139.0.7258.127-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0.7258.127-1) sid: resolved (fixed in 139.0.7258.127-1) trixi
debian
Debian Chromium vulnerabilities | cvebase