cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 25 of 107
CVE-2025-10892P3HIGHCVSS 8.8fixed in chromium 140.0.7339.207-1~deb12u1 (bookworm)2025
CVE-2025-10892 [HIGH] CVE-2025-10892: chromium - Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote... Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 140.0.7339.207-1~deb12u1) bullseye: open forky: resolved (fixed in 140.0.7339.207-1) sid: resolved (fixed in 140.0.7339.207-1) trixie: r
debian
CVE-2026-3919P3HIGHCVSS 8.8fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3919 [HIGH] CVE-2026-3919: chromium - Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an ... Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) si
debian
CVE-2026-0902P3HIGHCVSS 8.8fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0902 [HIGH] CVE-2026-0902: chromium - Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allow... Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1) bullseye: open forky: resolved (fixed in 144.0.7559.59-1) sid: resolved (fixed in 144.0.7559.59-1)
debian
CVE-2025-8010P3HIGHCVSS 8.8fixed in chromium 138.0.7204.168-1~deb12u1 (bookworm)2025
CVE-2025-8010 [HIGH] CVE-2025-8010: chromium - Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 138.0.7204.168-1~deb12u1) bullseye: open forky: resolved (fixed in 138.0.7204.168-1) sid: resolved (fixed in 138.0.7204.168-1) trixie: resol
debian
CVE-2025-8011P3HIGHCVSS 8.8fixed in chromium 138.0.7204.168-1~deb12u1 (bookworm)2025
CVE-2025-8011 [HIGH] CVE-2025-8011: chromium - Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 138.0.7204.168-1~deb12u1) bullseye: open forky: resolved (fixed in 138.0.7204.168-1) sid: resolved (fixed in 138.0.7204.168-1) trixie: resol
debian
CVE-2025-13720P3HIGHCVSS 8.8fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13720 [HIGH] CVE-2025-13720: chromium - Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote atta... Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1) bullseye: open forky: resolved (fixed in 143.0.7499.40-1) sid: resolved (
debian
CVE-2026-5908P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5908 [HIGH] CVE-2026-5908: chromium - Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo... Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5910P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5910 [HIGH] CVE-2026-5910: chromium - Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo... Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5909P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5909 [HIGH] CVE-2026-5909: chromium - Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo... Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5914P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5914 [HIGH] CVE-2026-5914: chromium - Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacke... Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2021-30610P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30610 [HIGH] CVE-2021-30610: chromium - Chromium: CVE-2021-30610 Use after free in Extensions API Chromium: CVE-2021-30610 Use after free in Extensions API Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2021-30620P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30620 [HIGH] CVE-2021-30620: chromium - Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2019-5866P3CRITICALCVSS 9.8fixed in chromium 76.0.3809.71-1 (bookworm)2019
CVE-2019-5866 [CRITICAL] CVE-2019-5866: chromium - Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.14... Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 76.0.3809.71-1) bullseye: resolved (fixed in 76.0.3809.71-1) forky: resolved (fixed in 76.0.3809.71-1) sid: resolved (fixed in 76.0.3809.71-1) trixie:
debian
CVE-2019-5870P3CRITICALCVSS 9.6fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-5870 [CRITICAL] CVE-2019-5870: chromium - Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote ... Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (fixed in
debian
CVE-2020-6457P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6457 [CRITICAL] CVE-2020-6457: chromium - Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allo... Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 83.0.4103.83-1) bullseye: resolved (fixed in 83.0.4103.83-1) forky: resolved (fixed in 83.0.4103.83-1) sid: resolved (fixed in 83.0.4103.83-1) trixie: resol
debian
CVE-2018-18356P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18356 [HIGH] CVE-2018-18356: chromium - An integer overflow in path handling lead to a use after free in Skia in Google ... An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in
debian
CVE-2021-21107P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21107 [CRITICAL] CVE-2021-21107: chromium - Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141... Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.141-0.1) bullseye: resolved (fixed in 87.0.4280.141-0.1) forky: resolved (fixed in 87.0.4280.141-0
debian
CVE-2021-21142P3CRITICALCVSS 9.6fixed in chromium 88.0.4324.146-1 (bookworm)2021
CVE-2021-21142 [CRITICAL] CVE-2021-21142: chromium - Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowe... Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.146-1) bullseye: resolved (fixed in 88.0.4324.146-1) forky: resolved (fixed in 88.0.4324.146-1) sid: resolved (fixed in 88.0.4324.146-1) trixie: r
debian
CVE-2020-6390P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6390 [HIGH] CVE-2020-6390: chromium - Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 al... Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: reso
debian
CVE-2021-38013P3CRITICALCVSS 9.6fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38013 [CRITICAL] CVE-2021-38013: chromium - Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS pri... Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolv
debian
Debian Chromium vulnerabilities | cvebase