Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 3 of 107
CVE-2024-4671P1CRITICALCVSS 9.6KEVfixed in chromium 124.0.6367.201-1~deb12u1 (bookworm)2024
CVE-2024-4671 [CRITICAL] CVE-2024-4671: chromium - Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a rem...
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 124.0.6367.201-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.201-1)
sid:
debian
CVE-2021-37973P1CRITICALCVSS 9.6KEVfixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37973 [CRITICAL] CVE-2021-37973: chromium - Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remot...
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: re
debian
CVE-2025-13223P1HIGHCVSS 8.8KEVfixed in chromium 142.0.7444.175-1~deb12u1 (bookworm)2025
CVE-2025-13223 [HIGH] CVE-2025-13223: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote a...
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.175-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.175-1)
sid: resolved (fixed in 142.0.7444.175-1)
trixie: res
debian
CVE-2021-21148P1HIGHCVSS 8.8KEVfixed in chromium 88.0.4324.150-1 (bookworm)2021
CVE-2021-21148 [HIGH] CVE-2021-21148: chromium - Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a rem...
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.150-1)
bullseye: resolved (fixed in 88.0.4324.150-1)
forky: resolved (fixed in 88.0.4324.150-1)
sid: resolved (fixed in 88.0.4324.150-1)
trixie: resolved (fix
debian
CVE-2023-2136P1CRITICALCVSS 9.6KEVfixed in chromium 112.0.5615.138-1 (bookworm)2023
CVE-2023-2136 [CRITICAL] CVE-2023-2136: chromium - Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remo...
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 112.0.5615.138-1)
bullseye: resolved (fixed in 112.0.5615.138-1~deb11u1)
forky: resolved (
debian
CVE-2024-4761P1HIGHCVSS 8.8KEVfixed in chromium 124.0.6367.207-1~deb12u1 (bookworm)2024
CVE-2024-4761 [HIGH] CVE-2024-4761: chromium - Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a rem...
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 124.0.6367.207-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.207-1)
sid: resolved (fixed in 124.0.6367.207-1)
trixie
debian
CVE-2022-3075P1CRITICALCVSS 9.6KEVfixed in chromium 105.0.5195.102-1 (bookworm)2022
CVE-2022-3075 [CRITICAL] CVE-2022-3075: chromium - Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 al...
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 105.0.5195.102-1)
bullseye: resolved (fixed in 105.0.5195.102-1~deb11u1)
forky: resolved (fixed in 105.0.5195.102
debian
CVE-2026-3910P1HIGHCVSS 8.8KEVfixed in chromium 146.0.7680.80-1~deb12u1 (bookworm)2026
CVE-2026-3910 [HIGH] CVE-2026-3910: chromium - Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allow...
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.80-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.80-1)
sid: resolved (fixed in 146.0.7680.80-1)
debian
CVE-2022-3723P1HIGHCVSS 8.8KEVfixed in chromium 107.0.5304.87-1 (bookworm)2022
CVE-2022-3723 [HIGH] CVE-2022-3723: chromium - Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote at...
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 107.0.5304.87-1)
bullseye: resolved (fixed in 107.0.5304.87-1~deb11u1)
forky: resolved (fixed in 107.0.5304.87-1)
sid: resolved (fixed in 107
debian
CVE-2026-3909P1HIGHCVSS 8.8KEVfixed in chromium 146.0.7680.80-1~deb12u1 (bookworm)2026
CVE-2026-3909 [HIGH] CVE-2026-3909: chromium - Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a re...
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.80-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.80-1)
sid: resolved (fixed in 146.0.7680.80-1)
trixie: re
debian
CVE-2023-7024P1HIGHCVSS 8.8KEVfixed in chromium 120.0.6099.129-1~deb12u1 (bookworm)2023
CVE-2023-7024 [HIGH] CVE-2023-7024: chromium - Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed ...
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 120.0.6099.129-1~deb12u1)
bullseye: resolved (fixed in 120.0.6099.129-1~deb11u1)
forky: resolved (fixed in 120.0.6099.129-1)
sid:
debian
CVE-2020-16017P1CRITICALCVSS 9.6KEVfixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16017 [CRITICAL] CVE-2020-16017: chromium - Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed...
Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: re
debian
CVE-2021-30563P1HIGHCVSS 8.8KEVfixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30563 [HIGH] CVE-2021-30563: chromium - Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in 93.0
debian
CVE-2021-21193P1HIGHCVSS 8.8KEVfixed in chromium 89.0.4389.90-1 (bookworm)2021
CVE-2021-21193 [HIGH] CVE-2021-21193: chromium - Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote ...
Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.90-1)
bullseye: resolved (fixed in 89.0.4389.90-1)
forky: resolved (fixed in 89.0.4389.90-1)
sid: resolved (fixed in 89.0.4389.90-1)
trixie: resolved (fixed in 89
debian
CVE-2021-21206P1HIGHCVSS 8.8KEVfixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21206 [HIGH] CVE-2021-21206: chromium - Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote...
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1)
trixie: resolved (fixed in 9
debian
CVE-2021-4102P1HIGHCVSS 8.8KEVfixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4102 [HIGH] CVE-2021-4102: chromium - Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote at...
Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: resolved
debian
CVE-2021-30554P1HIGHCVSS 8.8KEVfixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30554 [HIGH] CVE-2021-30554: chromium - Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote...
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in 9
debian
CVE-2020-6572P1HIGHCVSS 8.8KEVfixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6572 [HIGH] CVE-2020-6572: chromium - Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote ...
Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 81.0.4044.92-1)
bullseye: resolved (fixed in 81.0.4044.92-1)
forky: resolved (fixed in 81.0.4044.92-1)
sid: resolved (fixed in 81.0.4044.92-1)
trixie: resolved (fixed in 81.0.4044.92-1)
debian
CVE-2020-16013P1HIGHCVSS 8.8KEVfixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16013 [HIGH] CVE-2020-16013: chromium - Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allow...
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: r
debian
CVE-2021-30533P2MEDIUMCVSS 6.5KEVfixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30533 [MEDIUM] CVE-2021-30533: chromium - Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4...
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: res
debian