cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 30 of 107
CVE-2023-2313P3HIGHCVSS 8.8fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-2313 [HIGH] CVE-2023-2313: chromium - Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112... Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 112.0.5615.49-1) bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2) forky: re
debian
CVE-2024-5837P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5837 [HIGH] CVE-2024-5837: chromium - Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixi
debian
CVE-2024-5833P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5833 [HIGH] CVE-2024-5833: chromium - Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixi
debian
CVE-2024-5835P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5835 [HIGH] CVE-2024-5835: chromium - Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allow... Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.
debian
CVE-2025-1006P3HIGHCVSS 8.8fixed in chromium 133.0.6943.126-1~deb12u1 (bookworm)2025
CVE-2025-1006 [HIGH] CVE-2025-1006: chromium - Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a rem... Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted web app. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 133.0.6943.126-1~deb12u1) bullseye: open forky: resolved (fixed in 133.0.6943.126-1) sid: resolved (fixed in 133.0.6943.126-1) trixie:
debian
CVE-2024-7970P3HIGHCVSS 8.8fixed in chromium 128.0.6613.119-1~deb12u1 (bookworm)2024
CVE-2024-7970 [HIGH] CVE-2024-7970: chromium - Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a rem... Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 128.0.6613.119-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.119-1) sid: resolved (fixed in 128.0.6613.119-1) trixie:
debian
CVE-2024-9121P3HIGHCVSS 8.8fixed in chromium 129.0.6668.70-1~deb12u1 (bookworm)2024
CVE-2024-9121 [HIGH] CVE-2024-9121: chromium - Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allow... Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 129.0.6668.70-1~deb12u1) bullseye: open forky: resolved (fixed in 129.0.6668.70-1) sid: resolved (fixed in 129.0.66
debian
CVE-2024-5842P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5842 [HIGH] CVE-2024-5842: chromium - Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a r... Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.647
debian
CVE-2021-4322P3HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4322 [HIGH] CVE-2021-4322: chromium - Use after free in DevTools in Google Chrome prior to 91.0.4472.77 allowed an att... Use after free in DevTools in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fi
debian
CVE-2024-6774P3HIGHCVSS 8.8fixed in chromium 126.0.6478.182-1~deb12u1 (bookworm)2024
CVE-2024-6774 [HIGH] CVE-2024-6774: chromium - Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowe... Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.182-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.
debian
CVE-2025-4050P3HIGHCVSS 8.8fixed in chromium 136.0.7103.59-2~deb12u2 (bookworm)2025
CVE-2025-4050 [HIGH] CVE-2025-4050: chromium - Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 ... Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 136.0.7103.59-2~deb12u2) bullseye: open forky: resolved (fixed in
debian
CVE-2024-8905P3HIGHCVSS 8.8fixed in chromium 129.0.6668.58-1~deb12u1 (bookworm)2024
CVE-2024-8905 [HIGH] CVE-2024-8905: chromium - Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allow... Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 129.0.6668.58-1~deb12u1) bullseye: open forky: resolved (fixed in 129.0.6668.58-1) sid: resolved (fixed in 129.0.6668.58-1)
debian
CVE-2024-9603P3HIGHCVSS 8.8fixed in chromium 129.0.6668.100-1~deb12u1 (bookworm)2024
CVE-2024-9603 [HIGH] CVE-2024-9603: chromium - Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 129.0.6668.100-1~deb12u1) bullseye: open forky: resolved (fixed in 129.0.6668.100-1) sid: resolved (fixed in 129.0.6668.100-1) trixie: resol
debian
CVE-2024-5846P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5846 [HIGH] CVE-2024-5846: chromium - Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remot... Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixie: reso
debian
CVE-2024-5847P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5847 [HIGH] CVE-2024-5847: chromium - Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remot... Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixie: reso
debian
CVE-2024-6775P3HIGHCVSS 8.8fixed in chromium 126.0.6478.182-1~deb12u1 (bookworm)2024
CVE-2024-6775 [HIGH] CVE-2024-6775: chromium - Use after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed ... Use after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.182-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.64
debian
CVE-2024-5845P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5845 [HIGH] CVE-2024-5845: chromium - Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote... Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixie: resol
debian
CVE-2025-0443P3HIGHCVSS 8.8fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0443 [HIGH] CVE-2025-0443: chromium - Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.... Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1) bullseye: open forky: resolved (fixed in 132
debian
CVE-2024-8636P3HIGHCVSS 8.8fixed in chromium 128.0.6613.137-1~deb12u1 (bookworm)2024
CVE-2024-8636 [HIGH] CVE-2024-8636: chromium - Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a ... Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 128.0.6613.137-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.137-1) sid: resolved (fixed in 128.0.6613.137-1) trixi
debian
CVE-2023-7010P3HIGHCVSS 8.8fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-7010 [HIGH] CVE-2023-7010: chromium - Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remot... Use after free in WebRTC in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1) bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1) forky: resolved (fixed in 117.0.5938.62-1) sid: resolved (
debian
Debian Chromium vulnerabilities | cvebase