Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 31 of 107
CVE-2024-8198P3HIGHCVSS 8.8fixed in chromium 128.0.6613.113-1~deb12u1 (bookworm)2024
CVE-2024-8198 [HIGH] CVE-2024-8198: chromium - Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a ...
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.113-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.113-1)
sid: r
debian
CVE-2025-1918P3HIGHCVSS 8.8fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1918 [HIGH] CVE-2025-1918: chromium - Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a r...
Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1)
bullseye: open
forky: resolved (fixed in 134.0.6998.35-1)
sid: resolved (fixed in 134.0.6998.35
debian
CVE-2024-8193P3HIGHCVSS 8.8fixed in chromium 128.0.6613.113-1~deb12u1 (bookworm)2024
CVE-2024-8193 [HIGH] CVE-2024-8193: chromium - Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a ...
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.113-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.113-1)
sid: r
debian
CVE-2024-8194P3HIGHCVSS 8.8fixed in chromium 128.0.6613.113-1~deb12u1 (bookworm)2024
CVE-2024-8194 [HIGH] CVE-2024-8194: chromium - Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote a...
Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.113-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.113-1)
sid: resolved (fixed in 128.0.6613.113-1)
trixie: resol
debian
CVE-2024-11395P3HIGHCVSS 8.8fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11395 [HIGH] CVE-2024-11395: chromium - Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 131.0.6778.85-1)
sid: resolved (fixed in 131.0.6778.85-1)
trixie: resolve
debian
CVE-2025-9866P3HIGHCVSS 8.8fixed in chromium 140.0.7339.80-1~deb12u1 (bookworm)2025
CVE-2025-9866 [HIGH] CVE-2025-9866: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339....
Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 140.0.7339.80-1~deb12u1)
bullseye: open
forky: resolved (fixed in 140.0.7339.80-1)
sid: resolved (fixed in 140.0.7339.80-1
debian
CVE-2024-3169P3HIGHCVSS 8.8fixed in chromium 121.0.6167.139-1~deb12u1 (bookworm)2024
CVE-2024-3169 [HIGH] CVE-2024-3169: chromium - Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote a...
Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 121.0.6167.139-1~deb12u1)
bullseye: open
forky: resolved (fixed in 121.0.6167.139-1)
sid: resolved (fixed in 121.0.6167.139-1)
trixie: resol
debian
CVE-2024-3170P3HIGHCVSS 8.8fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-3170 [HIGH] CVE-2024-3170: chromium - Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remot...
Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 121.0.6167.85-1)
sid: resolved (fixed in 121.0.6167.85-1)
trixie: resol
debian
CVE-2024-11113P3HIGHCVSS 8.8fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11113 [HIGH] CVE-2024-11113: chromium - Use after free in Accessibility in Google Chrome prior to 131.0.6778.69 allowed ...
Use after free in Accessibility in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 131.0.6778.85-1)
si
debian
CVE-2025-3066P3HIGHCVSS 8.8fixed in chromium 135.0.7049.84-1~deb12u1 (bookworm)2025
CVE-2025-3066 [HIGH] CVE-2025-3066: chromium - Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed...
Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 135.0.7049.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 135.0.7049.84-1)
sid: resolved (fixed in 135.0.7049.84-1)
trixi
debian
CVE-2025-1920P3HIGHCVSS 8.8fixed in chromium 134.0.6998.88-1~deb12u1 (bookworm)2025
CVE-2025-1920 [HIGH] CVE-2025-1920: chromium - Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 134.0.6998.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 134.0.6998.88-1)
sid: resolved (fixed in 134.0.6998.88-1)
trixie: resolved
debian
CVE-2025-2136P3HIGHCVSS 8.8fixed in chromium 134.0.6998.88-1~deb12u1 (bookworm)2025
CVE-2025-2136 [HIGH] CVE-2025-2136: chromium - Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a re...
Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 134.0.6998.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 134.0.6998.88-1)
sid: resolved (fixed in 134.0.6998.88-1)
trixie:
debian
CVE-2024-12694P3HIGHCVSS 8.8fixed in chromium 131.0.6778.204-1~deb12u1 (bookworm)2024
CVE-2024-12694 [HIGH] CVE-2024-12694: chromium - Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a...
Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 131.0.6778.204-1~deb12u1)
bullseye: open
forky: resolved (fixed in 131.0.6778.204-1)
sid: resolved (fixed in 131.0.6778.204-1)
tr
debian
CVE-2021-38023P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-38023 [HIGH] CVE-2021-38023: chromium - Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a r...
Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0
debian
CVE-2025-8879P3HIGHCVSS 8.8fixed in chromium 139.0.7258.127-1~deb12u1 (bookworm)2025
CVE-2025-8879 [HIGH] CVE-2025-8879: chromium - Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed ...
Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 139.0.7258.127-1~deb12u1)
bullseye: open
forky: resolved (fixed in 139.0.7258.127-1)
sid: resolved (fixed in 139.0.7258.127-
debian
CVE-2025-12725P3HIGHCVSS 8.8fixed in chromium 142.0.7444.134-1~deb12u1 (bookworm)2025
CVE-2025-12725 [HIGH] CVE-2025-12725: chromium - Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137...
Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.134-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.134-1)
sid: resolved (fixed in 142.0.74
debian
CVE-2025-3620P3HIGHCVSS 8.8fixed in chromium 135.0.7049.95-1~deb12u1 (bookworm)2025
CVE-2025-3620 [HIGH] CVE-2025-3620: chromium - Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote a...
Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 135.0.7049.95-1~deb12u1)
bullseye: open
forky: resolved (fixed in 135.0.7049.95-1)
sid: resolved (fixed in 135.0.7049.95-1)
trixie: resolved
debian
CVE-2025-8882P3HIGHCVSS 8.8fixed in chromium 139.0.7258.127-1~deb12u1 (bookworm)2025
CVE-2025-8882 [HIGH] CVE-2025-8882: chromium - Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote...
Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 139.0.7258.127-1~deb12u1)
bullseye: open
forky: resolved (fixed in 139.0.7258.127
debian
CVE-2026-4462P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4462 [HIGH] CVE-2026-4462: chromium - Out of bounds read in Blink in Google Chrome prior to 146.0.7680.153 allowed a r...
Out of bounds read in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixi
debian
CVE-2026-4460P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4460 [HIGH] CVE-2026-4460: chromium - Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a re...
Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.153-1)
sid: resolved (fixed in 146.0.7680.153-1)
trixie
debian