cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 31 of 107
CVE-2024-8198P3HIGHCVSS 8.8fixed in chromium 128.0.6613.113-1~deb12u1 (bookworm)2024
CVE-2024-8198 [HIGH] CVE-2024-8198: chromium - Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a ... Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 128.0.6613.113-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.113-1) sid: r
debian
CVE-2025-1918P3HIGHCVSS 8.8fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1918 [HIGH] CVE-2025-1918: chromium - Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a r... Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1) bullseye: open forky: resolved (fixed in 134.0.6998.35-1) sid: resolved (fixed in 134.0.6998.35
debian
CVE-2024-8193P3HIGHCVSS 8.8fixed in chromium 128.0.6613.113-1~deb12u1 (bookworm)2024
CVE-2024-8193 [HIGH] CVE-2024-8193: chromium - Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a ... Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 128.0.6613.113-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.113-1) sid: r
debian
CVE-2024-8194P3HIGHCVSS 8.8fixed in chromium 128.0.6613.113-1~deb12u1 (bookworm)2024
CVE-2024-8194 [HIGH] CVE-2024-8194: chromium - Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 128.0.6613.113-1~deb12u1) bullseye: open forky: resolved (fixed in 128.0.6613.113-1) sid: resolved (fixed in 128.0.6613.113-1) trixie: resol
debian
CVE-2024-11395P3HIGHCVSS 8.8fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11395 [HIGH] CVE-2024-11395: chromium - Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778.85-1) sid: resolved (fixed in 131.0.6778.85-1) trixie: resolve
debian
CVE-2025-9866P3HIGHCVSS 8.8fixed in chromium 140.0.7339.80-1~deb12u1 (bookworm)2025
CVE-2025-9866 [HIGH] CVE-2025-9866: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.... Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 140.0.7339.80-1~deb12u1) bullseye: open forky: resolved (fixed in 140.0.7339.80-1) sid: resolved (fixed in 140.0.7339.80-1
debian
CVE-2024-3169P3HIGHCVSS 8.8fixed in chromium 121.0.6167.139-1~deb12u1 (bookworm)2024
CVE-2024-3169 [HIGH] CVE-2024-3169: chromium - Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote a... Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 121.0.6167.139-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.139-1) sid: resolved (fixed in 121.0.6167.139-1) trixie: resol
debian
CVE-2024-3170P3HIGHCVSS 8.8fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-3170 [HIGH] CVE-2024-3170: chromium - Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remot... Use after free in WebRTC in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.85-1) sid: resolved (fixed in 121.0.6167.85-1) trixie: resol
debian
CVE-2024-11113P3HIGHCVSS 8.8fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11113 [HIGH] CVE-2024-11113: chromium - Use after free in Accessibility in Google Chrome prior to 131.0.6778.69 allowed ... Use after free in Accessibility in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778.85-1) si
debian
CVE-2025-3066P3HIGHCVSS 8.8fixed in chromium 135.0.7049.84-1~deb12u1 (bookworm)2025
CVE-2025-3066 [HIGH] CVE-2025-3066: chromium - Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed... Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 135.0.7049.84-1~deb12u1) bullseye: open forky: resolved (fixed in 135.0.7049.84-1) sid: resolved (fixed in 135.0.7049.84-1) trixi
debian
CVE-2025-1920P3HIGHCVSS 8.8fixed in chromium 134.0.6998.88-1~deb12u1 (bookworm)2025
CVE-2025-1920 [HIGH] CVE-2025-1920: chromium - Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 134.0.6998.88-1~deb12u1) bullseye: open forky: resolved (fixed in 134.0.6998.88-1) sid: resolved (fixed in 134.0.6998.88-1) trixie: resolved
debian
CVE-2025-2136P3HIGHCVSS 8.8fixed in chromium 134.0.6998.88-1~deb12u1 (bookworm)2025
CVE-2025-2136 [HIGH] CVE-2025-2136: chromium - Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a re... Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 134.0.6998.88-1~deb12u1) bullseye: open forky: resolved (fixed in 134.0.6998.88-1) sid: resolved (fixed in 134.0.6998.88-1) trixie:
debian
CVE-2024-12694P3HIGHCVSS 8.8fixed in chromium 131.0.6778.204-1~deb12u1 (bookworm)2024
CVE-2024-12694 [HIGH] CVE-2024-12694: chromium - Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a... Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 131.0.6778.204-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778.204-1) sid: resolved (fixed in 131.0.6778.204-1) tr
debian
CVE-2021-38023P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-38023 [HIGH] CVE-2021-38023: chromium - Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a r... Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0
debian
CVE-2025-8879P3HIGHCVSS 8.8fixed in chromium 139.0.7258.127-1~deb12u1 (bookworm)2025
CVE-2025-8879 [HIGH] CVE-2025-8879: chromium - Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed ... Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 139.0.7258.127-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0.7258.127-1) sid: resolved (fixed in 139.0.7258.127-
debian
CVE-2025-12725P3HIGHCVSS 8.8fixed in chromium 142.0.7444.134-1~deb12u1 (bookworm)2025
CVE-2025-12725 [HIGH] CVE-2025-12725: chromium - Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137... Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.134-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.134-1) sid: resolved (fixed in 142.0.74
debian
CVE-2025-3620P3HIGHCVSS 8.8fixed in chromium 135.0.7049.95-1~deb12u1 (bookworm)2025
CVE-2025-3620 [HIGH] CVE-2025-3620: chromium - Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote a... Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 135.0.7049.95-1~deb12u1) bullseye: open forky: resolved (fixed in 135.0.7049.95-1) sid: resolved (fixed in 135.0.7049.95-1) trixie: resolved
debian
CVE-2025-8882P3HIGHCVSS 8.8fixed in chromium 139.0.7258.127-1~deb12u1 (bookworm)2025
CVE-2025-8882 [HIGH] CVE-2025-8882: chromium - Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote... Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 139.0.7258.127-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0.7258.127
debian
CVE-2026-4462P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4462 [HIGH] CVE-2026-4462: chromium - Out of bounds read in Blink in Google Chrome prior to 146.0.7680.153 allowed a r... Out of bounds read in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) trixi
debian
CVE-2026-4460P3HIGHCVSS 8.8fixed in chromium 146.0.7680.153-1~deb12u1 (bookworm)2026
CVE-2026-4460 [HIGH] CVE-2026-4460: chromium - Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a re... Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.153-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.153-1) sid: resolved (fixed in 146.0.7680.153-1) trixie
debian
Debian Chromium vulnerabilities | cvebase