Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 32 of 107
CVE-2024-3173P3HIGHCVSS 8.8fixed in chromium 120.0.6099.71-1~deb12u1 (bookworm)2024
CVE-2024-3173 [HIGH] CVE-2024-3173: chromium - Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 ...
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 120.0.6099.71-1~deb12u1)
bullseye: resolved (fixed in 120.0.6099.71-1~deb11u1)
forky: resolved (fixed in 120.0.6099.71-1)
s
debian
CVE-2025-3067P3HIGHCVSS 8.6fixed in chromium 135.0.7049.52-1~deb12u1 (bookworm)2025
CVE-2025-3067 [HIGH] CVE-2025-3067: chromium - Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to...
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted app. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 135.0.7049.52-1~deb12u1)
bullseye: open
forky: resolved (fixed
debian
CVE-2024-2886P3HIGHCVSS 7.5fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2886 [HIGH] CVE-2024-2886: chromium - Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a re...
Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.86-1)
sid: resolved (fixed in 123.0.6312.86-1)
trixie: resolved
debian
CVE-2021-30618P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30618 [HIGH] CVE-2021-30618: chromium - Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2021-30608P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30608 [HIGH] CVE-2021-30608: chromium - Chromium: CVE-2021-30608 Use after free in Web Share
Chromium: CVE-2021-30608 Use after free in Web Share
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2021-21216P3MEDIUMCVSS 6.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21216 [MEDIUM] CVE-2021-21216: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 ...
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1)
trixie: resolved (fixed in 9
debian
CVE-2020-6522P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6522 [CRITICAL] CVE-2020-6522: chromium - Inappropriate implementation in external protocol handlers in Google Chrome prio...
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 8
debian
CVE-2020-6465P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6465 [CRITICAL] CVE-2020-6465: chromium - Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 ...
Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: res
debian
CVE-2020-15961P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15961 [CRITICAL] CVE-2020-15961: chromium - Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183...
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in
debian
CVE-2020-6462P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6462 [CRITICAL] CVE-2020-6462: chromium - Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowe...
Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved
debian
CVE-2021-30571P3CRITICALCVSS 9.6fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30571 [CRITICAL] CVE-2021-30571: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515....
Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.8
debian
CVE-2020-6461P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6461 [CRITICAL] CVE-2020-6461: chromium - Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remo...
Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed i
debian
CVE-2026-5284P3HIGHCVSS 7.5fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5284 [HIGH] CVE-2026-5284: chromium - Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote...
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177-1)
sid: resolved (fixed in 1
debian
CVE-2019-5770P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5770 [HIGH] CVE-2019-5770: chromium - Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 al...
Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.0.3626.81-1)
trixie: resolve
debian
CVE-2021-37981P3CRITICALCVSS 9.6fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37981 [CRITICAL] CVE-2021-37981: chromium - Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a re...
Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid:
debian
CVE-2020-6505P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6505 [CRITICAL] CVE-2020-6505: chromium - Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remot...
Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.106-1)
bullseye: resolved (fixed in 83.0.4103.106-1)
forky: resolved (fixed in 83.0.4103.106-1)
sid: resolved (fixed in 83.0.4103.106-1)
trixie: resolved (fi
debian
CVE-2022-0097P3CRITICALCVSS 9.6fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0097 [CRITICAL] CVE-2022-0097: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 ...
Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved
debian
CVE-2022-0977P3CRITICALCVSS 9.6fixed in chromium 99.0.4844.74-1 (bookworm)2022
CVE-2022-0977 [CRITICAL] CVE-2022-0977: chromium - Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74...
Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 99.0.4844.74-1)
bullseye: resolved (fixed in 99.0.4844.74-1~deb11u1)
forky: resolved (fixed
debian
CVE-2020-16016P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16016 [CRITICAL] CVE-2020-16016: chromium - Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 all...
Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid
debian
CVE-2020-6449P3HIGHCVSS 8.8fixed in chromium 80.0.3987.149-1 (bookworm)2020
CVE-2020-6449 [HIGH] CVE-2020-6449: chromium - Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote...
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.149-1)
bullseye: resolved (fixed in 80.0.3987.149-1)
forky: resolved (fixed in 80.0.3987.149-1)
sid: resolved (fixed in 80.0.3987.149-1)
trixie: resolved (fixed in
debian