Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 37 of 107
CVE-2023-2722P3HIGHCVSS 8.8fixed in chromium 113.0.5672.126-1 (bookworm)2023
CVE-2023-2722 [HIGH] CVE-2023-2722: chromium - Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.12...
Use after free in Autofill UI in Google Chrome on Android prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 113.0.5672.126-1)
bullseye: resolved (fixed in 113.0.5672.126-1~deb11u1)
forky: resolved (fixed in 113.0.5672.126-1)
sid
debian
CVE-2022-3370P3HIGHCVSS 8.8fixed in chromium 106.0.5249.91-1 (bookworm)2022
CVE-2022-3370 [HIGH] CVE-2022-3370: chromium - Use after free in Custom Elements in Google Chrome prior to 106.0.5249.91 allowe...
Use after free in Custom Elements in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 106.0.5249.91-1)
bullseye: resolved (fixed in 106.0.5249.91-1~deb11u1)
forky: resolved (fixed in 106.0.5249.91-1)
sid: resolved
debian
CVE-2023-2312P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-2312 [HIGH] CVE-2023-2312: chromium - Use after free in Offline in Google Chrome on Android prior to 116.0.5845.96 all...
Use after free in Offline in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky
debian
CVE-2023-1530P3HIGHCVSS 8.8fixed in chromium 111.0.5563.110-1 (bookworm)2023
CVE-2023-1530 [HIGH] CVE-2023-1530: chromium - Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote ...
Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 111.0.5563.110-1)
bullseye: resolved (fixed in 111.0.5563.110-1~deb11u1)
forky: resolved (fixed in 111.0.5563.110-1)
sid: resolved (fixed i
debian
CVE-2024-1674P3HIGHCVSS 8.8fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-1674 [HIGH] CVE-2024-1674: chromium - Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261....
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1)
bullseye: open
forky: resolved (fixed in 122.0.6261.57-1)
sid: resolved (fixed in 122.0.6261.57-1
debian
CVE-2022-3885P3HIGHCVSS 8.8fixed in chromium 107.0.5304.110-1 (bookworm)2022
CVE-2022-3885 [HIGH] CVE-2022-3885: chromium - Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote a...
Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 107.0.5304.110-1)
bullseye: resolved (fixed in 107.0.5304.110-1~deb11u1)
forky: resolved (fixed in 107.0.5304.110-1)
sid: resolved (fixed in
debian
CVE-2023-1528P3HIGHCVSS 8.8fixed in chromium 111.0.5563.110-1 (bookworm)2023
CVE-2023-1528 [HIGH] CVE-2023-1528: chromium - Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a r...
Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 111.0.5563.110-1)
bullseye: resolved (fixed in 111.0.5563.110-1~deb11u1)
forky: resolved (fi
debian
CVE-2023-2461P3HIGHCVSS 8.8fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2461 [HIGH] CVE-2023-2461: chromium - Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 ...
Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 113.0.5672.63-1)
bullseye: resolved (fixed in 113.0.5672.63-
debian
CVE-2024-7255P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-7255 [HIGH] CVE-2024-7255: chromium - Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allow...
Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1)
sid: resolved (fixed in 127.0.65
debian
CVE-2023-0471P3HIGHCVSS 8.8fixed in chromium 109.0.5414.119-1 (bookworm)2023
CVE-2023-0471 [HIGH] CVE-2023-0471: chromium - Use after free in WebTransport in Google Chrome prior to 109.0.5414.119 allowed ...
Use after free in WebTransport in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 109.0.5414.119-1)
bullseye: resolved (fixed in 109.0.5414.119-1~deb11u1)
forky: resolved (fixed in 109.0.5414.119-1)
sid: resolved
debian
CVE-2022-3889P3HIGHCVSS 8.8fixed in chromium 107.0.5304.110-1 (bookworm)2022
CVE-2022-3889 [HIGH] CVE-2022-3889: chromium - Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote a...
Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 107.0.5304.110-1)
bullseye: resolved (fixed in 107.0.5304.110-1~deb11u1)
forky: resolved (fixed in 107.0.5304.110-1)
sid: resolved (fixed in
debian
CVE-2022-3445P3HIGHCVSS 8.8fixed in chromium 106.0.5249.119-1 (bookworm)2022
CVE-2022-3445 [HIGH] CVE-2022-3445: chromium - Use after free in Skia in Google Chrome prior to 106.0.5249.119 allowed a remote...
Use after free in Skia in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 106.0.5249.119-1)
bullseye: resolved (fixed in 106.0.5249.119-1~deb11u1)
forky: resolved (fixed in 106.0.5249.119-1)
sid: resolved (fixed
debian
CVE-2023-3730P3HIGHCVSS 8.8fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3730 [HIGH] CVE-2023-3730: chromium - Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a r...
Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1)
bullseye: resolved (fixed in 115.0.5790.98-1~deb1
debian
CVE-2022-3886P3HIGHCVSS 8.8fixed in chromium 107.0.5304.110-1 (bookworm)2022
CVE-2022-3886 [HIGH] CVE-2022-3886: chromium - Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 al...
Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 107.0.5304.110-1)
bullseye: resolved (fixed in 107.0.5304.110-1~deb11u1)
forky: resolved (fixed in 107.0.5304.110-1)
sid: re
debian
CVE-2022-4175P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4175 [HIGH] CVE-2022-4175: chromium - Use after free in Camera Capture in Google Chrome prior to 108.0.5359.71 allowed...
Use after free in Camera Capture in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
forky: resolved (fixed in 108.0.5359.71-1)
sid: resolved (
debian
CVE-2022-3652P3HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3652 [HIGH] CVE-2022-3652: chromium - Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote at...
Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 107.0.5304.68-1)
bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1)
forky: resolved (fixed in 107.0.5304.68-1)
sid: resolved (fixed in 107
debian
CVE-2022-3888P3HIGHCVSS 8.8fixed in chromium 107.0.5304.110-1 (bookworm)2022
CVE-2022-3888 [HIGH] CVE-2022-3888: chromium - Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a r...
Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 107.0.5304.110-1)
bullseye: resolved (fixed in 107.0.5304.110-1~deb11u1)
forky: resolved (fixed in 107.0.5304.110-1)
sid: resolved (f
debian
CVE-2023-0472P3HIGHCVSS 8.8fixed in chromium 109.0.5414.119-1 (bookworm)2023
CVE-2023-0472 [HIGH] CVE-2023-0472: chromium - Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remo...
Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 109.0.5414.119-1)
bullseye: resolved (fixed in 109.0.5414.119-1~deb11u1)
forky: resolved (fixed in 109.0.5414.119-1)
sid: resolved (fixe
debian
CVE-2022-3304P3HIGHCVSS 8.8fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3304 [HIGH] CVE-2022-3304: chromium - Use after free in CSS in Google Chrome prior to 106.0.5249.62 allowed a remote a...
Use after free in CSS in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
forky: resolved (fixed in 106.0.5249.61-1)
sid: resolved (fixed in 10
debian
CVE-2023-0473P3HIGHCVSS 8.8fixed in chromium 109.0.5414.119-1 (bookworm)2023
CVE-2023-0473 [HIGH] CVE-2023-0473: chromium - Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 all...
Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 109.0.5414.119-1)
bullseye: resolved (fixed in 109.0.5414.119-1~deb11u1)
forky: resolved (fixed in 109.0.5414.119-1)
sid: r
debian