Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 39 of 107
CVE-2024-6998P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-6998 [HIGH] CVE-2024-6998: chromium - Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed...
Use after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.
debian
CVE-2024-5844P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5844 [HIGH] CVE-2024-5844: chromium - Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowe...
Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.56-1)
sid: resolved (fixed in 126.0.6478.56-1)
t
debian
CVE-2024-7000P3HIGHCVSS 8.8fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-7000 [HIGH] CVE-2024-7000: chromium - Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote a...
Use after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1)
debian
CVE-2024-0812P3HIGHCVSS 8.8fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-0812 [HIGH] CVE-2024-0812: chromium - Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.61...
Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 121.0.6167.85-1)
sid: resolved (fixed in 121.0.6
debian
CVE-2024-0807P3HIGHCVSS 8.8fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-0807 [HIGH] CVE-2024-0807: chromium - Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a re...
Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 121.0.6167.85-1)
sid: resolved (fixed in 121.0.6167.85-1)
trixie: re
debian
CVE-2024-6773P3HIGHCVSS 8.8fixed in chromium 126.0.6478.182-1~deb12u1 (bookworm)2024
CVE-2024-6773 [HIGH] CVE-2024-6773: chromium - Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allo...
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.182-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.182-1)
sid: resolved (fixed in 126.0.6478.182-1)
debian
CVE-2024-9120P3HIGHCVSS 8.8fixed in chromium 129.0.6668.70-1~deb12u1 (bookworm)2024
CVE-2024-9120 [HIGH] CVE-2024-9120: chromium - Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowe...
Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 129.0.6668.70-1~deb12u1)
bullseye: open
forky: resolved (fixed in 129.0.6668.70-1)
sid: resolved (fixed in 129.0.6668.70-1)
trix
debian
CVE-2025-0436P3HIGHCVSS 8.8fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0436 [HIGH] CVE-2025-0436: chromium - Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remot...
Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1)
bullseye: open
forky: resolved (fixed in 132.0.6834.83-1)
sid: resolved (fixed in 132.0.6834.83-1)
trixie: resol
debian
CVE-2024-8637P3HIGHCVSS 8.8fixed in chromium 128.0.6613.137-1~deb12u1 (bookworm)2024
CVE-2024-8637 [HIGH] CVE-2024-8637: chromium - Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.1...
Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.137-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.137-1)
sid: resolved (fixed in 128.0.6613
debian
CVE-2024-8638P3HIGHCVSS 8.8fixed in chromium 128.0.6613.137-1~deb12u1 (bookworm)2024
CVE-2024-8638 [HIGH] CVE-2024-8638: chromium - Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote a...
Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.137-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.137-1)
sid: resolved (fixed in 128.0.6613.137-1)
trixie: res
debian
CVE-2025-1914P3HIGHCVSS 8.8fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1914 [HIGH] CVE-2025-1914: chromium - Out of bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remot...
Out of bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1)
bullseye: open
forky: resolved (fixed in 134.0.6998.35-1)
sid: resolved (fixed in 134.0.6998.35-1)
trixie: resol
debian
CVE-2024-9961P3HIGHCVSS 8.8fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9961 [HIGH] CVE-2024-9961: chromium - Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 ...
Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in
debian
CVE-2024-9957P3HIGHCVSS 8.8fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9957 [HIGH] CVE-2024-9957: chromium - Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a re...
Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.
debian
CVE-2024-3174P3HIGHCVSS 8.8fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2024
CVE-2024-3174 [HIGH] CVE-2024-3174: chromium - Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allo...
Inappropriate implementation in V8 in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1)
bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1)
forky: resolved (fixed in 119.0.6045.105-1)
debian
CVE-2024-9123P3HIGHCVSS 8.8fixed in chromium 129.0.6668.70-1~deb12u1 (bookworm)2024
CVE-2024-9123 [HIGH] CVE-2024-9123: chromium - Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remot...
Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 129.0.6668.70-1~deb12u1)
bullseye: open
forky: resolved (fixed in 129.0.6668.70-1)
sid: resolved (fixed in 129.0.6668.70-1)
trixie: res
debian
CVE-2025-2137P3HIGHCVSS 8.8fixed in chromium 134.0.6998.88-1~deb12u1 (bookworm)2025
CVE-2025-2137 [HIGH] CVE-2025-2137: chromium - Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remot...
Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 134.0.6998.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 134.0.6998.88-1)
sid: resolved (fixed in 134.0.6998.88-1)
trixie: res
debian
CVE-2024-8639P3HIGHCVSS 8.8fixed in chromium 128.0.6613.137-1~deb12u1 (bookworm)2024
CVE-2024-8639 [HIGH] CVE-2024-8639: chromium - Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 a...
Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 128.0.6613.137-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.137-1)
sid: resolved (fixed in 128.0.6613.137
debian
CVE-2024-3176P3HIGHCVSS 8.8fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2024
CVE-2024-3176 [HIGH] CVE-2024-3176: chromium - Out of bounds write in SwiftShader in Google Chrome prior to 117.0.5938.62 allow...
Out of bounds write in SwiftShader in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1)
forky: resolved (fixed in 117.0.5938.62-1)
sid
debian
CVE-2024-11112P3HIGHCVSS 8.8fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11112 [HIGH] CVE-2024-11112: chromium - Use after free in Media in Google Chrome on Windows prior to 131.0.6778.69 allow...
Use after free in Media in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 131.0.6778.85-1)
sid: resolved (fixed in 131.0.6778.85-1)
debian
CVE-2024-3168P3HIGHCVSS 8.8fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-3168 [HIGH] CVE-2024-3168: chromium - Use after free in DevTools in Google Chrome prior to 122.0.6261.57 allowed a rem...
Use after free in DevTools in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1)
bullseye: open
forky: resolved (fixed in 122.0.6261.57-1)
sid: resolved (fixed in 122.0.6261.57-1)
trixie: r
debian