cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 40 of 107
CVE-2025-0762P3HIGHCVSS 8.8fixed in chromium 132.0.6834.159-1~deb12u1 (bookworm)2025
CVE-2025-0762 [HIGH] CVE-2025-0762: chromium - Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a re... Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 132.0.6834.159-1~deb12u1) bullseye: open forky: resolved (fixed in 132.0.6834.159-1) sid: resolved (fixed in 132.0.6834.159-1
debian
CVE-2024-9959P3HIGHCVSS 8.8fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9959 [HIGH] CVE-2024-9959: chromium - Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a rem... Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1) bullseye: open forky: resolved (fixed in 130.0.6723.58-1) si
debian
CVE-2024-3171P3HIGHCVSS 8.8fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-3171 [HIGH] CVE-2024-3171: chromium - Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed ... Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.
debian
CVE-2026-5292P3HIGHCVSS 8.8fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5292 [HIGH] CVE-2026-5292: chromium - Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed... Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1) sid: resolved (fixed in 146.0.7680.177-1)
debian
CVE-2023-4070P3HIGHCVSS 8.1fixed in chromium 115.0.5790.170-1~deb12u1 (bookworm)2023
CVE-2023-4070 [HIGH] CVE-2023-4070: chromium - Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.170-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.170-1~deb11u1) forky: resolved (fixed in 115.0.5790.170-1) sid: resolved (fixed i
debian
CVE-2025-13639P3HIGHCVSS 8.1fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13639 [HIGH] CVE-2025-13639: chromium - Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 a... Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1) bullseye: open forky: resolved (fixed in 143.0.7499.40-1) sid: resolved (fixed in 143.0.7499.40-1) trixi
debian
CVE-2021-30609P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30609 [HIGH] CVE-2021-30609: chromium - Chromium: CVE-2021-30609 Use after free in Sign-In Chromium: CVE-2021-30609 Use after free in Sign-In Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2021-30613P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30613 [HIGH] CVE-2021-30613: chromium - Chromium: CVE-2021-30613 Use after free in Base internals Chromium: CVE-2021-30613 Use after free in Base internals Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2021-30624P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30624 [HIGH] CVE-2021-30624: chromium - Chromium: CVE-2021-30624 Use after free in Autofill Chromium: CVE-2021-30624 Use after free in Autofill Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2021-30622P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30622 [HIGH] CVE-2021-30622: chromium - Chromium: CVE-2021-30622 Use after free in WebApp Installs Chromium: CVE-2021-30622 Use after free in WebApp Installs Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2021-30623P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30623 [HIGH] CVE-2021-30623: chromium - Chromium: CVE-2021-30623 Use after free in Bookmarks Chromium: CVE-2021-30623 Use after free in Bookmarks Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2020-15963P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15963 [CRITICAL] CVE-2020-15963: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.418... Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed i
debian
CVE-2019-5850P3CRITICALCVSS 9.6fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5850 [CRITICAL] CVE-2019-5850: chromium - Use after free in offline mode in Google Chrome prior to 76.0.3809.87 allowed a ... Use after free in offline mode in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 76.0.3809.87-1) bullseye: resolved (fixed in 76.0.3809.87-1) forky: resolved (fixed in 76.0.3809.87-1) sid: resolved (fix
debian
CVE-2022-0466P3CRITICALCVSS 9.6fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0466 [CRITICAL] CVE-2022-0466: chromium - Inappropriate implementation in Extensions Platform in Google Chrome prior to 98... Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 98.0.4758.80-1) bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1) forky: resolved (fixed i
debian
CVE-2020-6385P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6385 [HIGH] CVE-2020-6385: chromium - Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.8... Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: resolved (fixe
debian
CVE-2020-6415P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6415 [HIGH] CVE-2020-6415: chromium - Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.8... Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie:
debian
CVE-2020-6414P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6414 [HIGH] CVE-2020-6414: chromium - Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.... Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie:
debian
CVE-2020-6387P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6387 [HIGH] CVE-2020-6387: chromium - Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a r... Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: resolved (
debian
CVE-2020-6398P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6398 [HIGH] CVE-2020-6398: chromium - Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allow... Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: resolved
debian
CVE-2019-5808P3HIGHCVSS 8.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5808 [HIGH] CVE-2019-5808: chromium - Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote... Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.108-1) trixie: resolved (fixed in
debian
Debian Chromium vulnerabilities | cvebase