Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 47 of 107
CVE-2023-3598P3HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-3598 [HIGH] CVE-2023-3598: chromium - Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 al...
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1)
forky: resolved (fixed in 114.0.5735.90-1)
si
debian
CVE-2023-0930P3HIGHCVSS 8.8fixed in chromium 110.0.5481.177-1 (bookworm)2023
CVE-2023-0930 [HIGH] CVE-2023-0930: chromium - Heap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a...
Heap buffer overflow in Video in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 110.0.5481.177-1)
bullseye: resolved (fixed in 110.0.5481.177-1~deb11u1)
forky: resolved (fixed in 110.0.5481.177-1)
sid: resolved
debian
CVE-2023-4368P3HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4368 [HIGH] CVE-2023-4368: chromium - Insufficient policy enforcement in Extensions API in Google Chrome prior to 116....
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~
debian
CVE-2022-4193P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4193 [HIGH] CVE-2022-4193: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 108...
Insufficient policy enforcement in File System API in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
forky: resolved (fixed in 108.0.5359.71-1)
debian
CVE-2023-3422P3HIGHCVSS 8.8fixed in chromium 114.0.5735.198-1~deb12u1 (bookworm)2023
CVE-2023-3422 [HIGH] CVE-2023-3422: chromium - Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an...
Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 114.0.5735.198-1~deb12u1)
bullseye: resolved (fixed in 114.0.5735.198-1~deb11u1)
for
debian
CVE-2022-4438P3HIGHCVSS 8.8fixed in chromium 108.0.5359.124-1 (bookworm)2022
CVE-2022-4438 [HIGH] CVE-2022-4438: chromium - Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed ...
Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 108.0.5359.124-1)
bullseye: resolved (fixed in 108.0.5359.124-1~deb11
debian
CVE-2023-0136P3HIGHCVSS 8.8fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0136 [HIGH] CVE-2023-0136: chromium - Inappropriate implementation in in Fullscreen API in Google Chrome on Android pr...
Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to execute incorrect security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 109.0.5414.74-1)
bullseye: resolved (fixed in 109.0.5414.74-2~deb11u1)
forky: resolved (fixed in 109.0.54
debian
CVE-2022-4194P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4194 [HIGH] CVE-2022-4194: chromium - Use after free in Accessibility in Google Chrome prior to 108.0.5359.71 allowed ...
Use after free in Accessibility in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
forky: resolved (fixed in 108.0.5359.71-1)
sid: resolved
debian
CVE-2022-3198P3HIGHCVSS 8.8fixed in chromium 105.0.5195.125-1 (bookworm)2022
CVE-2022-3198 [HIGH] CVE-2022-3198: chromium - Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote ...
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 105.0.5195.125-1)
bullseye: resolved (fixed in 105.0.5195.125-1~deb11u1)
forky: resolved (fixed in 105.0.5195.125-1)
sid: resolved (fixed in
debian
CVE-2022-2606P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2606 [HIGH] CVE-2022-2606: chromium - Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 al...
Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enable a specific Enterprise policy to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky: resolved (fixed in 10
debian
CVE-2022-4440P3HIGHCVSS 8.8fixed in chromium 108.0.5359.124-1 (bookworm)2022
CVE-2022-4440 [HIGH] CVE-2022-4440: chromium - Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a re...
Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.124-1)
bullseye: resolved (fixed in 108.0.5359.124-1~deb11u1)
forky: resolved (fixed in 108.0.5359.124-1)
sid: resolved (
debian
CVE-2022-4176P3HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4176 [HIGH] CVE-2022-4176: chromium - Out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros ...
Out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed i
debian
CVE-2023-0941P3HIGHCVSS 8.8fixed in chromium 110.0.5481.177-1 (bookworm)2023
CVE-2023-0941 [HIGH] CVE-2023-0941: chromium - Use after free in Prompts in Google Chrome prior to 110.0.5481.177 allowed a rem...
Use after free in Prompts in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 110.0.5481.177-1)
bullseye: resolved (fixed in 110.0.5481.177-1~deb11u1)
forky: resolved (fixed in 110.0.5481.177-1)
sid: resolved
debian
CVE-2022-2620P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2620 [HIGH] CVE-2022-2620: chromium - Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 all...
Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky: resolved (fixed
debian
CVE-2023-1222P3HIGHCVSS 8.8fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1222 [HIGH] CVE-2023-1222: chromium - Heap buffer overflow in Web Audio API in Google Chrome prior to 111.0.5563.64 al...
Heap buffer overflow in Web Audio API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-1)
sid: res
debian
CVE-2023-0932P3HIGHCVSS 8.8fixed in chromium 110.0.5481.177-1 (bookworm)2023
CVE-2023-0932 [HIGH] CVE-2023-0932: chromium - Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 all...
Use after free in WebRTC in Google Chrome on Windows prior to 110.0.5481.177 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 110.0.5481.177-1)
bullseye: resolved (fixed in 110.0.5481.177-1~
debian
CVE-2023-1215P3HIGHCVSS 8.8fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1215 [HIGH] CVE-2023-1215: chromium - Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote a...
Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-1)
sid: resolved (fixed in 11
debian
CVE-2022-4914P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-4914 [HIGH] CVE-2022-4914: chromium - Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 all...
Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
fork
debian
CVE-2022-3659P3HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3659 [HIGH] CVE-2022-3659: chromium - Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.530...
Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 107.0.5304.68-1)
bullseye: resolved (fixed in 107.0
debian
CVE-2023-1218P3HIGHCVSS 8.8fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1218 [HIGH] CVE-2023-1218: chromium - Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remot...
Use after free in WebRTC in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-1)
sid: resolved (fixed in
debian