cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 48 of 107
CVE-2022-2743P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2743 [HIGH] CVE-2022-2743: chromium - Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prio... Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to perform an out of bounds memory write via crafted UI interactions. (Chrome security severity: High) Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fix
debian
CVE-2023-1213P3HIGHCVSS 8.8fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1213 [HIGH] CVE-2023-1213: chromium - Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a ... Use after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 111.0.5563.64-1) bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1) forky: resolved (fixed in 111.0.5563.64-1) sid: resolved (fix
debian
CVE-2025-0447P3HIGHCVSS 8.8fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0447 [HIGH] CVE-2025-0447: chromium - Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.... Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1) bullseye: open forky: resolved (fixed in 132.0.6834.83-1) sid: resolved (fixed in 132.0.6834.83-1) tri
debian
CVE-2024-0806P3HIGHCVSS 8.8fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-0806 [HIGH] CVE-2024-0806: chromium - Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a re... Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.85-1) sid: resolved (fixed in 121.0.6167.85-1) trix
debian
CVE-2022-2742P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2742 [HIGH] CVE-2022-2742: chromium - Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 10... Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions. (Chrome security severity: High) Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104
debian
CVE-2025-1919P3HIGHCVSS 8.8fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1919 [HIGH] CVE-2025-1919: chromium - Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a re... Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1) bullseye: open forky: resolved (fixed in 134.0.6998.35-1) sid: resolved (fixed in 134.0.6998.35
debian
CVE-2024-11115P3HIGHCVSS 8.8fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11115 [HIGH] CVE-2024-11115: chromium - Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 1... Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed a remote attacker to perform privilege escalation via a series of UI gestures. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778.85-1) sid: resolved (fixed in 1
debian
CVE-2025-3068P3HIGHCVSS 8.8fixed in chromium 135.0.7049.52-1~deb12u1 (bookworm)2025
CVE-2025-3068 [HIGH] CVE-2025-3068: chromium - Inappropriate implementation in Intents in Google Chrome on Android prior to 135... Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 135.0.7049.52-1~deb12u1) bullseye: open forky: resolved (fixed in 135.0.7049.52-1) sid: resolved (fixed in 135.0.704
debian
CVE-2025-3069P3HIGHCVSS 8.8fixed in chromium 135.0.7049.52-1~deb12u1 (bookworm)2025
CVE-2025-3069 [HIGH] CVE-2025-3069: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.... Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 135.0.7049.52-1~deb12u1) bullseye: open forky: resolved (fixed in 135.0.7049.52-1) sid: resolved (fixed in 135.0.7049.52-1)
debian
CVE-2025-0437P3HIGHCVSS 8.8fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0437 [HIGH] CVE-2025-0437: chromium - Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a ... Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1) bullseye: open forky: resolved (fixed in 132.0.6834.83-1) sid: resolved (fixed in 132.0.6834.83-1) trixie:
debian
CVE-2025-1916P3HIGHCVSS 8.8fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1916 [HIGH] CVE-2025-1916: chromium - Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an at... Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1) bullseye: open forky: resolved (fixed in 134.0.6998.35-1) si
debian
CVE-2026-5904P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5904 [HIGH] CVE-2026-5904: chromium - Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed an attacker... Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2024-5158P3HIGHCVSS 8.1fixed in chromium 125.0.6422.76-1~deb12u1 (bookworm)2024
CVE-2024-5158 [HIGH] CVE-2024-5158: chromium - Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 125.0.6422.76-1~deb12u1) bullseye: open forky: resolved (fixed in 125.0.6422.76-1) sid: resolved (fixed in 125.0.6422.76-1) trixie: reso
debian
CVE-2025-11458P3HIGHCVSS 8.1fixed in chromium 141.0.7390.65-1~deb12u1 (bookworm)2025
CVE-2025-11458 [HIGH] CVE-2025-11458: chromium - Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a r... Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 141.0.7390.65-1~deb12u1) bullseye: open forky: resolved (fixed in 141.0.7390.65-1) sid: resolved (fixed in 141.0.7390.65-1) trixie
debian
CVE-2021-30607P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30607 [HIGH] CVE-2021-30607: chromium - Chromium: CVE-2021-30607 Use after free in Permissions Chromium: CVE-2021-30607 Use after free in Permissions Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2019-15903P3LOWCVSS 7.5fixed in expat 2.2.7-2 (bookworm)2019
CVE-2019-15903 [HIGH] CVE-2019-15903: chromium - In libexpat before 2.2.8, crafted XML input could fool the parser into changing ... In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2020-6471P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6471 [CRITICAL] CVE-2020-6471: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 83.... Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 83.0.4103.83-1) bullseye: resolved (fixed in 83.0.4103.83-1) forky: resolved (fixed in
debian
CVE-2025-11211P3HIGHCVSS 7.5fixed in chromium 141.0.7390.65-1~deb12u1 (bookworm)2025
CVE-2025-11211 [HIGH] CVE-2025-11211: chromium - Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a re... Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 141.0.7390.65-1~deb12u1) bullseye: open forky: resolved (fixed in 141.0.7390.65-1) sid: resolved (fixed in 141.0.7390.
debian
CVE-2021-21111P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21111 [CRITICAL] CVE-2021-21111: chromium - Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141... Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 87.0.4280.141-0.1) bullseye: resolved (fixed in 87.0.4280.141-0.1) forky: resolved (fixed in 8
debian
CVE-2025-12430P3HIGHCVSS 7.5fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12430 [HIGH] CVE-2025-12430: chromium - Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed ... Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) trixie: resolved (fi
debian
Debian Chromium vulnerabilities | cvebase