Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 49 of 107
CVE-2021-21111P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21111 [CRITICAL] CVE-2021-21111: chromium - Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141...
Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 87.0.4280.141-0.1)
bullseye: resolved (fixed in 87.0.4280.141-0.1)
forky: resolved (fixed in 8
debian
CVE-2025-12430P3HIGHCVSS 7.5fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12430 [HIGH] CVE-2025-12430: chromium - Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed ...
Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
trixie: resolved (fi
debian
CVE-2019-5827P3HIGHCVSS 8.8fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5827 [HIGH] CVE-2019-5827: chromium - Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 al...
Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 75.0.3770.80-1)
bullseye: resolved (fixed in 75.0.3770.80-1)
forky: resolved (fixed in 75.0.3770.80-1)
sid: resolved (fixed in 75.0.3770.80-1)
trixie: resolved
debian
CVE-2020-6413P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6413 [HIGH] CVE-2020-6413: chromium - Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 all...
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: resolved (fixed in
debian
CVE-2019-5822P3HIGHCVSS 8.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5822 [HIGH] CVE-2019-5822: chromium - Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 al...
Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74.0.3729.108-1)
trixie: resolved (fixe
debian
CVE-2019-5757P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5757 [HIGH] CVE-2019-5757: chromium - An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.8...
An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.0.3626.81-1)
trixie: re
debian
CVE-2021-21174P3HIGHCVSS 8.8fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21174 [HIGH] CVE-2021-21174: chromium - Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 ...
Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed in 89.0.4389.82-1)
trixie: resolved
debian
CVE-2019-13723P3HIGHCVSS 8.8fixed in chromium 78.0.3904.108-1 (bookworm)2019
CVE-2019-13723 [HIGH] CVE-2019-13723: chromium - Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a...
Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.108-1)
bullseye: resolved (fixed in 78.0.3904.108-1)
forky: resolved (fixed in 78.0.3904.108-1)
sid: resolved (fi
debian
CVE-2020-15976P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15976 [HIGH] CVE-2020-15976: chromium - Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowe...
Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: re
debian
CVE-2019-13724P3HIGHCVSS 8.8fixed in chromium 78.0.3904.108-1 (bookworm)2019
CVE-2019-13724 [HIGH] CVE-2019-13724: chromium - Out of bounds memory access in WebBluetooth in Google Chrome prior to 78.0.3904....
Out of bounds memory access in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.108-1)
bullseye: resolved (fixed in 78.0.3904.108-1)
forky: resolved (fixed in 78.0.3904.108-1)
sid:
debian
CVE-2020-15992P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15992 [HIGH] CVE-2020-15992: chromium - Insufficient policy enforcement in networking in Google Chrome prior to 86.0.424...
Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resol
debian
CVE-2020-6543P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6543 [HIGH] CVE-2020-6543: chromium - Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowe...
Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: reso
debian
CVE-2020-6544P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6544 [HIGH] CVE-2020-6544: chromium - Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote...
Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixe
debian
CVE-2020-6545P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6545 [HIGH] CVE-2020-6545: chromium - Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote...
Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixe
debian
CVE-2020-6496P3HIGHCVSS 8.8fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6496 [HIGH] CVE-2020-6496: chromium - Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allow...
Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.106-1)
bullseye: resolved (fixed in 83.0.4103.106-1)
forky: resolved (fixed in 83.0.4103.106-1)
sid: resolved (fixed in 83.0.4103.106-1)
trixie: resolv
debian
CVE-2021-30555P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30555 [HIGH] CVE-2021-30555: chromium - Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an att...
Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and user gesture.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
s
debian
CVE-2021-21196P3HIGHCVSS 8.8fixed in chromium 89.0.4389.114-1 (bookworm)2021
CVE-2021-21196 [HIGH] CVE-2021-21196: chromium - Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389....
Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.114-1)
bullseye: resolved (fixed in 89.0.4389.114-1)
forky: resolved (fixed in 89.0.4389.114-1)
sid: resolved (fixed in 89.0.4389.114-1)
trix
debian
CVE-2021-21233P3HIGHCVSS 8.8fixed in chromium 90.0.4430.93-1 (bookworm)2021
CVE-2021-21233 [HIGH] CVE-2021-21233: chromium - Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 ...
Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.93-1)
bullseye: resolved (fixed in 90.0.4430.93-1)
forky: resolved (fixed in 90.0.4430.93-1)
sid: resolved (fixed in 90.0.4430.93-1)
trixie: reso
debian
CVE-2020-6532P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6532 [HIGH] CVE-2020-6532: chromium - Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote ...
Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixed
debian
CVE-2021-21152P3HIGHCVSS 8.8fixed in chromium 88.0.4324.182-1 (bookworm)2021
CVE-2021-21152 [HIGH] CVE-2021-21152: chromium - Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 a...
Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.182-1)
bullseye: resolved (fixed in 88.0.4324.182-1)
forky: resolved (fixed in 88.0.4324.182-1)
sid: resolved (fixed in 88.0.4324.182-1)
trixie: r
debian