cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 49 of 107
CVE-2021-21111P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21111 [CRITICAL] CVE-2021-21111: chromium - Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141... Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 87.0.4280.141-0.1) bullseye: resolved (fixed in 87.0.4280.141-0.1) forky: resolved (fixed in 8
debian
CVE-2025-12430P3HIGHCVSS 7.5fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12430 [HIGH] CVE-2025-12430: chromium - Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed ... Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) trixie: resolved (fi
debian
CVE-2019-5827P3HIGHCVSS 8.8fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5827 [HIGH] CVE-2019-5827: chromium - Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 al... Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 75.0.3770.80-1) bullseye: resolved (fixed in 75.0.3770.80-1) forky: resolved (fixed in 75.0.3770.80-1) sid: resolved (fixed in 75.0.3770.80-1) trixie: resolved
debian
CVE-2020-6413P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6413 [HIGH] CVE-2020-6413: chromium - Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 all... Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) trixie: resolved (fixed in
debian
CVE-2019-5822P3HIGHCVSS 8.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5822 [HIGH] CVE-2019-5822: chromium - Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 al... Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.108-1) trixie: resolved (fixe
debian
CVE-2019-5757P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5757 [HIGH] CVE-2019-5757: chromium - An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.8... An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-1) trixie: re
debian
CVE-2021-21174P3HIGHCVSS 8.8fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21174 [HIGH] CVE-2021-21174: chromium - Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 ... Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 89.0.4389.82-1) bullseye: resolved (fixed in 89.0.4389.82-1) forky: resolved (fixed in 89.0.4389.82-1) sid: resolved (fixed in 89.0.4389.82-1) trixie: resolved
debian
CVE-2019-13723P3HIGHCVSS 8.8fixed in chromium 78.0.3904.108-1 (bookworm)2019
CVE-2019-13723 [HIGH] CVE-2019-13723: chromium - Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a... Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.108-1) bullseye: resolved (fixed in 78.0.3904.108-1) forky: resolved (fixed in 78.0.3904.108-1) sid: resolved (fi
debian
CVE-2020-15976P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15976 [HIGH] CVE-2020-15976: chromium - Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowe... Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: re
debian
CVE-2019-13724P3HIGHCVSS 8.8fixed in chromium 78.0.3904.108-1 (bookworm)2019
CVE-2019-13724 [HIGH] CVE-2019-13724: chromium - Out of bounds memory access in WebBluetooth in Google Chrome prior to 78.0.3904.... Out of bounds memory access in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.108-1) bullseye: resolved (fixed in 78.0.3904.108-1) forky: resolved (fixed in 78.0.3904.108-1) sid:
debian
CVE-2020-15992P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15992 [HIGH] CVE-2020-15992: chromium - Insufficient policy enforcement in networking in Google Chrome prior to 86.0.424... Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resol
debian
CVE-2020-6543P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6543 [HIGH] CVE-2020-6543: chromium - Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowe... Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: reso
debian
CVE-2020-6544P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6544 [HIGH] CVE-2020-6544: chromium - Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote... Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixe
debian
CVE-2020-6545P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6545 [HIGH] CVE-2020-6545: chromium - Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote... Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixe
debian
CVE-2020-6496P3HIGHCVSS 8.8fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6496 [HIGH] CVE-2020-6496: chromium - Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allow... Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 83.0.4103.106-1) bullseye: resolved (fixed in 83.0.4103.106-1) forky: resolved (fixed in 83.0.4103.106-1) sid: resolved (fixed in 83.0.4103.106-1) trixie: resolv
debian
CVE-2021-30555P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30555 [HIGH] CVE-2021-30555: chromium - Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an att... Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and user gesture. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) s
debian
CVE-2021-21196P3HIGHCVSS 8.8fixed in chromium 89.0.4389.114-1 (bookworm)2021
CVE-2021-21196 [HIGH] CVE-2021-21196: chromium - Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.... Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 89.0.4389.114-1) bullseye: resolved (fixed in 89.0.4389.114-1) forky: resolved (fixed in 89.0.4389.114-1) sid: resolved (fixed in 89.0.4389.114-1) trix
debian
CVE-2021-21233P3HIGHCVSS 8.8fixed in chromium 90.0.4430.93-1 (bookworm)2021
CVE-2021-21233 [HIGH] CVE-2021-21233: chromium - Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 ... Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 90.0.4430.93-1) bullseye: resolved (fixed in 90.0.4430.93-1) forky: resolved (fixed in 90.0.4430.93-1) sid: resolved (fixed in 90.0.4430.93-1) trixie: reso
debian
CVE-2020-6532P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6532 [HIGH] CVE-2020-6532: chromium - Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote ... Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixed
debian
CVE-2021-21152P3HIGHCVSS 8.8fixed in chromium 88.0.4324.182-1 (bookworm)2021
CVE-2021-21152 [HIGH] CVE-2021-21152: chromium - Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 a... Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.182-1) bullseye: resolved (fixed in 88.0.4324.182-1) forky: resolved (fixed in 88.0.4324.182-1) sid: resolved (fixed in 88.0.4324.182-1) trixie: r
debian
Debian Chromium vulnerabilities | cvebase