Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 5 of 107
CVE-2019-5797P3HIGHCVSS 7.5PoCfixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5797 [HIGH] CVE-2019-5797: chromium - Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remot...
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 73.0.3683.75-1)
bullseye: resolved (fixed in 73.0.3683.75-1)
forky: resolved (fixed in 73.0.3683.75-1)
sid: resolved (fixed in 73.0.3683.75-1)
trixie: resolved (fixed in 73
debian
CVE-2024-1283P2CRITICALCVSS 9.8fixed in chromium 121.0.6167.160-1~deb12u1 (bookworm)2024
CVE-2024-1283 [CRITICAL] CVE-2024-1283: chromium - Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a ...
Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 121.0.6167.160-1~deb12u1)
bullseye: open
forky: resolved (fixed in 121.0.6167.160-1)
sid: resolved (fixed in 121.0.6167.160-1)
t
debian
CVE-2020-6519P3MEDIUMCVSS 6.5PoCfixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6519 [MEDIUM] CVE-2020-6519: chromium - Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote att...
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixed in 87
debian
CVE-2023-6112P2HIGHCVSS 8.8fixed in chromium 119.0.6045.159-1~deb12u1 (bookworm)2023
CVE-2023-6112 [HIGH] CVE-2023-6112: chromium - Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a ...
Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 119.0.6045.159-1~deb12u1)
bullseye: resolved (fixed in 119.0.6045.159-1~deb11u1)
forky: resolved (fixed in 119.0.6045.159-1)
sid: re
debian
CVE-2023-2724P2HIGHCVSS 8.8fixed in chromium 113.0.5672.126-1 (bookworm)2023
CVE-2023-2724 [HIGH] CVE-2023-2724: chromium - Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote a...
Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 113.0.5672.126-1)
bullseye: resolved (fixed in 113.0.5672.126-1~deb11u1)
forky: resolved (fixed in 113.0.5672.126-1)
sid: resolved (fixed in
debian
CVE-2026-0907P2CRITICALCVSS 9.8fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0907 [CRITICAL] CVE-2026-0907: chromium - Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allo...
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 144.0.7559.59-1)
sid: resolved (fixed in 144.0.7559.59-1)
trixie: resolve
debian
CVE-2023-4355P2HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4355 [HIGH] CVE-2023-4355: chromium - Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowe...
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky: resolved (fixed in 116.0.5845.96-1)
sid: r
debian
CVE-2023-4069P2HIGHCVSS 8.8fixed in chromium 115.0.5790.170-1~deb12u1 (bookworm)2023
CVE-2023-4069 [HIGH] CVE-2023-4069: chromium - Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote a...
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 115.0.5790.170-1~deb12u1)
bullseye: resolved (fixed in 115.0.5790.170-1~deb11u1)
forky: resolved (fixed in 115.0.5790.170-1)
sid: resolved (
debian
CVE-2023-2935P2HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2935 [HIGH] CVE-2023-2935: chromium - Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1)
forky: resolved (fixed in 114.0.5735.90-1)
sid: resolved (fixe
debian
CVE-2023-2936P2HIGHCVSS 8.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2936 [HIGH] CVE-2023-2936: chromium - Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote at...
Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1)
forky: resolved (fixed in 114.0.5735.90-1)
sid: resolved (fixe
debian
CVE-2024-0517P2HIGHCVSS 8.8fixed in chromium 120.0.6099.224-1~deb12u1 (bookworm)2024
CVE-2024-0517 [HIGH] CVE-2024-0517: chromium - Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a rem...
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 120.0.6099.224-1~deb12u1)
bullseye: resolved (fixed in 120.0.6099.224-1~deb11u1)
forky: resolved (fixed in 120.0.6099.224-1)
sid: resol
debian
CVE-2021-38001P2HIGHCVSS 8.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-38001 [HIGH] CVE-2021-38001: chromium - Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote att...
Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: resolved
debian
CVE-2022-2998P2HIGHCVSS 8.8fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2998 [HIGH] CVE-2022-2998: chromium - Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allo...
Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI interaction to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.101-1)
bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1)
forky: resolved (fixed i
debian
CVE-2022-4178P2HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4178 [HIGH] CVE-2022-4178: chromium - Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote ...
Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
forky: resolved (fixed in 1
debian
CVE-2022-3654P2HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3654 [HIGH] CVE-2022-3654: chromium - Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remot...
Use after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 107.0.5304.68-1)
bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1)
forky: resolved (fixed in 107.0.5304.68-1)
sid: resolved (fixed in
debian
CVE-2020-6551P2HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6551 [HIGH] CVE-2020-6551: chromium - Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote...
Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixe
debian
CVE-2020-6550P2HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6550 [HIGH] CVE-2020-6550: chromium - Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a re...
Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (
debian
CVE-2022-0289P2HIGHCVSS 8.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0289 [HIGH] CVE-2022-0289: chromium - Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a...
Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1)
sid: resolved (fixed in 97.0.4692.99-1)
trixie: resolve
debian
CVE-2023-4427P2HIGHCVSS 8.1fixed in chromium 116.0.5845.110-1~deb12u1 (bookworm)2023
CVE-2023-4427 [HIGH] CVE-2023-4427: chromium - Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allow...
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 116.0.5845.110-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.110-1~deb11u1)
forky: resolved (fixed in 116.0.5845.110-1)
s
debian
CVE-2021-21132P2CRITICALCVSS 9.6fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21132 [CRITICAL] CVE-2021-21132: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 ...
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.
debian