cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 56 of 107
CVE-2024-0813P3HIGHCVSS 8.8fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-0813 [HIGH] CVE-2024-0813: chromium - Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed a... Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.
debian
CVE-2025-10201P3HIGHCVSS 8.8fixed in chromium 140.0.7339.127-1~deb12u1 (bookworm)2025
CVE-2025-10201 [HIGH] CVE-2025-10201: chromium - Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeO... Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 140.0.7339.127-1~deb12u1) bullseye: open forky: resolved (fixed in 140.0.7339.127-1) sid: resolved (fixed in
debian
CVE-2019-5755P3HIGHCVSS 8.1fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5755 [HIGH] CVE-2019-5755: chromium - Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81... Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-1) trixie: resolved (fi
debian
CVE-2026-3539P3HIGHCVSS 8.8fixed in chromium 145.0.7632.159-1~deb12u1 (bookworm)2026
CVE-2026-3539 [HIGH] CVE-2026-3539: chromium - Object lifecycle issue in DevTools in Google Chrome prior to 145.0.7632.159 allo... Object lifecycle issue in DevTools in Google Chrome prior to 145.0.7632.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 145.0.7632.159-1~deb12u1) bullseye: open forky: resolved (fixed in 145.
debian
CVE-2021-21172P3HIGHCVSS 8.1fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21172 [HIGH] CVE-2021-21172: chromium - Insufficient policy enforcement in File System API in Google Chrome on Windows p... Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 89.0.4389.82-1) bullseye: resolved (fixed in 89.0.4389.82-1) forky: resolved (fixed in 89.0.4389.82-1) sid: resolved (fixed in 89.0.4389.82
debian
CVE-2025-0611P3HIGHCVSS 8.2fixed in chromium 132.0.6834.110-1~deb12u1 (bookworm)2025
CVE-2025-0611 [HIGH] CVE-2025-0611: chromium - Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remot... Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 132.0.6834.110-1~deb12u1) bullseye: open forky: resolved (fixed in 132.0.6834.110-1) sid: resolved (fixed in 132.0.6834.110-1) trixie: re
debian
CVE-2025-11209P3HIGHCVSS 8.2fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11209 [HIGH] CVE-2025-11209: chromium - Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141... Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1) bullseye: open forky: resolved (fixed in 141.0.7390.54-1) sid: resolved (f
debian
CVE-2025-1915P3HIGHCVSS 8.1fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1915 [HIGH] CVE-2025-1915: chromium - Improper Limitation of a Pathname to a Restricted Directory in DevTools in Googl... Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1) b
debian
CVE-2026-5907P3HIGHCVSS 8.1fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5907 [HIGH] CVE-2026-5907: chromium - Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 al... Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2020-6469P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6469 [CRITICAL] CVE-2020-6469: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 83.... Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 83.0.4103.83-1) bullseye: resolved (fixed in 83.0.4103.83-1) forky: resolved (fixed in
debian
CVE-2026-2319P3HIGHCVSS 7.5fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2319 [HIGH] CVE-2026-2319: chromium - Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attack... Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures and install a malicious extension to potentially exploit object corruption via a malicious file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1) bullseye: open forky: resolved
debian
CVE-2022-1312P3CRITICALCVSS 9.6fixed in chromium 100.0.4896.88-1 (bookworm)2022
CVE-2022-1312 [CRITICAL] CVE-2022-1312: chromium - Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an att... Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 100.0.4896.88-1) bullseye: resolved (fixed in 100.0.4896.88-1~deb11u1) forky: resolved (fixed in 100.0.4896.88-
debian
CVE-2020-6381P3HIGHCVSS 8.8fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6381 [HIGH] CVE-2020-6381: chromium - Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to... Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106
debian
CVE-2020-6455P3HIGHCVSS 8.8fixed in chromium 81.0.4044.92-1 (bookworm)2020
CVE-2020-6455 [HIGH] CVE-2020-6455: chromium - Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a re... Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 81.0.4044.92-1) bullseye: resolved (fixed in 81.0.4044.92-1) forky: resolved (fixed in 81.0.4044.92-1) sid: resolved (fixed in 81.0.4044.92-1) trixie: resolved (fixed in
debian
CVE-2019-5772P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5772 [HIGH] CVE-2019-5772: chromium - Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome... Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.362
debian
CVE-2019-5769P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5769 [HIGH] CVE-2019-5769: chromium - Incorrect handling of invalid end character position when front rendering in Bli... Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolve
debian
CVE-2018-17481P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-17481 [HIGH] CVE-2018-17481: chromium - Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.357... Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 71.0.3578.80-1) trixie:
debian
CVE-2019-5763P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5763 [HIGH] CVE-2019-5763: chromium - Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 a... Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-1) trixie: resolve
debian
CVE-2018-18336P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18336 [HIGH] CVE-2018-18336: chromium - Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allo... Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 71.0.3578.80-1) trixie: resolved
debian
CVE-2020-6530P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6530 [HIGH] CVE-2020-6530: chromium - Out of bounds memory access in developer tools in Google Chrome prior to 84.0.41... Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.
debian
Debian Chromium vulnerabilities | cvebase