cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 6 of 107
CVE-2023-2725P2HIGHCVSS 8.8fixed in chromium 113.0.5672.126-1 (bookworm)2023
CVE-2023-2725 [HIGH] CVE-2023-2725: chromium - Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an... Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 113.0.5672.126-1) bullseye: resolved (fixed in 113.0.5672.126-1~deb11u1) forky: reso
debian
CVE-2023-4362P2HIGHCVSS 8.8fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4362 [HIGH] CVE-2023-4362: chromium - Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowe... Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control of a WebUI process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fi
debian
CVE-2024-2625P2HIGHCVSS 8.8fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2625 [HIGH] CVE-2024-2625: chromium - Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a r... Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1) bullseye: open forky: resolved (fixed in 123.0.6312.58-1) sid: resolved (fixed in 123.0.6312.58-1) trixie:
debian
CVE-2020-6549P2HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6549 [HIGH] CVE-2020-6549: chromium - Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote... Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixe
debian
CVE-2025-5959P2HIGHCVSS 8.8fixed in chromium 137.0.7151.103-1~deb12u1 (bookworm)2025
CVE-2025-5959 [HIGH] CVE-2025-5959: chromium - Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 137.0.7151.103-1~deb12u1) bullseye: open forky: resolved (fixed in 137.0.7151.103-1) sid: resolved (fixed in 137.0.7151.103-1) trixie: r
debian
CVE-2020-6541P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6541 [HIGH] CVE-2020-6541: chromium - Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remot... Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fix
debian
CVE-2021-30560P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30560 [HIGH] CVE-2021-30560: chromium - Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a r... Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed
debian
CVE-2025-12428P2HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12428 [HIGH] CVE-2025-12428: chromium - Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) trixie: resolved (fixe
debian
CVE-2026-2315P2HIGHCVSS 8.8fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2315 [HIGH] CVE-2026-2315: chromium - Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 a... Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632.45-1) sid: resolved (fixed in 145.
debian
CVE-2022-2480P3HIGHCVSS 8.8fixed in chromium 103.0.5060.134-1 (bookworm)2022
CVE-2022-2480 [HIGH] CVE-2022-2480: chromium - Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 al... Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 103.0.5060.134-1) bullseye: resolved (fixed in 103.0.5060.134-1~deb11u1) forky: resolved (fixed in 103.0.5060.134-1) sid: resolved (fixed in 103.0.5060.134-1)
debian
CVE-2021-21118P3HIGHCVSS 8.8fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21118 [HIGH] CVE-2021-21118: chromium - Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowe... Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.96-0.1) bullseye: resolved (fixed in 88.0.4324.96-0.1) forky: resolved (fixed in 88.0.4324.96-0.1) sid: resolved (fixed in 88.0.4324.96-0.1
debian
CVE-2022-1232P3HIGHCVSS 8.8fixed in chromium 100.0.4896.75-1 (bookworm)2022
CVE-2022-1232 [HIGH] CVE-2022-1232: chromium - Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote at... Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 100.0.4896.75-1) bullseye: resolved (fixed in 100.0.4896.75-1~deb11u1) forky: resolved (fixed in 100.0.4896.75-1) sid: resolved (fixed in 100.0.4896.75-1) trixie: resolved (fix
debian
CVE-2023-2723P3HIGHCVSS 8.8fixed in chromium 113.0.5672.126-1 (bookworm)2023
CVE-2023-2723 [HIGH] CVE-2023-2723: chromium - Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a re... Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 113.0.5672.126-1) bullseye: resolved (fixed in 113.0.5672.126-1~deb11u1) forky: resolved (fix
debian
CVE-2024-3833P3HIGHCVSS 8.8fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3833 [HIGH] CVE-2024-3833: chromium - Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed... Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.60-1) sid: resolved (fixed in 124.0.6367.60-1) tri
debian
CVE-2023-3215P3HIGHCVSS 8.8fixed in chromium 114.0.5735.133-1~deb12u1 (bookworm)2023
CVE-2023-3215 [HIGH] CVE-2023-3215: chromium - Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remo... Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 114.0.5735.133-1~deb12u1) bullseye: resolved (fixed in 114.0.5735.133-1~deb11u1) forky: resolved (fixed in 114.0.5735.133-1) sid: resolv
debian
CVE-2024-2173P3HIGHCVSS 8.8fixed in chromium 122.0.6261.111-1~deb12u1 (bookworm)2024
CVE-2024-2173 [HIGH] CVE-2024-2173: chromium - Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allow... Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 122.0.6261.111-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.111-1) sid: resolved (fixed in 122.0.6261.111-1)
debian
CVE-2023-3217P3HIGHCVSS 8.8fixed in chromium 114.0.5735.133-1~deb12u1 (bookworm)2023
CVE-2023-3217 [HIGH] CVE-2023-3217: chromium - Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remot... Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 114.0.5735.133-1~deb12u1) bullseye: resolved (fixed in 114.0.5735.133-1~deb11u1) forky: resolved (fixed in 114.0.5735.133-1) sid: resolve
debian
CVE-2022-4906P2HIGHCVSS 8.8fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4906 [HIGH] CVE-2022-4906: chromium - Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 al... Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) forky: resolved (fixed in 108.0.5359.71-1) sid: resolved (fi
debian
CVE-2024-2174P3HIGHCVSS 8.8fixed in chromium 122.0.6261.111-1~deb12u1 (bookworm)2024
CVE-2024-2174 [HIGH] CVE-2024-2174: chromium - Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allo... Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 122.0.6261.111-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.111-1) sid: resolved (fixed in 122.0.6261.111-1)
debian
CVE-2026-2314P3HIGHCVSS 8.8fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2314 [HIGH] CVE-2026-2314: chromium - Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a... Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632.45-1) sid: resolved (fixed in 145.0.7632.45-1) trixie:
debian
Debian Chromium vulnerabilities | cvebase