cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 61 of 107
CVE-2023-0134P3HIGHCVSS 8.8fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0134 [HIGH] CVE-2023-0134: chromium - Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attack... Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 109.0.5414.74-1) bullseye: resolved (fixed in 109.0.5414.74-2~deb
debian
CVE-2023-0135P3HIGHCVSS 8.8fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0135 [HIGH] CVE-2023-0135: chromium - Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attack... Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 109.0.5414.74-1) bullseye: resolved (fixed in 109.0.5414.74-2~deb
debian
CVE-2022-3655P3HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3655 [HIGH] CVE-2022-3655: chromium - Heap buffer overflow in Media Galleries in Google Chrome prior to 107.0.5304.62 ... Heap buffer overflow in Media Galleries in Google Chrome prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1) f
debian
CVE-2022-2608P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2608 [HIGH] CVE-2022-2608: chromium - Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.511... Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved
debian
CVE-2022-3449P3HIGHCVSS 8.8fixed in chromium 106.0.5249.119-1 (bookworm)2022
CVE-2022-3449 [HIGH] CVE-2022-3449: chromium - Use after free in Safe Browsing in Google Chrome prior to 106.0.5249.119 allowed... Use after free in Safe Browsing in Google Chrome prior to 106.0.5249.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 106.0.5249.119-1) bullseye: resolved (fixed in 106.0.5249.119-1~deb11u1) f
debian
CVE-2022-3657P3HIGHCVSS 8.8fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-3657 [HIGH] CVE-2022-3657: chromium - Use after free in Extensions in Google Chrome prior to 107.0.5304.62 allowed an ... Use after free in Extensions in Google Chrome prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1) forky
debian
CVE-2022-2617P3HIGHCVSS 8.8fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2617 [HIGH] CVE-2022-2617: chromium - Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed... Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions. Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved (fixed in 104.0.5112.79-
debian
CVE-2022-0114P3HIGHCVSS 8.1fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0114 [HIGH] CVE-2022-0114: chromium - Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4... Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) s
debian
CVE-2023-4761P3HIGHCVSS 8.1fixed in chromium 116.0.5845.180-1~deb12u1 (bookworm)2023
CVE-2023-4761 [HIGH] CVE-2023-4761: chromium - Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 al... Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.180-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.180-1~deb11u1) f
debian
CVE-2025-0997P3HIGHCVSS 8.1fixed in chromium 133.0.6943.98-1~deb12u1 (bookworm)2025
CVE-2025-0997 [HIGH] CVE-2025-0997: chromium - Use after free in Navigation in Google Chrome prior to 133.0.6943.98 allowed a r... Use after free in Navigation in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 133.0.6943.98-1~deb12u1) bullseye: open forky: resolved (fixed in 133.0.6943.98-1) sid: resolved (fixed in 133.0.6943.98-1) tr
debian
CVE-2026-5915P3HIGHCVSS 8.1fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5915 [HIGH] CVE-2026-5915: chromium - Insufficient validation of untrusted input in WebML in Google Chrome prior to 14... Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2024-3840P3HIGHCVSS 7.5fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3840 [HIGH] CVE-2024-3840: chromium - Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.... Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.60-1) sid: resolved (fixed in 124.0.63
debian
CVE-2026-3924P3HIGHCVSS 7.5fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3924 [HIGH] CVE-2026-3924: chromium - use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a... use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: r
debian
CVE-2025-12437P3HIGHCVSS 7.5fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12437 [HIGH] CVE-2025-12437: chromium - Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a rem... Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444
debian
CVE-2025-13721P3HIGHCVSS 7.5fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13721 [HIGH] CVE-2025-13721: chromium - Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to ... Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1) bullseye: open forky: resolved (fixed in 143.0.7499.40-1) sid: resolved (fixed in 143.0.7499.40-1) trixie: resolved (fixed
debian
CVE-2026-3932P3HIGHCVSS 7.5fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3932 [HIGH] CVE-2026-3932: chromium - Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.... Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: resolved (fixed in 146.0.76
debian
CVE-2020-6509P3CRITICALCVSS 9.6fixed in chromium 83.0.4103.116-1 (bookworm)2020
CVE-2020-6509 [CRITICAL] CVE-2020-6509: chromium - Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an ... Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 83.0.4103.116-1) bullseye: resolved (fixed in 83.0.4103.116-1) forky: resolved (fixed in 83.0.4103.116-1) si
debian
CVE-2019-5791P3HIGHCVSS 8.8fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5791 [HIGH] CVE-2019-5791: chromium - Inappropriate optimization in V8 in Google Chrome prior to 73.0.3683.75 allowed ... Inappropriate optimization in V8 in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. Scope: local bookworm: resolved (fixed in 73.0.3683.75-1) bullseye: resolved (fixed in 73.0.3683.75-1) forky: resolved (fixed in 73.0.3683.75-1) sid: resolved (fixed in 73.0.3683.75-1) trixie: resolved (fix
debian
CVE-2019-13736P3HIGHCVSS 8.8fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13736 [HIGH] CVE-2019-13736: chromium - Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remo... Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fixed in
debian
CVE-2018-18341P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18341 [HIGH] CVE-2018-18341: chromium - An integer overflow leading to a heap buffer overflow in Blink in Google Chrome ... An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 71.0.3
debian
Debian Chromium vulnerabilities | cvebase