Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 64 of 107
CVE-2024-11114P3HIGHCVSS 8.3fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11114 [HIGH] CVE-2024-11114: chromium - Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0...
Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 1
debian
CVE-2024-10229P3HIGHCVSS 8.1fixed in chromium 130.0.6723.69-1~deb12u1 (bookworm)2024
CVE-2024-10229 [HIGH] CVE-2024-10229: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723....
Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 130.0.6723.69-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.69-1)
sid: resolved (fixed in 130.0.6723.69-1)
debian
CVE-2026-5913P3HIGHCVSS 8.1fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5913 [HIGH] CVE-2026-5913: chromium - Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a re...
Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2021-21123P3MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21123 [MEDIUM] CVE-2021-21123: chromium - Insufficient data validation in File System API in Google Chrome prior to 88.0.4...
Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.1)
debian
CVE-2019-19926P3HIGHCVSS 7.5fixed in chromium 80.0.3987.106-1 (bookworm)2019
CVE-2019-19926 [HIGH] CVE-2019-19926: chromium - multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsin...
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.1
debian
CVE-2019-19925P3HIGHCVSS 7.5fixed in chromium 80.0.3987.106-1 (bookworm)2019
CVE-2019-19925 [HIGH] CVE-2019-19925: chromium - zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname ...
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: resolved (fixed in 80.0.3987.106-1)
debian
CVE-2019-5759P3CRITICALCVSS 9.6fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5759 [CRITICAL] CVE-2019-5759: chromium - Incorrect lifetime handling in HTML select elements in Google Chrome on Android ...
Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixe
debian
CVE-2024-0804P3HIGHCVSS 7.5fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-0804 [HIGH] CVE-2024-0804: chromium - Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121...
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 121.0.6167.85-1)
sid: resolved (fixed in 121.0.6167.85-1
debian
CVE-2026-5277P3HIGHCVSS 7.5fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5277 [HIGH] CVE-2026-5277: chromium - Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 al...
Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177
debian
CVE-2025-12726P3HIGHCVSS 7.5fixed in chromium 142.0.7444.134-1~deb12u1 (bookworm)2025
CVE-2025-12726 [HIGH] CVE-2025-12726: chromium - Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0...
Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.134-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.744
debian
CVE-2019-5820P3HIGHCVSS 8.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5820 [HIGH] CVE-2019-5820: chromium - Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a rem...
Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74.0.3729.108-1)
trixie: resolved (fixed
debian
CVE-2019-5821P3HIGHCVSS 8.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5821 [HIGH] CVE-2019-5821: chromium - Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a rem...
Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74.0.3729.108-1)
trixie: resolved (fixed
debian
CVE-2018-18359P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18359 [HIGH] CVE-2018-18359: chromium - Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.357...
Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie
debian
CVE-2020-6458P3HIGHCVSS 8.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6458 [HIGH] CVE-2020-6458: chromium - Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 a...
Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolved
debian
CVE-2019-5806P3HIGHCVSS 8.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5806 [HIGH] CVE-2019-5806: chromium - Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 all...
Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74.0.3729.108-1)
trixie: resol
debian
CVE-2019-5811P3HIGHCVSS 8.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5811 [HIGH] CVE-2019-5811: chromium - Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729....
Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74.0.3729.108-1)
trixie: resolved
debian
CVE-2019-13721P3HIGHCVSS 8.8fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13721 [HIGH] CVE-2019-13721: chromium - Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote...
Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 7
debian
CVE-2019-5783P3HIGHCVSS 8.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5783 [HIGH] CVE-2019-5783: chromium - Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72...
Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.0.3626.81
debian
CVE-2020-6459P3HIGHCVSS 8.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6459 [HIGH] CVE-2020-6459: chromium - Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a rem...
Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolved (fixed in
debian
CVE-2021-30586P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30586 [HIGH] CVE-2021-30586: chromium - Use after free in dialog box handling in Windows in Google Chrome prior to 92.0....
Use after free in dialog box handling in Windows in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.8
debian