Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 66 of 107
CVE-2021-21143P3HIGHCVSS 8.8fixed in chromium 88.0.4324.146-1 (bookworm)2021
CVE-2021-21143 [HIGH] CVE-2021-21143: chromium - Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allow...
Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 88.0.4324.146-1)
bullseye: resolved (fixed in 88.0.4324.146-1)
forky: resolved (fixed in 88.0.4324.146-1)
debian
CVE-2019-5841P3HIGHCVSS 8.8fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5841 [HIGH] CVE-2019-5841: chromium - Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80...
Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 75.0.3770.80-1)
bullseye: resolved (fixed in 75.0.3770.80-1)
forky: resolved (fixed in 75.0.3770.80-1)
sid: resolved (fixed in 75.0.3770.80-1)
trixie: resol
debian
CVE-2019-5856P3HIGHCVSS 8.8fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5856 [HIGH] CVE-2019-5856: chromium - Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.8...
Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixed in 7
debian
CVE-2019-13696P3HIGHCVSS 8.8fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13696 [HIGH] CVE-2019-13696: chromium - Use after free in JavaScript in Google Chrome prior to 77.0.3865.120 allowed a r...
Use after free in JavaScript in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed
debian
CVE-2022-0604P3HIGHCVSS 8.8fixed in chromium 98.0.4758.102-1 (bookworm)2022
CVE-2022-0604 [HIGH] CVE-2022-0604: chromium - Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allow...
Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.102-1)
bullseye: resolved (fixed in 98.0.4758.102-1~deb11u1)
for
debian
CVE-2022-1870P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1870 [HIGH] CVE-2022-1870: chromium - Use after free in App Service in Google Chrome prior to 102.0.5005.61 allowed an...
Use after free in App Service in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolved (fixed in 102.0.5005.61-1
debian
CVE-2022-1856P3HIGHCVSS 8.8fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1856 [HIGH] CVE-2022-1856: chromium - Use after free in User Education in Google Chrome prior to 102.0.5005.61 allowed...
Use after free in User Education in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension or specific user interaction.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: re
debian
CVE-2020-6575P3HIGHCVSS 8.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6575 [HIGH] CVE-2020-6575: chromium - Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker w...
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280
debian
CVE-2021-21205P3HIGHCVSS 8.1fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21205 [HIGH] CVE-2021-21205: chromium - Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 9...
Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1)
trixi
debian
CVE-2023-4431P3HIGHCVSS 8.1fixed in chromium 116.0.5845.110-1~deb12u1 (bookworm)2023
CVE-2023-4431 [HIGH] CVE-2023-4431: chromium - Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 al...
Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 116.0.5845.110-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.110-1~deb11u1)
forky: resolved (fixed in 116.0.5845.110
debian
CVE-2022-1130P3HIGHCVSS 8.1fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1130 [HIGH] CVE-2022-1130: chromium - Insufficient validation of trust input in WebOTP in Google Chrome on Android pri...
Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to send arbitrary intents from any app via a malicious app.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.0.4896.60-1)
sid: resolved (fixed in 100
debian
CVE-2026-5282P3HIGHCVSS 8.1fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5282 [HIGH] CVE-2026-5282: chromium - Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed...
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177-1)
sid: resolved (fixed in 146.0.7680.177-1)
t
debian
CVE-2024-1676P3MEDIUMCVSS 5.4fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-1676 [MEDIUM] CVE-2024-1676: chromium - Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261....
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1)
bullseye: open
forky: resolved (fixed in 122.0.6261.57-1)
sid: resolved (fixed in 122.0.6261.57-1)
trixie: reso
debian
CVE-2019-19880P3HIGHCVSS 7.5fixed in chromium 80.0.3987.106-1 (bookworm)2019
CVE-2019-19880 [HIGH] CVE-2019-19880: chromium - exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an i...
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed i
debian
CVE-2019-19923P3HIGHCVSS 7.5fixed in chromium 80.0.3987.106-1 (bookworm)2019
CVE-2019-19923 [HIGH] CVE-2019-19923: chromium - flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT D...
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid
debian
CVE-2024-9960P3HIGHCVSS 7.5fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9960 [HIGH] CVE-2024-9960: chromium - Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote ...
Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.58-1)
sid: resolved (fixed in 130.0.6723.58-1)
trixie: resol
debian
CVE-2025-0612P3HIGHCVSS 7.5fixed in chromium 132.0.6834.110-1~deb12u1 (bookworm)2025
CVE-2025-0612 [HIGH] CVE-2025-0612: chromium - Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.110 allow...
Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 132.0.6834.110-1~deb12u1)
bullseye: open
forky: resolved (fixed in 132.0.6834.110-1)
sid: resolved (fixed in 132.0.6834.110-1)
debian
CVE-2021-21126P3MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21126 [MEDIUM] CVE-2021-21126: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.432...
Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.1)
trix
debian
CVE-2024-7017P3HIGHCVSS 7.5fixed in chromium 126.0.6478.182-1~deb12u1 (bookworm)2024
CVE-2024-7017 [HIGH] CVE-2024-7017: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.18...
Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.182-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.182-1)
sid: resolved (fixed in 126.0.6478
debian
CVE-2020-6514P3MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6514 [MEDIUM] CVE-2020-6514: chromium - Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 al...
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixe
debian