Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 68 of 107
CVE-2021-30593P3HIGHCVSS 8.1fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30593 [HIGH] CVE-2021-30593: chromium - Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed ...
Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolv
debian
CVE-2021-21198P3HIGHCVSS 7.4fixed in chromium 89.0.4389.114-1 (bookworm)2021
CVE-2021-21198 [HIGH] CVE-2021-21198: chromium - Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remo...
Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.114-1)
bullseye: resolved (fixed in 89.0.4389.114-1)
forky: resolved (fixed in 89.0.4389.114-1)
sid: resolved (fixed
debian
CVE-2022-1485P3HIGHCVSS 7.5fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1485 [HIGH] CVE-2022-1485: chromium - Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowe...
Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
trixie:
debian
CVE-2020-16021P3HIGHCVSS 7.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16021 [HIGH] CVE-2020-16021: chromium - Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed ...
Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to perform OS-level privilege escalation via a malicious file.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (
debian
CVE-2021-30536P3HIGHCVSS 8.1fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30536 [HIGH] CVE-2021-30536: chromium - Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote...
Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in
debian
CVE-2020-6555P3HIGHCVSS 7.6fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6555 [HIGH] CVE-2020-6555: chromium - Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a re...
Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.8
debian
CVE-2019-5815P3HIGHCVSS 7.5fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5815 [HIGH] CVE-2019-5815: chromium - Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could...
Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74.0.3729.108-1)
trixie: resolved (fixe
debian
CVE-2021-30577P3HIGHCVSS 7.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30577 [HIGH] CVE-2021-30577: chromium - Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515...
Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation via a crafted file.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resol
debian
CVE-2023-2939P3HIGHCVSS 7.8fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2939 [HIGH] CVE-2023-2939: chromium - Insufficient data validation in Installer in Google Chrome on Windows prior to 1...
Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via crafted symbolic link. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1)
forky: resolved (fixed in 114.0.57
debian
CVE-2024-9956P3HIGHCVSS 7.8fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9956 [HIGH] CVE-2024-9956: chromium - Inappropriate implementation in WebAuthentication in Google Chrome on Android pr...
Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.58-1)
sid: resolved (fixed in
debian
CVE-2022-1487P3HIGHCVSS 7.5fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1487 [HIGH] CVE-2022-1487: chromium - Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote...
Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via running a Wayland test.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
trixie: resolve
debian
CVE-2024-7977P3HIGHCVSS 7.8fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7977 [HIGH] CVE-2024-7977: chromium - Insufficient data validation in Installer in Google Chrome on Windows prior to 1...
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.
debian
CVE-2024-7980P3HIGHCVSS 7.8fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7980 [HIGH] CVE-2024-7980: chromium - Insufficient data validation in Installer in Google Chrome on Windows prior to 1...
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.
debian
CVE-2024-7979P3HIGHCVSS 7.8fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7979 [HIGH] CVE-2024-7979: chromium - Insufficient data validation in Installer in Google Chrome on Windows prior to 1...
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.
debian
CVE-2018-20072P3HIGHCVSS 7.8fixed in chromium 73.0.3683.75-1 (bookworm)2018
CVE-2018-20072 [HIGH] CVE-2018-20072: chromium - Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allow...
Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 73.0.3683.75-1)
bullseye: resolved (fixed in 73.0.3683.75-1)
forky: resolved (fixed in 73.0.3683.75-1)
sid: resolved (fixed in
debian
CVE-2022-1145P3HIGHCVSS 7.5fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1145 [HIGH] CVE-2022-1145: chromium - Use after free in Extensions in Google Chrome prior to 100.0.4896.60 allowed an ...
Use after free in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interaction and profile destruction.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fi
debian
CVE-2026-5273P3MEDIUMCVSS 6.3fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5273 [MEDIUM] CVE-2026-5273: chromium - Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote ...
Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177-1)
sid: resolved (fixed in 146.0.7680.177-1)
trixie
debian
CVE-2021-21130P3MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21130 [MEDIUM] CVE-2021-21130: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 88....
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.
debian
CVE-2021-21129P3MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21129 [MEDIUM] CVE-2021-21129: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 88....
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.
debian
CVE-2021-21141P3MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21141 [MEDIUM] CVE-2021-21141: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 88....
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.1)
debian