Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 69 of 107
CVE-2020-6510P3HIGHCVSS 7.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6510 [HIGH] CVE-2020-6510: chromium - Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 ...
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie
debian
CVE-2021-37969P3HIGHCVSS 7.8fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37969 [HIGH] CVE-2021-37969: chromium - Inappropriate implementation in Google Updater in Google Chrome on Windows prior...
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.
debian
CVE-2021-37980P3HIGHCVSS 7.4fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37980 [HIGH] CVE-2021-37980: chromium - Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 a...
Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: res
debian
CVE-2024-7018P3HIGHCVSS 7.8fixed in chromium 124.0.6367.78-1~deb12u1 (bookworm)2024
CVE-2024-7018 [HIGH] CVE-2024-7018: chromium - Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a re...
Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 124.0.6367.78-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.78-1)
sid: resolved (fixed in 124.0.6367.78-1)
trixie: r
debian
CVE-2019-13768P3HIGHCVSS 7.4fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-13768 [HIGH] CVE-2019-13768: chromium - Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remot...
Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chrome security severity: High)
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.0.3626
debian
CVE-2022-3308P3HIGHCVSS 7.4fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3308 [HIGH] CVE-2022-3308: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 106...
Insufficient policy enforcement in developer tools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
forky: resolved (fixed in 106.0.5249.
debian
CVE-2025-11207P3MEDIUMCVSS 6.5fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11207 [MEDIUM] CVE-2025-11207: chromium - Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390...
Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1)
bullseye: open
forky: resolved (fixed in 141.0.7390.54-1)
sid: resolved (fixed in 141.0.7390.5
debian
CVE-2019-5849P3HIGHCVSS 8.1fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5849 [HIGH] CVE-2019-5849: chromium - Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remo...
Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixed in 76.0.3809.87-1)
tri
debian
CVE-2021-21134P3MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21134 [MEDIUM] CVE-2021-21134: chromium - Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96...
Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.1)
trixie: resolved (f
debian
CVE-2019-5780P3HIGHCVSS 7.8fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5780 [HIGH] CVE-2019-5780: chromium - Insufficient restrictions on what can be done with Apple Events in Google Chrome...
Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.0.3626.81-1)
trixie:
debian
CVE-2020-15980P3HIGHCVSS 7.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15980 [HIGH] CVE-2020-15980: chromium - Insufficient policy enforcement in Intents in Google Chrome on Android prior to ...
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass navigation restrictions via crafted Intents.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
t
debian
CVE-2021-21117P3HIGHCVSS 7.8fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21117 [HIGH] CVE-2021-21117: chromium - Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.432...
Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalation via a crafted file.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.1)
tri
debian
CVE-2021-4098P3HIGHCVSS 7.4fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-4098 [HIGH] CVE-2021-4098: chromium - Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 all...
Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
s
debian
CVE-2026-5893P3MEDIUMCVSS 6.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5893 [MEDIUM] CVE-2026-5893: chromium - Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to ...
Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2021-30511P4HIGHCVSS 8.1fixed in chromium 90.0.4430.212-1 (bookworm)2021
CVE-2021-30511 [HIGH] CVE-2021-30511: chromium - Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed...
Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.212-1)
bullseye: resolved (fixed in 90.0.4430.212-1)
forky: resolved (fixed in 90.0.4430.212-1)
sid: re
debian
CVE-2021-21139P4MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21139 [MEDIUM] CVE-2021-21139: chromium - Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.43...
Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.1)
t
debian
CVE-2019-13706P4HIGHCVSS 7.8fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13706 [HIGH] CVE-2019-13706: chromium - Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 all...
Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved
debian
CVE-2019-5819P4HIGHCVSS 7.8fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5819 [HIGH] CVE-2019-5819: chromium - Insufficient data validation in developer tools in Google Chrome on OS X prior t...
Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74.0.372
debian
CVE-2021-21133P3MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21133 [MEDIUM] CVE-2021-21133: chromium - Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324...
Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolve
debian
CVE-2019-13673P4HIGHCVSS 7.4fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13673 [HIGH] CVE-2019-13673: chromium - Insufficient data validation in developer tools in Google Chrome prior to 77.0.3...
Insufficient data validation in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (
debian