cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 7 of 107
CVE-2025-0291P2HIGHCVSS 8.8fixed in chromium 131.0.6778.264-1~deb12u1 (bookworm)2025
CVE-2025-0291 [HIGH] CVE-2025-0291: chromium - Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 131.0.6778.264-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778.264-1) sid: resolved (fixed in 131.0.6778.264-1) trixie: r
debian
CVE-2024-3156P3HIGHCVSS 8.8fixed in chromium 123.0.6312.105-1~deb12u1 (bookworm)2024
CVE-2024-3156 [HIGH] CVE-2024-3156: chromium - Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allo... Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 123.0.6312.105-1~deb12u1) bullseye: open forky: resolved (fixed in 123.0.6312.105-1) sid: resolved (fixed in 123.0
debian
CVE-2026-0628P3HIGHCVSS 8.8fixed in chromium 143.0.7499.192-1~deb12u1 (bookworm)2026
CVE-2026-0628 [HIGH] CVE-2026-0628: chromium - Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7... Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 143.0.7499.192-1~deb12u1) bullseye: open forky: r
debian
CVE-2024-0223P3HIGHCVSS 8.8fixed in chromium 120.0.6099.199-1~deb12u1 (bookworm)2024
CVE-2024-0223 [HIGH] CVE-2024-0223: chromium - Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a... Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.199-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.199-1~deb11u1) forky: resolved (fixed in 120.0.6099.199-1) sid: r
debian
CVE-2026-2313P3HIGHCVSS 8.8fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2313 [HIGH] CVE-2026-2313: chromium - Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote a... Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632.45-1) sid: resolved (fixed in 145.0.7632.45-1) trixie: resolved
debian
CVE-2025-6191P3HIGHCVSS 8.8fixed in chromium 137.0.7151.119-1~deb12u1 (bookworm)2025
CVE-2025-6191 [HIGH] CVE-2025-6191: chromium - Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote... Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 137.0.7151.119-1~deb12u1) bullseye: open forky: resolved (fixed in 137.0.7151.119-1) sid: resolved (fixed in 137.0.7151.119-1)
debian
CVE-2019-13767P3HIGHCVSS 8.8fixed in chromium 79.0.3945.130-1 (bookworm)2019
CVE-2019-13767 [HIGH] CVE-2019-13767: chromium - Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a ... Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.130-1) bullseye: resolved (fixed in 79.0.3945.130-1) forky: resolved (fixed in 79.0.3945.130-1) sid: resolved (fix
debian
CVE-2024-6779P3CRITICALCVSS 9.6fixed in chromium 126.0.6478.182-1~deb12u1 (bookworm)2024
CVE-2024-6779 [CRITICAL] CVE-2024-6779: chromium - Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allow... Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 126.0.6478.182-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.182-1) sid: resolved (fixed in 126.0.6478.18
debian
CVE-2023-4068P3HIGHCVSS 8.1fixed in chromium 115.0.5790.170-1~deb12u1 (bookworm)2023
CVE-2023-4068 [HIGH] CVE-2023-4068: chromium - Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 115.0.5790.170-1~deb12u1) bullseye: resolved (fixed in 115.0.5790.170-1~deb11u1) forky: resolved (fixed in 115.0.5790.170-1) sid: resolved (fixed i
debian
CVE-2025-10891P3HIGHCVSS 8.8fixed in chromium 140.0.7339.207-1~deb12u1 (bookworm)2025
CVE-2025-10891 [HIGH] CVE-2025-10891: chromium - Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote... Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 140.0.7339.207-1~deb12u1) bullseye: open forky: resolved (fixed in 140.0.7339.207-1) sid: resolved (fixed in 140.0.7339.207-1) trixie: r
debian
CVE-2025-12036P3HIGHCVSS 8.8fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12036 [HIGH] CVE-2025-12036: chromium - Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allow... Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1) bullseye: open forky: resolved (fixed in 142.0.7444.59-1) sid: resolved (fixed in 142.0.7444.59-1) t
debian
CVE-2022-3842P3HIGHCVSS 7.5fixed in chromium 105.0.5195.125-1 (bookworm)2022
CVE-2022-3842 [HIGH] CVE-2022-3842: chromium - Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a r... Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 105.0.5195.125-1) bullseye: resolved (fixed in 105.0.5195.125-1~deb11u1) forky: resolved (fi
debian
CVE-2024-1670P3HIGHCVSS 8.8fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-1670 [HIGH] CVE-2024-1670: chromium - Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote ... Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.57-1) sid: resolved (fixed in 122.0.6261.57-1) trixie: resolve
debian
CVE-2024-4058P3HIGHCVSS 8.8fixed in chromium 124.0.6367.78-1~deb12u1 (bookworm)2024
CVE-2024-4058 [HIGH] CVE-2024-4058: chromium - Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote... Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) Scope: local bookworm: resolved (fixed in 124.0.6367.78-1~deb12u1) bullseye: open forky: resolved (fixed in 124.0.6367.78-1) sid: resolved (fixed in 124.0.6367.78-1) trixie: re
debian
CVE-2026-3062P3CRITICALCVSS 9.8fixed in chromium 145.0.7632.116-1~deb12u1 (bookworm)2026
CVE-2026-3062 [CRITICAL] CVE-2026-3062: chromium - Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632... Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 145.0.7632.116-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632.116-1) sid: resolved (fixed in 145.
debian
CVE-2025-14765P3HIGHCVSS 8.8fixed in chromium 143.0.7499.169-1~deb12u1 (bookworm)2025
CVE-2025-14765 [HIGH] CVE-2025-14765: chromium - Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remo... Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 143.0.7499.169-1~deb12u1) bullseye: open forky: resolved (fixed in 143.0.7499.169-1) sid: resolved (fixed in 143.0.7499.169-1) trixie:
debian
CVE-2025-2135P3HIGHCVSS 8.8fixed in chromium 134.0.6998.88-1~deb12u1 (bookworm)2025
CVE-2025-2135 [HIGH] CVE-2025-2135: chromium - Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 134.0.6998.88-1~deb12u1) bullseye: open forky: resolved (fixed in 134.0.6998.88-1) sid: resolved (fixed in 134.0.6998.88-1) trixie: resolved
debian
CVE-2021-30558P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30558 [HIGH] CVE-2021-30558: chromium - Insufficient policy enforcement in content security policy in Google Chrome prio... Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chrome security severity: Medium) Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 93.0.4577.
debian
CVE-2024-1675P3HIGHCVSS 8.8fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-1675 [HIGH] CVE-2024-1675: chromium - Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261... Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1) bullseye: open forky: resolved (fixed in 122.0.6261.57-1) sid: resolved (fixed in 122.0.6261.57-
debian
CVE-2025-14766P3HIGHCVSS 8.8fixed in chromium 143.0.7499.169-1~deb12u1 (bookworm)2025
CVE-2025-14766 [HIGH] CVE-2025-14766: chromium - Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allo... Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 143.0.7499.169-1~deb12u1) bullseye: open forky: resolved (fixed in 143.0.7499.169-1) sid: resolved (fixed in 143.0.7499.169-
debian
Debian Chromium vulnerabilities | cvebase