Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 70 of 107
CVE-2021-21222P4MEDIUMCVSS 6.5fixed in chromium 90.0.4430.85-1 (bookworm)2021
CVE-2021-21222 [MEDIUM] CVE-2021-21222: chromium - Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remo...
Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.85-1)
bullseye: resolved (fixed in 90.0.4430.85-1)
forky: resolved (fixed in 90.0.4430.85-1)
sid: resolved (fixed in 90.0.4430.85-
debian
CVE-2025-11206P4HIGHCVSS 7.1fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11206 [HIGH] CVE-2025-11206: chromium - Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a ...
Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1)
bullseye: open
forky: resolved (fixed in 141.0.7390.54-1)
sid: resolved (fixed in 141.0.7390.54-1)
trixi
debian
CVE-2025-3070P4MEDIUMCVSS 6.5fixed in chromium 135.0.7049.52-1~deb12u1 (bookworm)2025
CVE-2025-3070 [MEDIUM] CVE-2025-3070: chromium - Insufficient validation of untrusted input in Extensions in Google Chrome prior ...
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 135.0.7049.52-1~deb12u1)
bullseye: open
forky: resolved (fixed in 135.0.7049.52-1)
sid: resolved (fixed in 1
debian
CVE-2025-12431P4MEDIUMCVSS 6.5fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12431 [MEDIUM] CVE-2025-12431: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444....
Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in
debian
CVE-2021-21137P4MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21137 [MEDIUM] CVE-2021-21137: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 ...
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.
debian
CVE-2021-30615P3MEDIUMCVSS 6.5fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30615 [MEDIUM] CVE-2021-30615: chromium - Chromium: CVE-2021-30615 Cross-origin data leak in Navigation
Chromium: CVE-2021-30615 Cross-origin data leak in Navigation
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fixed in 93.0.4577.82-1)
debian
CVE-2021-30582P4MEDIUMCVSS 6.5fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30582 [MEDIUM] CVE-2021-30582: chromium - Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.10...
Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
trixie: resolved (fix
debian
CVE-2019-5881P4HIGHCVSS 8.1fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-5881 [HIGH] CVE-2019-5881: chromium - Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed...
Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87
debian
CVE-2021-21136P3MEDIUMCVSS 6.5fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21136 [MEDIUM] CVE-2021-21136: chromium - Insufficient policy enforcement in WebView in Google Chrome on Android prior to ...
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.1)
tr
debian
CVE-2022-0301P4HIGHCVSS 7.8fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0301 [HIGH] CVE-2022-0301: chromium - Heap buffer overflow in DevTools in Google Chrome prior to 97.0.4692.99 allowed ...
Heap buffer overflow in DevTools in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1)
sid: r
debian
CVE-2020-15983P4HIGHCVSS 7.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15983 [HIGH] CVE-2020-15983: chromium - Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0...
Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
t
debian
CVE-2019-5798P4MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5798 [MEDIUM] CVE-2019-5798: chromium - Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 a...
Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 73.0.3683.75-1)
bullseye: resolved (fixed in 73.0.3683.75-1)
forky: resolved (fixed in 73.0.3683.75-1)
sid: resolved (fixed in 73.0.3683.75-1)
trixie: reso
debian
CVE-2019-13668P4HIGHCVSS 7.4fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13668 [HIGH] CVE-2019-13668: chromium - Insufficient policy enforcement in developer tools in Google Chrome prior to 77....
Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolve
debian
CVE-2020-6426P4MEDIUMCVSS 6.5fixed in chromium 80.0.3987.149-1 (bookworm)2020
CVE-2020-6426 [MEDIUM] CVE-2020-6426: chromium - Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allow...
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.149-1)
bullseye: resolved (fixed in 80.0.3987.149-1)
forky: resolved (fixed in 80.0.3987.149-1)
sid: resolved (fixed in 80.0.3987.149-1)
trixie: resol
debian
CVE-2019-13750P4MEDIUMCVSS 6.5fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13750 [MEDIUM] CVE-2019-13750: chromium - Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 al...
Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolve
debian
CVE-2023-2460P4HIGHCVSS 7.1fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2460 [HIGH] CVE-2023-2460: chromium - Insufficient validation of untrusted input in Extensions in Google Chrome prior ...
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 113.0.5672.63-1)
bullseye: resolved (fixed in 113.0.5672.63-1~deb
debian
CVE-2021-21212P4MEDIUMCVSS 6.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21212 [MEDIUM] CVE-2021-21212: chromium - Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to...
Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowed a remote attacker to potentially compromise WiFi connection security via a malicious WAP.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0
debian
CVE-2026-5903P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5903 [MEDIUM] CVE-2026-5903: chromium - Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a...
Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5919P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5919 [MEDIUM] CVE-2026-5919: chromium - Insufficient validation of untrusted input in WebSockets in Google Chrome prior ...
Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5901P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5901 [MEDIUM] CVE-2026-5901: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727...
Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Chrome Extension. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 1
debian