Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 71 of 107
CVE-2025-12445P4MEDIUMCVSS 6.5fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12445 [MEDIUM] CVE-2025-12445: chromium - Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an a...
Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: r
debian
CVE-2023-3739P3MEDIUMCVSS 6.3fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3739 [MEDIUM] CVE-2023-3739: chromium - Insufficient validation of untrusted input in Chromad in Google Chrome on Chrome...
Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1)
bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1)
forky: resolved (fixed in
debian
CVE-2020-6506P4MEDIUMCVSS 6.5fixed in chromium 83.0.4103.106-1 (bookworm)2020
CVE-2020-6506 [MEDIUM] CVE-2020-6506: chromium - Insufficient policy enforcement in WebView in Google Chrome on Android prior to ...
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.106-1)
bullseye: resolved (fixed in 83.0.4103.106-1)
forky: resolved (fixed in 83.0.4103.106-1)
sid: resolved (fixed in 83.0.4103.106-1)
trixie:
debian
CVE-2019-5880P4HIGHCVSS 7.4fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-5880 [HIGH] CVE-2019-5880: chromium - Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 ...
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in
debian
CVE-2018-18351P4MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18351 [MEDIUM] CVE-2018-18351: chromium - Lack of proper validation of ancestor frames site when sending lax cookies in Na...
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: res
debian
CVE-2020-6401P4MEDIUMCVSS 6.5fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6401 [MEDIUM] CVE-2020-6401: chromium - Insufficient validation of untrusted input in Omnibox in Google Chrome prior to ...
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.
debian
CVE-2021-21210P4MEDIUMCVSS 6.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21210 [MEDIUM] CVE-2021-21210: chromium - Inappropriate implementation in Network in Google Chrome prior to 90.0.4430.72 a...
Inappropriate implementation in Network in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially access local UDP ports via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1)
trixie: reso
debian
CVE-2021-21182P4MEDIUMCVSS 6.5fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21182 [MEDIUM] CVE-2021-21182: chromium - Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.43...
Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: res
debian
CVE-2021-30531P4MEDIUMCVSS 6.5fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30531 [MEDIUM] CVE-2021-30531: chromium - Insufficient policy enforcement in Content Security Policy in Google Chrome prio...
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-
debian
CVE-2019-5835P4MEDIUMCVSS 6.5fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5835 [MEDIUM] CVE-2019-5835: chromium - Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 all...
Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 75.0.3770.80-1)
bullseye: resolved (fixed in 75.0.3770.80-1)
forky: resolved (fixed in 75.0.3770.80-1)
sid: resolved (fixed in 75.0.3770.80-1)
tri
debian
CVE-2021-21221P4MEDIUMCVSS 6.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21221 [MEDIUM] CVE-2021-21221: chromium - Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90....
Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolve
debian
CVE-2021-21208P4MEDIUMCVSS 6.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21208 [MEDIUM] CVE-2021-21208: chromium - Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0...
Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain spoofing via a crafted QR code.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1)
debian
CVE-2024-4060P4MEDIUMCVSS 6.5fixed in chromium 124.0.6367.78-1~deb12u1 (bookworm)2024
CVE-2024-4060 [MEDIUM] CVE-2024-4060: chromium - Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote ...
Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 124.0.6367.78-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.78-1)
sid: resolved (fixed in 124.0.6367.78-1)
trixie: resol
debian
CVE-2024-4948P4MEDIUMCVSS 6.5fixed in chromium 125.0.6422.60-1~deb12u1 (bookworm)2024
CVE-2024-4948 [MEDIUM] CVE-2024-4948: chromium - Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote ...
Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 125.0.6422.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 125.0.6422.60-1)
sid: resolved (fixed in 125.0.6422.60-1)
trixie: resol
debian
CVE-2024-4950P4MEDIUMCVSS 6.5fixed in chromium 125.0.6422.60-1~deb12u1 (bookworm)2024
CVE-2024-4950 [MEDIUM] CVE-2024-4950: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.6...
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 125.0.6422.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 125.0.6422.60-
debian
CVE-2022-0461P4MEDIUMCVSS 6.5fixed in chromium 98.0.4758.80-1 (bookworm)2022
CVE-2022-0461 [MEDIUM] CVE-2022-0461: chromium - Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote at...
Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass iframe sandbox via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 98.0.4758.80-1)
bullseye: resolved (fixed in 98.0.4758.80-1~deb11u1)
forky: resolved (fixed in 98.0.4758.80-1)
sid: resolved (fixed in 98.0.4758.80-1)
trixie: resolved (fixed in 98.0.4758.
debian
CVE-2024-3515P4MEDIUMCVSS 6.5fixed in chromium 123.0.6312.122-1~deb12u1 (bookworm)2024
CVE-2024-3515 [MEDIUM] CVE-2024-3515: chromium - Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote...
Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 123.0.6312.122-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.122-1)
sid: resolved (fixed in 123.0.6312.122-1)
trixie: r
debian
CVE-2024-2626P4MEDIUMCVSS 6.5fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2626 [MEDIUM] CVE-2024-2626: chromium - Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowe...
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.58-1)
sid: resolved (fixed in 123.0.6312.58-1)
debian
CVE-2020-15988P4MEDIUMCVSS 6.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15988 [MEDIUM] CVE-2020-15988: chromium - Insufficient policy enforcement in downloads in Google Chrome on Windows prior t...
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker who convinced the user to open files to execute arbitrary code via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid:
debian
CVE-2023-5475P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5475 [MEDIUM] CVE-2023-5475: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70...
Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.59
debian