cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 72 of 107
CVE-2022-3309P4MEDIUMCVSS 6.5fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3309 [MEDIUM] CVE-2022-3309: chromium - Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 ... Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1
debian
CVE-2024-5839P4MEDIUMCVSS 6.5fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5839 [MEDIUM] CVE-2024-5839: chromium - Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0... Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 12
debian
CVE-2024-5843P4MEDIUMCVSS 6.5fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5843 [MEDIUM] CVE-2024-5843: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.5... Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixie: r
debian
CVE-2025-5065P4MEDIUMCVSS 6.5fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5065 [MEDIUM] CVE-2025-5065: chromium - Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 1... Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1) bullseye: open forky: resolved (fixed in 137.0.7151.55-1) sid: resolved (fixed in 137.0.7151.55-
debian
CVE-2021-4323P4MEDIUMCVSS 6.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-4323 [MEDIUM] CVE-2021-4323: chromium - Insufficient validation of untrusted input in Extensions in Google Chrome prior ... Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to access local files via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 90.0.4430.72-1) bullseye: resolved (fixed in 90.0.4430.72-1) for
debian
CVE-2026-5876P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5876 [MEDIUM] CVE-2026-5876: chromium - Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7... Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5885P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5885 [MEDIUM] CVE-2026-5885: chromium - Insufficient validation of untrusted input in WebML in Google Chrome on Windows ... Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-2318P4MEDIUMCVSS 6.5fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2318 [MEDIUM] CVE-2026-2318: chromium - Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0... Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1) bullseye: open forky: resolved (fixed in 145.
debian
CVE-2026-1504P4MEDIUMCVSS 6.5fixed in chromium 144.0.7559.109-1~deb12u1 (bookworm)2026
CVE-2026-1504 [MEDIUM] CVE-2026-1504: chromium - Inappropriate implementation in Background Fetch API in Google Chrome prior to 1... Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 144.0.7559.109-1~deb12u1) bullseye: open forky: resolved (fixed in 144.0.7559.109-1) sid: resolved (fixed in 144.0.7559
debian
CVE-2026-5881P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5881 [MEDIUM] CVE-2026-5881: chromium - Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allo... Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-2320P4MEDIUMCVSS 6.5fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2320 [MEDIUM] CVE-2026-2320: chromium - Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.... Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632
debian
CVE-2023-5473P4MEDIUMCVSS 6.3fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5473 [MEDIUM] CVE-2023-5473: chromium - Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote ... Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1) bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1) forky: resolved (f
debian
CVE-2026-3937P4MEDIUMCVSS 6.5fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3937 [MEDIUM] CVE-2026-3937: chromium - Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.76... Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.71-1) sid: resolved (fixed in 146.0.7680.71-1) trixie:
debian
CVE-2026-5905P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5905 [MEDIUM] CVE-2026-5905: chromium - Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.... Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2025-0444P4MEDIUMCVSS 6.3fixed in chromium 133.0.6943.53-1~deb12u1 (bookworm)2025
CVE-2025-0444 [MEDIUM] CVE-2025-0444: chromium - Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote ... Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 133.0.6943.53-1~deb12u1) bullseye: open forky: resolved (fixed in 133.0.6943.53-1) sid: resolved (fixed in 133.0.6943.53-1) trixie: resol
debian
CVE-2025-0451P4MEDIUMCVSS 6.3fixed in chromium 133.0.6943.53-1~deb12u1 (bookworm)2025
CVE-2025-0451 [MEDIUM] CVE-2025-0451: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6... Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 133.0.6943.53-1~deb12u1) bullseye: open forky: resolved (fixed in
debian
CVE-2025-4051P4MEDIUMCVSS 6.3fixed in chromium 136.0.7103.59-2~deb12u2 (bookworm)2025
CVE-2025-4051 [MEDIUM] CVE-2025-4051: chromium - Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59... Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 136.0.7103.59-2~deb12u2) bullseye: open forky: resolved (fixed
debian
CVE-2025-11216P4MEDIUMCVSS 6.3fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11216 [MEDIUM] CVE-2025-11216: chromium - Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7... Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7390.54 allowed a remote attacker to perform domain spoofing via a crafted video file. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1) bullseye: open forky: resolved (fixed in 141.0.7390.54-1) sid: resolved (fixed in 141.0.7390.54-1)
debian
CVE-2025-11213P4MEDIUMCVSS 6.3fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11213 [MEDIUM] CVE-2025-11213: chromium - Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141... Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1) bullseye: open forky: resolved (fixed
debian
CVE-2025-11208P4MEDIUMCVSS 6.3fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11208 [MEDIUM] CVE-2025-11208: chromium - Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 al... Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1) bullseye: open forky: resolved (fixed in 141.0.7390.54
debian
Debian Chromium vulnerabilities | cvebase