Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 72 of 107
CVE-2022-3309P4MEDIUMCVSS 6.5fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3309 [MEDIUM] CVE-2022-3309: chromium - Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 ...
Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1
debian
CVE-2024-5839P4MEDIUMCVSS 6.5fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5839 [MEDIUM] CVE-2024-5839: chromium - Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0...
Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.56-1)
sid: resolved (fixed in 12
debian
CVE-2024-5843P4MEDIUMCVSS 6.5fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5843 [MEDIUM] CVE-2024-5843: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.5...
Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.56-1)
sid: resolved (fixed in 126.0.6478.56-1)
trixie: r
debian
CVE-2025-5065P4MEDIUMCVSS 6.5fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5065 [MEDIUM] CVE-2025-5065: chromium - Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 1...
Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1)
bullseye: open
forky: resolved (fixed in 137.0.7151.55-1)
sid: resolved (fixed in 137.0.7151.55-
debian
CVE-2021-4323P4MEDIUMCVSS 6.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-4323 [MEDIUM] CVE-2021-4323: chromium - Insufficient validation of untrusted input in Extensions in Google Chrome prior ...
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to access local files via a crafted Chrome Extension. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
for
debian
CVE-2026-5876P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5876 [MEDIUM] CVE-2026-5876: chromium - Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7...
Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5885P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5885 [MEDIUM] CVE-2026-5885: chromium - Insufficient validation of untrusted input in WebML in Google Chrome on Windows ...
Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-2318P4MEDIUMCVSS 6.5fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2318 [MEDIUM] CVE-2026-2318: chromium - Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0...
Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.
debian
CVE-2026-1504P4MEDIUMCVSS 6.5fixed in chromium 144.0.7559.109-1~deb12u1 (bookworm)2026
CVE-2026-1504 [MEDIUM] CVE-2026-1504: chromium - Inappropriate implementation in Background Fetch API in Google Chrome prior to 1...
Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 144.0.7559.109-1~deb12u1)
bullseye: open
forky: resolved (fixed in 144.0.7559.109-1)
sid: resolved (fixed in 144.0.7559
debian
CVE-2026-5881P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5881 [MEDIUM] CVE-2026-5881: chromium - Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allo...
Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-2320P4MEDIUMCVSS 6.5fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2320 [MEDIUM] CVE-2026-2320: chromium - Inappropriate implementation in File input in Google Chrome prior to 145.0.7632....
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632
debian
CVE-2023-5473P4MEDIUMCVSS 6.3fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5473 [MEDIUM] CVE-2023-5473: chromium - Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote ...
Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1)
forky: resolved (f
debian
CVE-2026-3937P4MEDIUMCVSS 6.5fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3937 [MEDIUM] CVE-2026-3937: chromium - Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.76...
Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
trixie:
debian
CVE-2026-5905P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5905 [MEDIUM] CVE-2026-5905: chromium - Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0....
Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2025-0444P4MEDIUMCVSS 6.3fixed in chromium 133.0.6943.53-1~deb12u1 (bookworm)2025
CVE-2025-0444 [MEDIUM] CVE-2025-0444: chromium - Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote ...
Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 133.0.6943.53-1~deb12u1)
bullseye: open
forky: resolved (fixed in 133.0.6943.53-1)
sid: resolved (fixed in 133.0.6943.53-1)
trixie: resol
debian
CVE-2025-0451P4MEDIUMCVSS 6.3fixed in chromium 133.0.6943.53-1~deb12u1 (bookworm)2025
CVE-2025-0451 [MEDIUM] CVE-2025-0451: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6...
Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 133.0.6943.53-1~deb12u1)
bullseye: open
forky: resolved (fixed in
debian
CVE-2025-4051P4MEDIUMCVSS 6.3fixed in chromium 136.0.7103.59-2~deb12u2 (bookworm)2025
CVE-2025-4051 [MEDIUM] CVE-2025-4051: chromium - Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59...
Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 136.0.7103.59-2~deb12u2)
bullseye: open
forky: resolved (fixed
debian
CVE-2025-11216P4MEDIUMCVSS 6.3fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11216 [MEDIUM] CVE-2025-11216: chromium - Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7...
Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7390.54 allowed a remote attacker to perform domain spoofing via a crafted video file. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1)
bullseye: open
forky: resolved (fixed in 141.0.7390.54-1)
sid: resolved (fixed in 141.0.7390.54-1)
debian
CVE-2025-11213P4MEDIUMCVSS 6.3fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11213 [MEDIUM] CVE-2025-11213: chromium - Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141...
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1)
bullseye: open
forky: resolved (fixed
debian
CVE-2025-11208P4MEDIUMCVSS 6.3fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11208 [MEDIUM] CVE-2025-11208: chromium - Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 al...
Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1)
bullseye: open
forky: resolved (fixed in 141.0.7390.54
debian