cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 75 of 107
CVE-2023-5479P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5479 [MEDIUM] CVE-2023-5479: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5... Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1) bullseye: resolved (fixed in 118.0.5993.70-1~d
debian
CVE-2022-2618P4MEDIUMCVSS 6.5fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2618 [MEDIUM] CVE-2022-2618: chromium - Insufficient validation of untrusted input in Internals in Google Chrome prior t... Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a malicious file . Scope: local bookworm: resolved (fixed in 104.0.5112.79-1) bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1) forky: resolved (fixed in 104.0.5112.79-1) sid: resolved (fixed in 104.0.5112
debian
CVE-2023-4367P4MEDIUMCVSS 6.5fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4367 [MEDIUM] CVE-2023-4367: chromium - Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.... Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.96-
debian
CVE-2022-3311P4MEDIUMCVSS 6.5fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3311 [MEDIUM] CVE-2022-3311: chromium - Use after free in import in Google Chrome prior to 106.0.5249.62 allowed a remot... Use after free in import in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in
debian
CVE-2022-4911P4MEDIUMCVSS 6.5fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-4911 [MEDIUM] CVE-2022-4911: chromium - Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62... Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 106.0.5249.61-1) bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1) forky: resolved (fixed in 106.0.5249.61-1) sid: resolv
debian
CVE-2022-2861P4MEDIUMCVSS 6.5fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2861 [MEDIUM] CVE-2022-2861: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5... Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page. Scope: local bookworm: resolved (fixed in 104.0.5112.101-1) bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1) forky: resolved (fixed in
debian
CVE-2023-0139P4MEDIUMCVSS 6.5fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0139 [MEDIUM] CVE-2023-0139: chromium - Insufficient validation of untrusted input in Downloads in Google Chrome on Wind... Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 109.0.5414.74-1) bullseye: resolved (fixed in 109.0.5414.74-2~deb11u1) forky: resolved (fixed in 109.
debian
CVE-2023-2311P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-2311 [MEDIUM] CVE-2023-2311: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 112... Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 112.0.5615.49-1) bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2) forky: resolved (fixed in 112.0.5615.49-1
debian
CVE-2022-1868P4MEDIUMCVSS 6.5fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1868 [MEDIUM] CVE-2022-1868: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 102.0.5... Inappropriate implementation in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 102.0.5005.61-1) bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1) forky: resolved (fixed in 102.0.50
debian
CVE-2022-4925P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-4925 [MEDIUM] CVE-2022-4925: chromium - Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.... Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via malicious network traffic. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1)
debian
CVE-2024-5840P4MEDIUMCVSS 6.5fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5840 [MEDIUM] CVE-2024-5840: chromium - Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote a... Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixie: reso
debian
CVE-2025-5066P4MEDIUMCVSS 6.5fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5066 [MEDIUM] CVE-2025-5066: chromium - Inappropriate implementation in Messages in Google Chrome on Android prior to 13... Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1) bullseye: open forky: resolved (fixed in 1
debian
CVE-2025-0442P4MEDIUMCVSS 6.5fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0442 [MEDIUM] CVE-2025-0442: chromium - Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83... Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1) bullseye: open forky: resolved (fixed in 132.0.6834.8
debian
CVE-2022-4955P4MEDIUMCVSS 6.5fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4955 [MEDIUM] CVE-2022-4955: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71... Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 108.0.5359.71-1) bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1) fo
debian
CVE-2026-5888P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5888 [MEDIUM] CVE-2026-5888: chromium - Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a... Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2025-8881P4MEDIUMCVSS 6.5fixed in chromium 139.0.7258.127-1~deb12u1 (bookworm)2025
CVE-2025-8881 [MEDIUM] CVE-2025-8881: chromium - Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258... Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 139.0.7258.127-1~deb12u1) bullseye: open forky: resolved (fixed in 139.
debian
CVE-2026-2316P4MEDIUMCVSS 6.5fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2316 [MEDIUM] CVE-2026-2316: chromium - Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.4... Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632.45-1) sid: resolved (fixed in 145.0.7632.45-1) trixie:
debian
CVE-2026-5283P4MEDIUMCVSS 6.5fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5283 [MEDIUM] CVE-2026-5283: chromium - Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 a... Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1) sid: resolved (fixed in 146.0.7680.177-1) trixie:
debian
CVE-2026-2317P4MEDIUMCVSS 6.5fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2317 [MEDIUM] CVE-2026-2317: chromium - Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.4... Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1) bullseye: open forky: resolved (fixed in 145.0.7632.45-1) sid: resolved (fixed in 145.0.7632.45-1) trixi
debian
CVE-2026-5291P4MEDIUMCVSS 6.5fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5291 [MEDIUM] CVE-2026-5291: chromium - Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 a... Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1) sid: reso
debian
Debian Chromium vulnerabilities | cvebase