Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 75 of 107
CVE-2023-5479P4MEDIUMCVSS 6.5fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5479 [MEDIUM] CVE-2023-5479: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5...
Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.5993.70-1~d
debian
CVE-2022-2618P4MEDIUMCVSS 6.5fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2618 [MEDIUM] CVE-2022-2618: chromium - Insufficient validation of untrusted input in Internals in Google Chrome prior t...
Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a malicious file .
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky: resolved (fixed in 104.0.5112.79-1)
sid: resolved (fixed in 104.0.5112
debian
CVE-2023-4367P4MEDIUMCVSS 6.5fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4367 [MEDIUM] CVE-2023-4367: chromium - Insufficient policy enforcement in Extensions API in Google Chrome prior to 116....
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-
debian
CVE-2022-3311P4MEDIUMCVSS 6.5fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3311 [MEDIUM] CVE-2022-3311: chromium - Use after free in import in Google Chrome prior to 106.0.5249.62 allowed a remot...
Use after free in import in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
forky: resolved (fixed in
debian
CVE-2022-4911P4MEDIUMCVSS 6.5fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-4911 [MEDIUM] CVE-2022-4911: chromium - Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62...
Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
forky: resolved (fixed in 106.0.5249.61-1)
sid: resolv
debian
CVE-2022-2861P4MEDIUMCVSS 6.5fixed in chromium 104.0.5112.101-1 (bookworm)2022
CVE-2022-2861 [MEDIUM] CVE-2022-2861: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5...
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.101-1)
bullseye: resolved (fixed in 104.0.5112.101-1~deb11u1)
forky: resolved (fixed in
debian
CVE-2023-0139P4MEDIUMCVSS 6.5fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0139 [MEDIUM] CVE-2023-0139: chromium - Insufficient validation of untrusted input in Downloads in Google Chrome on Wind...
Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 109.0.5414.74-1)
bullseye: resolved (fixed in 109.0.5414.74-2~deb11u1)
forky: resolved (fixed in 109.
debian
CVE-2023-2311P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-2311 [MEDIUM] CVE-2023-2311: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 112...
Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.49-1
debian
CVE-2022-1868P4MEDIUMCVSS 6.5fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1868 [MEDIUM] CVE-2022-1868: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 102.0.5...
Inappropriate implementation in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolved (fixed in 102.0.50
debian
CVE-2022-4925P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-4925 [MEDIUM] CVE-2022-4925: chromium - Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97....
Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via malicious network traffic. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
debian
CVE-2024-5840P4MEDIUMCVSS 6.5fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5840 [MEDIUM] CVE-2024-5840: chromium - Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote a...
Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.56-1)
sid: resolved (fixed in 126.0.6478.56-1)
trixie: reso
debian
CVE-2025-5066P4MEDIUMCVSS 6.5fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5066 [MEDIUM] CVE-2025-5066: chromium - Inappropriate implementation in Messages in Google Chrome on Android prior to 13...
Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1)
bullseye: open
forky: resolved (fixed in 1
debian
CVE-2025-0442P4MEDIUMCVSS 6.5fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0442 [MEDIUM] CVE-2025-0442: chromium - Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83...
Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1)
bullseye: open
forky: resolved (fixed in 132.0.6834.8
debian
CVE-2022-4955P4MEDIUMCVSS 6.5fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4955 [MEDIUM] CVE-2022-4955: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71...
Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
fo
debian
CVE-2026-5888P4MEDIUMCVSS 6.5fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5888 [MEDIUM] CVE-2026-5888: chromium - Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a...
Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2025-8881P4MEDIUMCVSS 6.5fixed in chromium 139.0.7258.127-1~deb12u1 (bookworm)2025
CVE-2025-8881 [MEDIUM] CVE-2025-8881: chromium - Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258...
Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 139.0.7258.127-1~deb12u1)
bullseye: open
forky: resolved (fixed in 139.
debian
CVE-2026-2316P4MEDIUMCVSS 6.5fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2316 [MEDIUM] CVE-2026-2316: chromium - Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.4...
Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.45-1)
sid: resolved (fixed in 145.0.7632.45-1)
trixie:
debian
CVE-2026-5283P4MEDIUMCVSS 6.5fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5283 [MEDIUM] CVE-2026-5283: chromium - Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 a...
Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177-1)
sid: resolved (fixed in 146.0.7680.177-1)
trixie:
debian
CVE-2026-2317P4MEDIUMCVSS 6.5fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2317 [MEDIUM] CVE-2026-2317: chromium - Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.4...
Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.45-1)
sid: resolved (fixed in 145.0.7632.45-1)
trixi
debian
CVE-2026-5291P4MEDIUMCVSS 6.5fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5291 [MEDIUM] CVE-2026-5291: chromium - Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 a...
Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177-1)
sid: reso
debian