Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 79 of 107
CVE-2023-1821P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1821 [MEDIUM] CVE-2023-1821: chromium - Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49...
Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.
debian
CVE-2023-1816P4MEDIUMCVSS 6.5fixed in chromium 112.0.5615.49-1 (bookworm)2023
CVE-2023-1816 [MEDIUM] CVE-2023-1816: chromium - Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615...
Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.49
debian
CVE-2023-4350P4MEDIUMCVSS 6.5fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4350 [MEDIUM] CVE-2023-4350: chromium - Inappropriate implementation in Fullscreen in Google Chrome on Android prior to ...
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky:
debian
CVE-2020-6569P4MEDIUMCVSS 6.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6569 [MEDIUM] CVE-2020-6569: chromium - Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remo...
Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixe
debian
CVE-2022-0120P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0120 [MEDIUM] CVE-2022-0120: chromium - Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71...
Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0
debian
CVE-2022-1500P4MEDIUMCVSS 6.5fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1500 [MEDIUM] CVE-2022-1500: chromium - Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.4...
Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
tri
debian
CVE-2022-0291P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0291 [MEDIUM] CVE-2022-0291: chromium - Inappropriate implementation in Storage in Google Chrome prior to 97.0.4692.99 a...
Inappropriate implementation in Storage in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1)
sid: resolved (fix
debian
CVE-2024-3839P4MEDIUMCVSS 6.5fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3839 [MEDIUM] CVE-2024-3839: chromium - Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a re...
Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.60-1)
sid: resolved (fixed i
debian
CVE-2022-1128P4MEDIUMCVSS 6.5fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1128 [MEDIUM] CVE-2022-1128: chromium - Inappropriate implementation in Web Share API in Google Chrome on Windows prior ...
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.0.4896.60-1)
sid: resolved
debian
CVE-2023-0700P4MEDIUMCVSS 6.5fixed in chromium 110.0.5481.77-1 (bookworm)2023
CVE-2023-0700 [MEDIUM] CVE-2023-0700: chromium - Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77...
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 110.0.5481.77-1)
bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1)
forky: resolved (fixed in
debian
CVE-2022-3313P4MEDIUMCVSS 6.5fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3313 [MEDIUM] CVE-2022-3313: chromium - Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 all...
Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
forky: resolved (fixed in 106.0.5249.61-1)
sid: resolved (fixed in 1
debian
CVE-2022-3054P4MEDIUMCVSS 6.5fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3054 [MEDIUM] CVE-2022-3054: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195...
Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: resolved (fixed in 105.0.5195.52-1)
sid: resolved (fixed in 105.0.5195.52
debian
CVE-2022-2605P4MEDIUMCVSS 6.5fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2605 [MEDIUM] CVE-2022-2605: chromium - Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a rem...
Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky: resolved (fixed in 104.0.5112.79-1)
sid: resolved (fixed in 104.0.5112.79-1)
trixie: resol
debian
CVE-2022-4187P4MEDIUMCVSS 6.5fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4187 [MEDIUM] CVE-2022-4187: chromium - Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to...
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
forky: resolved (fixed in 108.0.5359.
debian
CVE-2023-0131P4MEDIUMCVSS 6.5fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0131 [MEDIUM] CVE-2023-0131: chromium - Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109....
Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 109.0.5414.74-1)
bullseye: resolved (fixed in 109.0.5414.74-2~deb11u1)
forky: resolved (fixed in 109.0.5414.74
debian
CVE-2022-4913P4MEDIUMCVSS 6.5fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-4913 [MEDIUM] CVE-2022-4913: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195....
Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to spoof extension storage via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: resolved (
debian
CVE-2023-0140P4MEDIUMCVSS 6.5fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0140 [MEDIUM] CVE-2023-0140: chromium - Inappropriate implementation in in File System API in Google Chrome on Windows p...
Inappropriate implementation in in File System API in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 109.0.5414.74-1)
bullseye: resolved (fixed in 109.0.5414.74-2~deb11u1)
forky: resolved (fixed in 109.0.
debian
CVE-2022-2622P4MEDIUMCVSS 6.5fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2622 [MEDIUM] CVE-2022-2622: chromium - Insufficient validation of untrusted input in Safe Browsing in Google Chrome on ...
Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file.
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky: resolved (fixed in 104.0.5112.79-1)
sid: resolved (fixed i
debian
CVE-2022-4922P4MEDIUMCVSS 6.5fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-4922 [MEDIUM] CVE-2022-4922: chromium - Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 all...
Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 99.0.4844.51-1)
bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1)
forky: resolved (fixed in 99.0.4844.51-1)
sid: resolved (fixed in 99
debian
CVE-2022-1862P4MEDIUMCVSS 6.5fixed in chromium 102.0.5005.61-1 (bookworm)2022
CVE-2022-1862 [MEDIUM] CVE-2022-1862: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 102.0.5005....
Inappropriate implementation in Extensions in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass profile restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 102.0.5005.61-1)
bullseye: resolved (fixed in 102.0.5005.61-1~deb11u1)
forky: resolved (fixed in 102.0.5005.61-1
debian