cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 8 of 107
CVE-2026-0906P3CRITICALCVSS 9.8fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0906 [CRITICAL] CVE-2026-0906: chromium - Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowe... Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1) bullseye: open forky: resolved (fixed in 144.0.7559.59-1) sid: resolved (fixed in 144.0.7559.
debian
CVE-2023-4430P3HIGHCVSS 8.8fixed in chromium 116.0.5845.110-1~deb12u1 (bookworm)2023
CVE-2023-4430 [HIGH] CVE-2023-4430: chromium - Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remo... Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 116.0.5845.110-1~deb12u1) bullseye: resolved (fixed in 116.0.5845.110-1~deb11u1) forky: resolved (fixed in 116.0.5845.110-1) sid: resolv
debian
CVE-2025-7656P3HIGHCVSS 8.8fixed in chromium 138.0.7204.157-1~deb12u1 (bookworm)2025
CVE-2025-7656 [HIGH] CVE-2025-7656: chromium - Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote... Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 138.0.7204.157-1~deb12u1) bullseye: open forky: resolved (fixed in 138.0.7204.157-1) sid: resolved (fixed in 138.0.7204.157-1) trixie: res
debian
CVE-2021-21121P3CRITICALCVSS 9.6fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21121 [CRITICAL] CVE-2021-21121: chromium - Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowe... Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.96-0.1) bullseye: resolved (fixed in 88.0.4324.96-0.1) forky: resolved (fixed in 88.0.4324.96-0.1) sid: resolved (fixed in 88.0.4324.96-0.1) trixi
debian
CVE-2018-20346P3HIGHCVSS 8.1fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-20346 [HIGH] CVE-2018-20346: chromium - SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer ... SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan. Scope: loc
debian
CVE-2023-5482P3HIGHCVSS 8.8fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5482 [HIGH] CVE-2023-5482: chromium - Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 all... Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1) bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1) forky: resolved (fixed in 119.0.6045.105-1)
debian
CVE-2024-9954P3HIGHCVSS 8.8fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9954 [HIGH] CVE-2024-9954: chromium - Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote at... Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1) bullseye: open forky: resolved (fixed in 130.0.6723.58-1) sid: resolved (fixed in 130.0.6723.58-1) trixie: resolved
debian
CVE-2024-12692P3HIGHCVSS 8.8fixed in chromium 131.0.6778.204-1~deb12u1 (bookworm)2024
CVE-2024-12692 [HIGH] CVE-2024-12692: chromium - Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 131.0.6778.204-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778.204-1) sid: resolved (fixed in 131.0.6778.204-1) trixie: res
debian
CVE-2021-30625P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30625 [HIGH] CVE-2021-30625: chromium - Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a... Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: res
debian
CVE-2025-9478P3HIGHCVSS 8.8fixed in chromium 139.0.7258.154-1~deb12u1 (bookworm)2025
CVE-2025-9478 [HIGH] CVE-2025-9478: chromium - Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remot... Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) Scope: local bookworm: resolved (fixed in 139.0.7258.154-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0.7258.154-1) sid: resolved (fixed in 139.0.7258.154-1) trixie
debian
CVE-2025-4052P3CRITICALCVSS 9.8fixed in chromium 136.0.7103.59-2~deb12u2 (bookworm)2025
CVE-2025-4052 [CRITICAL] CVE-2025-4052: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59... Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 136.0.7103.59-2~deb12u2) bullseye: open forky: resolved (fixed
debian
CVE-2025-9132P3HIGHCVSS 8.8fixed in chromium 139.0.7258.138-1~deb12u1 (bookworm)2025
CVE-2025-9132 [HIGH] CVE-2025-9132: chromium - Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a rem... Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 139.0.7258.138-1~deb12u1) bullseye: open forky: resolved (fixed in 139.0.7258.138-1) sid: resolved (fixed in 139.0.7258.138-1) trixie:
debian
CVE-2021-30598P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30598 [HIGH] CVE-2021-30598: chromium - Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote at... Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (fixed in 93.0.4577.82-1) trixie: resolved (fixed in
debian
CVE-2025-0434P3HIGHCVSS 8.8fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0434 [HIGH] CVE-2025-0434: chromium - Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowe... Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1) bullseye: open forky: resolved (fixed in 132.0.6834.83-1) sid: resolved (fixed in 132.0.6834.83-1) trix
debian
CVE-2024-9122P3HIGHCVSS 8.8fixed in chromium 129.0.6668.70-1~deb12u1 (bookworm)2024
CVE-2024-9122 [HIGH] CVE-2024-9122: chromium - Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 129.0.6668.70-1~deb12u1) bullseye: open forky: resolved (fixed in 129.0.6668.70-1) sid: resolved (fixed in 129.0.6668.70-1) trixie: resolved
debian
CVE-2021-30557P3HIGHCVSS 8.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30557 [HIGH] CVE-2021-30557: chromium - Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an a... Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 93.0.4577.82-1) bullseye: resolved (fixed in 93.0.4577.82-1) forky: resolved (fixed in 93.0.4577.82-1) sid: resolved (f
debian
CVE-2024-2887P3HIGHCVSS 7.7fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2887 [HIGH] CVE-2024-2887: chromium - Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a ... Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1) bullseye: open forky: resolved (fixed in 123.0.6312.86-1) sid: resolved (fixed in 123.0.6312.86-1) trixie: resolved (fix
debian
CVE-2024-5841P3HIGHCVSS 8.8fixed in chromium 126.0.6478.56-1~deb12u1 (bookworm)2024
CVE-2024-5841 [HIGH] CVE-2024-5841: chromium - Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote at... Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1) bullseye: open forky: resolved (fixed in 126.0.6478.56-1) sid: resolved (fixed in 126.0.6478.56-1) trixie: resolve
debian
CVE-2024-12382P3HIGHCVSS 8.8fixed in chromium 131.0.6778.139-1~deb12u1 (bookworm)2024
CVE-2024-12382 [HIGH] CVE-2024-12382: chromium - Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a r... Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 131.0.6778.139-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778.139-1) sid: resolved (fixed in 131.0.6778.139-1) trix
debian
CVE-2024-12381P3HIGHCVSS 8.8fixed in chromium 131.0.6778.139-1~deb12u1 (bookworm)2024
CVE-2024-12381 [HIGH] CVE-2024-12381: chromium - Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote a... Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 131.0.6778.139-1~deb12u1) bullseye: open forky: resolved (fixed in 131.0.6778.139-1) sid: resolved (fixed in 131.0.6778.139-1) trixie: res
debian
Debian Chromium vulnerabilities | cvebase