Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 84 of 107
CVE-2022-2160P4MEDIUMCVSS 6.5fixed in chromium 103.0.5060.53-1 (bookworm)2022
CVE-2022-2160 [MEDIUM] CVE-2022-2160: chromium - Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to...
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 103.0.5060.53-1)
bullseye: resolved (fixed in 103.0.5060.53-1
debian
CVE-2022-2612P4MEDIUMCVSS 6.5fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2612 [MEDIUM] CVE-2022-2612: chromium - Side-channel information leakage in Keyboard input in Google Chrome prior to 104...
Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky:
debian
CVE-2022-0292P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0292 [MEDIUM] CVE-2022-0292: chromium - Inappropriate implementation in Fenced Frames in Google Chrome prior to 97.0.469...
Inappropriate implementation in Fenced Frames in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1)
sid
debian
CVE-2022-2615P4MEDIUMCVSS 6.5fixed in chromium 104.0.5112.79-1 (bookworm)2022
CVE-2022-2615 [MEDIUM] CVE-2022-2615: chromium - Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112....
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 104.0.5112.79-1)
bullseye: resolved (fixed in 104.0.5112.79-1~deb11u1)
forky: resolved (fixed in 104.0.5112.79-1)
sid: resolved (fixed in 104.0.5112.79-1)
trixie: re
debian
CVE-2022-0305P4MEDIUMCVSS 6.5fixed in chromium 97.0.4692.99-1 (bookworm)2022
CVE-2022-0305 [MEDIUM] CVE-2022-0305: chromium - Inappropriate implementation in Service Worker API in Google Chrome prior to 97....
Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.99-1)
bullseye: resolved (fixed in 97.0.4692.99-1~deb11u2)
forky: resolved (fixed in 97.0.4692.99-1)
sid: re
debian
CVE-2022-1137P4MEDIUMCVSS 6.5fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1137 [MEDIUM] CVE-2022-1137: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896....
Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially sensitive information via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.
debian
CVE-2022-4915P4MEDIUMCVSS 6.5fixed in chromium 103.0.5060.134-1 (bookworm)2022
CVE-2022-4915 [MEDIUM] CVE-2022-4915: chromium - Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5...
Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 103.0.5060.134-1)
bullseye: resolved (fixed in 103.0.5060.134-1~deb11u1)
forky: resolved (fixed in 103.0.5060.134-1)
sid:
debian
CVE-2019-5879P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-5879 [MEDIUM] CVE-2019-5879: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.386...
Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolv
debian
CVE-2023-0133P4MEDIUMCVSS 6.5fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0133 [MEDIUM] CVE-2023-0133: chromium - Inappropriate implementation in in Permission prompts in Google Chrome on Androi...
Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main origin permission delegation via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 109.0.5414.74-1)
bullseye: resolved (fixed in 109.0.5414.74-2~deb11u1)
forky: resolved (
debian
CVE-2022-4926P4MEDIUMCVSS 6.5fixed in chromium 109.0.5414.119-1 (bookworm)2022
CVE-2022-4926 [MEDIUM] CVE-2022-4926: chromium - Insufficient policy enforcement in Intents in Google Chrome on Android prior to ...
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 109.0.5414.119-1)
bullseye: resolved (fixed in 109.0.5414.119-1~deb11u1)
forky: resolved (fixed in 109.0.5414.119
debian
CVE-2023-0130P4MEDIUMCVSS 6.5fixed in chromium 109.0.5414.74-1 (bookworm)2023
CVE-2023-0130 [MEDIUM] CVE-2023-0130: chromium - Inappropriate implementation in in Fullscreen API in Google Chrome on Android pr...
Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 109.0.5414.74-1)
bullseye: resolved (fixed in 109.0.5414.74-2~deb11u1)
forky: resolved (f
debian
CVE-2023-0697P4MEDIUMCVSS 6.5fixed in chromium 110.0.5481.77-1 (bookworm)2023
CVE-2023-0697 [MEDIUM] CVE-2023-0697: chromium - Inappropriate implementation in Full screen mode in Google Chrome on Android pri...
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 110.0.5481.77-1)
bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1)
forky: resolved (fixed in 1
debian
CVE-2025-0441P4MEDIUMCVSS 6.5fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0441 [MEDIUM] CVE-2025-0441: chromium - Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.68...
Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive information from the system via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1)
bullseye: open
forky: resolved (fixed in 132.0.6834.83-1)
sid: res
debian
CVE-2025-1921P4MEDIUMCVSS 6.5fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1921 [MEDIUM] CVE-2025-1921: chromium - Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.699...
Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1)
bullseye: open
forky: resolved (fixed in 134.0.6998.35-1)
sid: resolved (fixed in 134.
debian
CVE-2022-1499P4MEDIUMCVSS 6.3fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1499 [MEDIUM] CVE-2022-1499: chromium - Inappropriate implementation in WebAuthentication in Google Chrome prior to 101....
Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
debian
CVE-2025-14372P4MEDIUMCVSS 6.1fixed in chromium 143.0.7499.109-1~deb12u1 (bookworm)2025
CVE-2025-14372 [MEDIUM] CVE-2025-14372: chromium - Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allo...
Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 143.0.7499.109-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.0.7499.109-1)
sid: resolved (fixed in 143.0.7499
debian
CVE-2026-5896P4MEDIUMCVSS 6.1fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5896 [MEDIUM] CVE-2026-5896: chromium - Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote ...
Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2021-30597P4MEDIUMCVSS 6.8fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30597 [MEDIUM] CVE-2021-30597: chromium - Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 a...
Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-1)
t
debian
CVE-2019-5781P4MEDIUMCVSS 6.5fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5781 [MEDIUM] CVE-2019-5781: chromium - Incorrect handling of a confusable character in Omnibox in Google Chrome prior t...
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.
debian
CVE-2019-5775P4MEDIUMCVSS 6.5fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5775 [MEDIUM] CVE-2019-5775: chromium - Incorrect handling of a confusable character in Omnibox in Google Chrome prior t...
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.
debian