Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 88 of 107
CVE-2019-13678P4MEDIUMCVSS 6.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13678 [MEDIUM] CVE-2019-13678: chromium - Incorrect data validation in downloads in Google Chrome prior to 77.0.3865.75 al...
Incorrect data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed
debian
CVE-2019-5857P4MEDIUMCVSS 6.5fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5857 [MEDIUM] CVE-2019-5857: chromium - Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.8...
Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixed in 76.0.3809.87-1)
trixie:
debian
CVE-2019-5754P4MEDIUMCVSS 6.5fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-5754 [MEDIUM] CVE-2019-5754: chromium - Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 a...
Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid
debian
CVE-2019-5848P4MEDIUMCVSS 6.5fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5848 [MEDIUM] CVE-2019-5848: chromium - Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allo...
Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixed in 76.0.38
debian
CVE-2018-20070P4MEDIUMCVSS 6.5fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-20070 [MEDIUM] CVE-2018-20070: chromium - Incorrect handling of confusable characters in URL Formatter in Google Chrome pr...
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed
debian
CVE-2024-3847P4MEDIUMCVSS 6.1fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3847 [MEDIUM] CVE-2024-3847: chromium - Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60...
Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.60-1)
sid: resolved (fixed in 124.0.6367.60-1)
t
debian
CVE-2026-5899P4MEDIUMCVSS 6.1fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5899 [MEDIUM] CVE-2026-5899: chromium - Insufficient policy enforcement in History Navigation in Google Chrome prior to ...
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.
debian
CVE-2020-6394P4MEDIUMCVSS 5.4fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6394 [MEDIUM] CVE-2020-6394: chromium - Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 ...
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: resol
debian
CVE-2025-5283P4MEDIUMCVSS 5.4fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5283 [MEDIUM] CVE-2025-5283: chromium - Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remot...
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1)
bullseye: open
forky: resolved (fixed in 137.0.7151.55-1)
sid: resolved (fixed in 137.0.7151.55-1)
trixie: r
debian
CVE-2025-0445P4MEDIUMCVSS 5.4fixed in chromium 133.0.6943.53-1~deb12u1 (bookworm)2025
CVE-2025-0445 [MEDIUM] CVE-2025-0445: chromium - Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote at...
Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 133.0.6943.53-1~deb12u1)
bullseye: open
forky: resolved (fixed in 133.0.6943.53-1)
sid: resolved (fixed in 133.0.6943.53-1)
trixie: resolve
debian
CVE-2025-6557P4MEDIUMCVSS 5.4fixed in chromium 138.0.7204.49-1~deb12u1 (bookworm)2025
CVE-2025-6557 [MEDIUM] CVE-2025-6557: chromium - Insufficient data validation in DevTools in Google Chrome on Windows prior to 13...
Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 138.0.7204.49-1~deb12u1)
bullseye: open
forky: resolved (fixed in 1
debian
CVE-2025-12440P4MEDIUMCVSS 5.3fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12440 [MEDIUM] CVE-2025-12440: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59...
Inappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: ope
debian
CVE-2025-12909P4MEDIUMCVSS 5.3fixed in chromium 140.0.7339.80-1~deb12u1 (bookworm)2025
CVE-2025-12909 [MEDIUM] CVE-2025-12909: chromium - Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339...
Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via Devtools. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 140.0.7339.80-1~deb12u1)
bullseye: open
forky: resolved (fixed in 140.0.7339.80-1)
sid: resolved (fixed in 140.0.7339.80-1)
trixie: resolve
debian
CVE-2026-3940P4MEDIUMCVSS 5.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3940 [MEDIUM] CVE-2026-3940: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680...
Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1
debian
CVE-2026-3930P4MEDIUMCVSS 5.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3930 [MEDIUM] CVE-2026-3930: chromium - Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 a...
Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1)
debian
CVE-2019-5855P4MEDIUMCVSS 6.5fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5855 [MEDIUM] CVE-2019-5855: chromium - Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remo...
Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixed in 76.0.3809.87-1)
trixie: resolved (fixed in
debian
CVE-2019-5867P4MEDIUMCVSS 6.5fixed in chromium 76.0.3809.100-1 (bookworm)2019
CVE-2019-5867 [MEDIUM] CVE-2019-5867: chromium - Out of bounds read in JavaScript in Google Chrome prior to 76.0.3809.100 allowed...
Out of bounds read in JavaScript in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 76.0.3809.100-1)
bullseye: resolved (fixed in 76.0.3809.100-1)
forky: resolved (fixed in 76.0.3809.100-1)
sid: resolved (fixed in 76.0.3809.100-1)
trixie: resolve
debian
CVE-2020-6535P4MEDIUMCVSS 6.1fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6535 [MEDIUM] CVE-2020-6535: chromium - Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 all...
Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1
debian
CVE-2023-5480P4MEDIUMCVSS 6.1fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5480 [MEDIUM] CVE-2023-5480: chromium - Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.10...
Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1)
bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1)
forky: resolved (fixed in 119.0.6045.105-1)
sid: reso
debian
CVE-2022-1494P4MEDIUMCVSS 6.1fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1494 [MEDIUM] CVE-2022-1494: chromium - Insufficient data validation in Trusted Types in Google Chrome prior to 101.0.49...
Insufficient data validation in Trusted Types in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass trusted types policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-1)
tr
debian