Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 89 of 107
CVE-2024-3841P4MEDIUMCVSS 6.1fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3841 [MEDIUM] CVE-2024-3841: chromium - Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0...
Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.60-1)
sid: resolved (fixe
debian
CVE-2022-3863P4MEDIUMCVSS 6.1fixed in chromium 100.0.4896.75-1 (bookworm)2022
CVE-2022-3863 [MEDIUM] CVE-2022-3863: chromium - Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowe...
Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrome security severity: High)
Scope: local
bookworm: resolved (fixed in 100.0.4896.75-1)
bullseye: resolved (fixed in 100.0.4896.75-1~deb11u1)
forky: resolved (fixed in 100.0.4896.75-1)
sid: resolved
debian
CVE-2020-6412P4MEDIUMCVSS 5.4fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6412 [MEDIUM] CVE-2020-6412: chromium - Insufficient validation of untrusted input in Omnibox in Google Chrome prior to ...
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.
debian
CVE-2020-6411P4MEDIUMCVSS 5.4fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6411 [MEDIUM] CVE-2020-6411: chromium - Insufficient validation of untrusted input in Omnibox in Google Chrome prior to ...
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.
debian
CVE-2021-30539P4MEDIUMCVSS 5.4fixed in chromium 93.0.4577.82-1 (bookworm)2021
CVE-2021-30539 [MEDIUM] CVE-2021-30539: chromium - Insufficient policy enforcement in content security policy in Google Chrome prio...
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 93.0.4577.82-1)
bullseye: resolved (fixed in 93.0.4577.82-1)
forky: resolved (fixed in 93.0.4577.82-1)
sid: resolved (fixed in 93.0.4577.82-
debian
CVE-2022-3201P4MEDIUMCVSS 5.4fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3201 [MEDIUM] CVE-2022-3201: chromium - Insufficient validation of untrusted input in DevTools in Google Chrome on Chrom...
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 10
debian
CVE-2023-4359P4MEDIUMCVSS 5.3fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4359 [MEDIUM] CVE-2023-4359: chromium - Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 11...
Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed a remote attacker to potentially spoof elements of the security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky: resolved (
debian
CVE-2025-5064P4MEDIUMCVSS 5.4fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5064 [MEDIUM] CVE-2025-5064: chromium - Inappropriate implementation in Background Fetch API in Google Chrome prior to 1...
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1)
bullseye: open
forky: resolved (fixed in 137.0.7151.55-1)
sid: resolved (fixed in 137.0.7151.
debian
CVE-2025-9867P4MEDIUMCVSS 5.4fixed in chromium 140.0.7339.80-1~deb12u1 (bookworm)2025
CVE-2025-9867 [MEDIUM] CVE-2025-9867: chromium - Inappropriate implementation in Downloads in Google Chrome on Android prior to 1...
Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 140.0.7339.80-1~deb12u1)
bullseye: open
forky: resolved (fixed in 140.0.7339.80-1)
sid: resolved (fixed in 140.0.7339.80-
debian
CVE-2025-9865P4MEDIUMCVSS 5.4fixed in chromium 140.0.7339.80-1~deb12u1 (bookworm)2025
CVE-2025-9865 [MEDIUM] CVE-2025-9865: chromium - Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140...
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 140.0.7339.80-1~deb12u1)
bullseye: open
forky: resolved (fixed i
debian
CVE-2025-12435P4MEDIUMCVSS 5.4fixed in chromium 142.0.7444.59-1~deb12u1 (bookworm)2025
CVE-2025-12435 [MEDIUM] CVE-2025-12435: chromium - Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444...
Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 142.0.7444.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 142.0.7444.59-1)
sid: resolved (fixed in 142.0.7444.59-1)
trix
debian
CVE-2026-2322P4MEDIUMCVSS 5.4fixed in chromium 145.0.7632.75-1~deb12u1 (bookworm)2026
CVE-2026-2322 [MEDIUM] CVE-2026-2322: chromium - Inappropriate implementation in File input in Google Chrome prior to 145.0.7632....
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.45
debian
CVE-2025-13632P4MEDIUMCVSS 5.4fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13632 [MEDIUM] CVE-2025-13632: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41...
Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1)
bullseye: open
forky: resolved (fixe
debian
CVE-2025-11210P4MEDIUMCVSS 5.4fixed in chromium 141.0.7390.54-1~deb12u1 (bookworm)2025
CVE-2025-11210 [MEDIUM] CVE-2025-11210: chromium - Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 ...
Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 141.0.7390.54-1~deb12u1)
bullseye: open
forky: resolved (fixed in 141.0.7390.
debian
CVE-2026-0901P4MEDIUMCVSS 5.4fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0901 [MEDIUM] CVE-2026-0901: chromium - Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0...
Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 144.0.7559.59-1)
sid: resolved (fixed in 144.0.7559.59-1)
tri
debian
CVE-2026-3063P4MEDIUMCVSS 5.4fixed in chromium 145.0.7632.116-1~deb12u1 (bookworm)2026
CVE-2026-3063 [MEDIUM] CVE-2026-3063: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.11...
Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via DevTools. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 145.0.7632.116-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.
debian
CVE-2026-0904P4MEDIUMCVSS 5.4fixed in chromium 144.0.7559.59-1~deb12u1 (bookworm)2026
CVE-2026-0904 [MEDIUM] CVE-2026-0904: chromium - Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.755...
Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 144.0.7559.59-1~deb12u1)
bullseye: open
forky: resolved (fixed in 144.0.7559.59-1)
sid: resolved (fixed in 144.0.7559.59-1)
t
debian
CVE-2025-13097P4MEDIUMCVSS 5.4fixed in chromium 136.0.7103.59-2~deb12u2 (bookworm)2025
CVE-2025-13097 [MEDIUM] CVE-2025-13097: chromium - Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59...
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 136.0.7103.59-2~deb12u2)
bullseye: open
forky: resolved (fixed in 136.0.7103.59-2)
sid: resolved (fixed in 136.0.7
debian
CVE-2026-5895P4MEDIUMCVSS 5.4fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5895 [MEDIUM] CVE-2026-5895: chromium - Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 ...
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2025-6555P4MEDIUMCVSS 5.4fixed in chromium 138.0.7204.49-1~deb12u1 (bookworm)2025
CVE-2025-6555 [MEDIUM] CVE-2025-6555: chromium - Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a re...
Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 138.0.7204.49-1~deb12u1)
bullseye: open
forky: resolved (fixed in 138.0.7204.49-1)
sid: resolved (fixed in 138.0.7204.49-1)
trixie
debian