cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 9 of 107
CVE-2021-21124P3CRITICALCVSS 9.6fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21124 [CRITICAL] CVE-2021-21124: chromium - Potential user after free in Speech Recognizer in Google Chrome on Android prior... Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.96-0.1) bullseye: resolved (fixed in 88.0.4324.96-0.1) forky: resolved (fixed in 88.0.4324.96-0.1) sid: resolved (fixed in
debian
CVE-2025-5063P3HIGHCVSS 8.8fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5063 [HIGH] CVE-2025-5063: chromium - Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a ... Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1) bullseye: open forky: resolved (fixed in 137.0.7151.55-1) sid: resolved (fixed in 137.0.7151.55-1) trixie:
debian
CVE-2026-5865P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5865 [HIGH] CVE-2026-5865: chromium - Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote at... Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2021-21110P3CRITICALCVSS 9.6fixed in chromium 87.0.4280.141-0.1 (bookworm)2021
CVE-2021-21110 [CRITICAL] CVE-2021-21110: chromium - Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed ... Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.141-0.1) bullseye: resolved (fixed in 87.0.4280.141-0.1) forky: resolved (fixed in 87.0.4280.141-0.1) sid: resolved (fixed in 87.0.4280.141-0.1) tri
debian
CVE-2024-1284P3CRITICALCVSS 9.8fixed in chromium 121.0.6167.160-1~deb12u1 (bookworm)2024
CVE-2024-1284 [CRITICAL] CVE-2024-1284: chromium - Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote... Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 121.0.6167.160-1~deb12u1) bullseye: open forky: resolved (fixed in 121.0.6167.160-1) sid: resolved (fixed in 121.0.6167.160-1) trixie:
debian
CVE-2021-21157P3HIGHCVSS 8.8fixed in chromium 88.0.4324.182-1 (bookworm)2021
CVE-2021-21157 [HIGH] CVE-2021-21157: chromium - Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 a... Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.182-1) bullseye: resolved (fixed in 88.0.4324.182-1) forky: resolved (fixed in 88.0.4324.182-1) sid: resolved (fixed in 88.0.4324.182-1) trixie: r
debian
CVE-2025-5068P3HIGHCVSS 8.8fixed in chromium 137.0.7151.68-1~deb12u1 (bookworm)2025
CVE-2025-5068 [HIGH] CVE-2025-5068: chromium - Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote... Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 137.0.7151.68-1~deb12u1) bullseye: open forky: resolved (fixed in 137.0.7151.68-1) sid: resolved (fixed in 137.0.7151.68-1) trixie: reso
debian
CVE-2026-5289P3CRITICALCVSS 9.6fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5289 [CRITICAL] CVE-2026-5289: chromium - Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a ... Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1) s
debian
CVE-2026-5874P3CRITICALCVSS 9.6fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5874 [CRITICAL] CVE-2026-5874: chromium - Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a re... Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2021-21122P3HIGHCVSS 8.8fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21122 [HIGH] CVE-2021-21122: chromium - Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote ... Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.96-0.1) bullseye: resolved (fixed in 88.0.4324.96-0.1) forky: resolved (fixed in 88.0.4324.96-0.1) sid: resolved (fixed in 88.0.4324.96-0.1) trixie: resolved (fix
debian
CVE-2021-21120P3HIGHCVSS 8.8fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21120 [HIGH] CVE-2021-21120: chromium - Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote... Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.96-0.1) bullseye: resolved (fixed in 88.0.4324.96-0.1) forky: resolved (fixed in 88.0.4324.96-0.1) sid: resolved (fixed in 88.0.4324.96-0.1) trixie: resolved (fi
debian
CVE-2021-21119P3HIGHCVSS 8.8fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21119 [HIGH] CVE-2021-21119: chromium - Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote ... Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.96-0.1) bullseye: resolved (fixed in 88.0.4324.96-0.1) forky: resolved (fixed in 88.0.4324.96-0.1) sid: resolved (fixed i
debian
CVE-2026-5858P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5858 [HIGH] CVE-2026-5858: chromium - Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a ... Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2021-21128P3HIGHCVSS 8.8fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21128 [HIGH] CVE-2021-21128: chromium - Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a r... Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 88.0.4324.96-0.1) bullseye: resolved (fixed in 88.0.4324.96-0.1) forky: resolved (fixed in 88.0.4324.96-0.1) sid: resolved (fixed in 88.0.4324.96-0.1) trixie: resolve
debian
CVE-2026-5860P3HIGHCVSS 8.8fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5860 [HIGH] CVE-2026-5860: chromium - Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remot... Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-4680P3HIGHCVSS 8.8fixed in chromium 146.0.7680.164-1~deb12u1 (bookworm)2026
CVE-2026-4680 [HIGH] CVE-2026-4680: chromium - Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remot... Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.164-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.164-1) sid: resolved (fixed in 146.0.7680.164-1) trixie
debian
CVE-2026-5287P3HIGHCVSS 8.8fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5287 [HIGH] CVE-2026-5287: chromium - Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote ... Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1) sid: resolved (fixed in 146.0.7680.177-1) trixie: r
debian
CVE-2026-5285P3HIGHCVSS 8.8fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5285 [HIGH] CVE-2026-5285: chromium - Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remot... Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1) sid: resolved (fixed in 146.0.7680.177-1) trixie
debian
CVE-2026-4678P3HIGHCVSS 8.8fixed in chromium 146.0.7680.164-1~deb12u1 (bookworm)2026
CVE-2026-4678 [HIGH] CVE-2026-4678: chromium - Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remo... Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.164-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.164-1) sid: resolved (fixed in 146.0.7680.164-1) trixi
debian
CVE-2026-5280P3HIGHCVSS 8.8fixed in chromium 146.0.7680.177-1~deb12u1 (bookworm)2026
CVE-2026-5280 [HIGH] CVE-2026-5280: chromium - Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a r... Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7680.177-1) sid: resolved (fixed in 146.0.7680.177-1) tr
debian
Debian Chromium vulnerabilities | cvebase