Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 90 of 107
CVE-2024-9966P4MEDIUMCVSS 5.3fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9966 [MEDIUM] CVE-2024-9966: chromium - Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723...
Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.58-1)
sid: resolved (fixed in 130.0.6723.58-1
debian
CVE-2026-5886P4MEDIUMCVSS 5.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5886 [MEDIUM] CVE-2026-5886: chromium - Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 al...
Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5892P4UNKNOWNfixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5892 CVE-2026-5892: chromium - Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 ...
Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to install a PWA without user consent via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2021-21140P4MEDIUMCVSS 6.8fixed in chromium 88.0.4324.96-0.1 (bookworm)2021
CVE-2021-21140 [MEDIUM] CVE-2021-21140: chromium - Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local ...
Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.
Scope: local
bookworm: resolved (fixed in 88.0.4324.96-0.1)
bullseye: resolved (fixed in 88.0.4324.96-0.1)
forky: resolved (fixed in 88.0.4324.96-0.1)
sid: resolved (fixed in 88.0.4324.96-0.1)
trixie: re
debian
CVE-2022-3048P4MEDIUMCVSS 6.8fixed in chromium 105.0.5195.52-1 (bookworm)2022
CVE-2022-3048 [MEDIUM] CVE-2022-3048: chromium - Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome ...
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
Scope: local
bookworm: resolved (fixed in 105.0.5195.52-1)
bullseye: resolved (fixed in 105.0.5195.52-1~deb11u1)
forky: resolved (fixed in 105.0.5195.52-1)
debian
CVE-2020-6470P4MEDIUMCVSS 6.1fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6470 [MEDIUM] CVE-2020-6470: chromium - Insufficient validation of untrusted input in clipboard in Google Chrome prior t...
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.
debian
CVE-2021-37999P4MEDIUMCVSS 6.1fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37999 [MEDIUM] CVE-2021-37999: chromium - Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638...
Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved
debian
CVE-2022-1492P4MEDIUMCVSS 6.1fixed in chromium 101.0.4951.41-1 (bookworm)2022
CVE-2022-1492 [MEDIUM] CVE-2022-1492: chromium - Insufficient data validation in Blink Editing in Google Chrome prior to 101.0.49...
Insufficient data validation in Blink Editing in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 101.0.4951.41-1)
bullseye: resolved (fixed in 101.0.4951.41-1~deb11u1)
forky: resolved (fixed in 101.0.4951.41-1)
sid: resolved (fixed in 101.0.4951.41-
debian
CVE-2025-12910P4MEDIUMCVSS 6.2fixed in chromium 140.0.7339.80-1~deb12u1 (bookworm)2025
CVE-2025-12910 [MEDIUM] CVE-2025-12910: chromium - Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80...
Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 140.0.7339.80-1~deb12u1)
bullseye: open
forky: resolved (fixed in 140.0.7339.80-1)
sid: resolved (fixed in 140.0.7339.80-1)
debian
CVE-2024-8907P4MEDIUMCVSS 6.1fixed in chromium 129.0.6668.58-1~deb12u1 (bookworm)2024
CVE-2024-8907 [MEDIUM] CVE-2024-8907: chromium - Insufficient data validation in Omnibox in Google Chrome on Android prior to 129...
Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 129.0.6668.58-1~deb12u1)
bullseye: open
debian
CVE-2020-6425P4MEDIUMCVSS 5.4fixed in chromium 80.0.3987.149-1 (bookworm)2020
CVE-2020-6425 [MEDIUM] CVE-2020-6425: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.398...
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 80.0.3987.149-1)
bullseye: resolved (fixed in 80.0.3987.149-1)
forky: resolved (fixed in 80.0.3987.149-1)
si
debian
CVE-2019-13711P4MEDIUMCVSS 5.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13711 [MEDIUM] CVE-2019-13711: chromium - Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.390...
Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (
debian
CVE-2024-1672P4MEDIUMCVSS 5.4fixed in chromium 122.0.6261.57-1~deb12u1 (bookworm)2024
CVE-2024-1672 [MEDIUM] CVE-2024-1672: chromium - Inappropriate implementation in Content Security Policy in Google Chrome prior t...
Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 122.0.6261.57-1~deb12u1)
bullseye: open
forky: resolved (fixed in 122.0.6261.57-1)
sid: resolved (fixed in
debian
CVE-2023-4361P4MEDIUMCVSS 5.3fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4361 [MEDIUM] CVE-2023-4361: chromium - Inappropriate implementation in Autofill in Google Chrome on Android prior to 11...
Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky: resolved (fixed in 116.0.58
debian
CVE-2019-13680P4MEDIUMCVSS 5.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13680 [MEDIUM] CVE-2019-13680: chromium - Inappropriate implementation in TLS in Google Chrome prior to 77.0.3865.75 allow...
Inappropriate implementation in TLS in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof client IP address to websites via crafted TLS connections.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: res
debian
CVE-2025-5067P4MEDIUMCVSS 5.4fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5067 [MEDIUM] CVE-2025-5067: chromium - Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.5...
Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1)
bullseye: open
forky: resolved (fixed in 137.0.7151.55-1)
sid: resolved (fixed in 137.0.7151.55-1)
trixie: res
debian
CVE-2025-0996P4MEDIUMCVSS 5.4fixed in chromium 133.0.6943.98-1~deb12u1 (bookworm)2025
CVE-2025-0996 [MEDIUM] CVE-2025-0996: chromium - Inappropriate implementation in Browser UI in Google Chrome on Android prior to ...
Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 133.0.6943.98-1~deb12u1)
bullseye: open
forky: resolved (fixed in 133.0.6943.98-1)
sid: resolved (
debian
CVE-2025-3073P4MEDIUMCVSS 5.4fixed in chromium 135.0.7049.52-1~deb12u1 (bookworm)2025
CVE-2025-3073 [MEDIUM] CVE-2025-3073: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52...
Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 135.0.7049.52-1~deb12u1)
bullseye: open
forky: resolved (fixed in 135.0.7049.52-1
debian
CVE-2025-3072P4MEDIUMCVSS 5.4fixed in chromium 135.0.7049.52-1~deb12u1 (bookworm)2025
CVE-2025-3072 [MEDIUM] CVE-2025-3072: chromium - Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049...
Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 135.0.7049.52-1~deb12u1)
bullseye: open
forky: resolved (fixed in 135.0.7049.5
debian
CVE-2025-3071P4MEDIUMCVSS 5.4fixed in chromium 135.0.7049.52-1~deb12u1 (bookworm)2025
CVE-2025-3071 [MEDIUM] CVE-2025-3071: chromium - Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049...
Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 135.0.7049.52-1~deb12u1)
bullseye: open
forky: resolved (fixed in 135.0.
debian