Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 91 of 107
CVE-2024-0333P4MEDIUMCVSS 5.3fixed in chromium 120.0.6099.216-1~deb12u1 (bookworm)2024
CVE-2024-0333 [MEDIUM] CVE-2024-0333: chromium - Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099....
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 120.0.6099.216-1~deb12u1)
bullseye: resolved (fixed in 120.0.6099.216-1~deb11u1)
forky: resolve
debian
CVE-2025-6556P4MEDIUMCVSS 5.4fixed in chromium 138.0.7204.49-1~deb12u1 (bookworm)2025
CVE-2025-6556 [MEDIUM] CVE-2025-6556: chromium - Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.4...
Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 138.0.7204.49-1~deb12u1)
bullseye: open
forky: resolved (fixed in 138.0.7204.49-1)
sid: resolved (fixed in 138.0.7204.49-1)
debian
CVE-2019-13714P4MEDIUMCVSS 6.1fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13714 [MEDIUM] CVE-2019-13714: chromium - Insufficient validation of untrusted input in Color Enhancer extension in Google...
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904
debian
CVE-2020-16030P4MEDIUMCVSS 6.1fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16030 [MEDIUM] CVE-2020-16030: chromium - Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 all...
Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
t
debian
CVE-2022-0801P4MEDIUMCVSS 6.1fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0801 [MEDIUM] CVE-2022-0801: chromium - Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844....
Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass XSS preventions via a crafted HTML page. (Chrome security severity: Medium)
Scope: local
bookworm: resolved (fixed in 99.0.4844.51-1)
bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1)
forky: resolved (fixed in 99.0.4844.51-1)
sid: resolved (fixe
debian
CVE-2022-1132P4MEDIUMCVSS 6.1fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1132 [MEDIUM] CVE-2022-1132: chromium - Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS p...
Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation restrictions via physical access to the device.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.0.4896.60-1)
sid: resolved (
debian
CVE-2020-6516P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6516 [MEDIUM] CVE-2020-6516: chromium - Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote at...
Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fixed in 87.0.4280
debian
CVE-2021-21217P4MEDIUMCVSS 5.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21217 [MEDIUM] CVE-2021-21217: chromium - Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a re...
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1
debian
CVE-2019-13660P4MEDIUMCVSS 5.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13660 [MEDIUM] CVE-2019-13660: chromium - UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote ...
UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 78.0.3904.87-1)
debian
CVE-2022-4910P4MEDIUMCVSS 5.4fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-4910 [MEDIUM] CVE-2022-4910: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62...
Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 107.0.5304.68-1)
bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1)
forky: resolved (fixed in 107.0.5304.68-1)
sid: res
debian
CVE-2021-21200P4MEDIUMCVSS 5.4fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21200 [MEDIUM] CVE-2021-21200: chromium - Out of bounds read in WebUI Settings in Google Chrome prior to 89.0.4389.72 allo...
Out of bounds read in WebUI Settings in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chrome security severity: Low)
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-1)
sid: resolved (fixed
debian
CVE-2025-3074P4MEDIUMCVSS 5.4fixed in chromium 135.0.7049.52-1~deb12u1 (bookworm)2025
CVE-2025-3074 [MEDIUM] CVE-2025-3074: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.5...
Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 135.0.7049.52-1~deb12u1)
bullseye: open
forky: resolved (fixed in 135.0.7049.52-1)
sid: resolved (fixed in 135.0.7049.52-1)
trixie: res
debian
CVE-2025-5281P4MEDIUMCVSS 5.4fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5281 [MEDIUM] CVE-2025-5281: chromium - Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 ...
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1)
bullseye: open
forky: resolved (fixed in 137.0.7151.55-1)
sid: resolved (fixed in 137.0.7151.
debian
CVE-2025-12906P4MEDIUMCVSS 5.4fixed in chromium 140.0.7339.80-1~deb12u1 (bookworm)2025
CVE-2025-12906 [MEDIUM] CVE-2025-12906: chromium - Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339...
Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 140.0.7339.80-1~deb12u1)
bullseye: open
forky: resolved (fixed in 140.0.7339.80-1)
sid: resolved (fixed in 140.0.7339.80-1)
trixie:
debian
CVE-2026-5890P4UNKNOWNfixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5890 CVE-2026-5890: chromium - Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attac...
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2021-21218P4MEDIUMCVSS 5.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21218 [MEDIUM] CVE-2021-21218: chromium - Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a re...
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1
debian
CVE-2021-21219P4MEDIUMCVSS 5.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21219 [MEDIUM] CVE-2021-21219: chromium - Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a re...
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 90.0.4430.72-1)
bullseye: resolved (fixed in 90.0.4430.72-1)
forky: resolved (fixed in 90.0.4430.72-1)
sid: resolved (fixed in 90.0.4430.72-1
debian
CVE-2019-5823P4MEDIUMCVSS 5.4fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5823 [MEDIUM] CVE-2019-5823: chromium - Insufficient policy enforcement in service workers in Google Chrome prior to 74....
Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 74.0.3729.108-1)
bullseye: resolved (fixed in 74.0.3729.108-1)
forky: resolved (fixed in 74.0.3729.108-1)
sid: resolved (fixed in 74.0.3729.108-1)
tr
debian
CVE-2021-37958P4MEDIUMCVSS 5.4fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37958 [MEDIUM] CVE-2021-37958: chromium - Inappropriate implementation in Navigation in Google Chrome on Windows prior to ...
Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved
debian
CVE-2019-13684P4MEDIUMCVSS 5.3fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-13684 [MEDIUM] CVE-2019-13684: chromium - Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.8...
Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.0.3626.81-1)
trixie: resolved (fix
debian