cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 91 of 107
CVE-2024-0333P4MEDIUMCVSS 5.3fixed in chromium 120.0.6099.216-1~deb12u1 (bookworm)2024
CVE-2024-0333 [MEDIUM] CVE-2024-0333: chromium - Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.... Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: resolved (fixed in 120.0.6099.216-1~deb12u1) bullseye: resolved (fixed in 120.0.6099.216-1~deb11u1) forky: resolve
debian
CVE-2025-6556P4MEDIUMCVSS 5.4fixed in chromium 138.0.7204.49-1~deb12u1 (bookworm)2025
CVE-2025-6556 [MEDIUM] CVE-2025-6556: chromium - Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.4... Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 138.0.7204.49-1~deb12u1) bullseye: open forky: resolved (fixed in 138.0.7204.49-1) sid: resolved (fixed in 138.0.7204.49-1)
debian
CVE-2019-13714P4MEDIUMCVSS 6.1fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13714 [MEDIUM] CVE-2019-13714: chromium - Insufficient validation of untrusted input in Color Enhancer extension in Google... Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904
debian
CVE-2020-16030P4MEDIUMCVSS 6.1fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16030 [MEDIUM] CVE-2020-16030: chromium - Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 all... Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) t
debian
CVE-2022-0801P4MEDIUMCVSS 6.1fixed in chromium 99.0.4844.51-1 (bookworm)2022
CVE-2022-0801 [MEDIUM] CVE-2022-0801: chromium - Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.... Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass XSS preventions via a crafted HTML page. (Chrome security severity: Medium) Scope: local bookworm: resolved (fixed in 99.0.4844.51-1) bullseye: resolved (fixed in 99.0.4844.51-1~deb11u1) forky: resolved (fixed in 99.0.4844.51-1) sid: resolved (fixe
debian
CVE-2022-1132P4MEDIUMCVSS 6.1fixed in chromium 100.0.4896.60-1 (bookworm)2022
CVE-2022-1132 [MEDIUM] CVE-2022-1132: chromium - Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS p... Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation restrictions via physical access to the device. Scope: local bookworm: resolved (fixed in 100.0.4896.60-1) bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1) forky: resolved (fixed in 100.0.4896.60-1) sid: resolved (
debian
CVE-2020-6516P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6516 [MEDIUM] CVE-2020-6516: chromium - Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote at... Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fixed in 87.0.4280
debian
CVE-2021-21217P4MEDIUMCVSS 5.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21217 [MEDIUM] CVE-2021-21217: chromium - Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a re... Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file. Scope: local bookworm: resolved (fixed in 90.0.4430.72-1) bullseye: resolved (fixed in 90.0.4430.72-1) forky: resolved (fixed in 90.0.4430.72-1) sid: resolved (fixed in 90.0.4430.72-1
debian
CVE-2019-13660P4MEDIUMCVSS 5.3fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13660 [MEDIUM] CVE-2019-13660: chromium - UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote ... UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: resolved (fixed in 78.0.3904.87-1)
debian
CVE-2022-4910P4MEDIUMCVSS 5.4fixed in chromium 107.0.5304.68-1 (bookworm)2022
CVE-2022-4910 [MEDIUM] CVE-2022-4910: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62... Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 107.0.5304.68-1) bullseye: resolved (fixed in 107.0.5304.68-1~deb11u1) forky: resolved (fixed in 107.0.5304.68-1) sid: res
debian
CVE-2021-21200P4MEDIUMCVSS 5.4fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21200 [MEDIUM] CVE-2021-21200: chromium - Out of bounds read in WebUI Settings in Google Chrome prior to 89.0.4389.72 allo... Out of bounds read in WebUI Settings in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chrome security severity: Low) Scope: local bookworm: resolved (fixed in 89.0.4389.82-1) bullseye: resolved (fixed in 89.0.4389.82-1) forky: resolved (fixed in 89.0.4389.82-1) sid: resolved (fixed
debian
CVE-2025-3074P4MEDIUMCVSS 5.4fixed in chromium 135.0.7049.52-1~deb12u1 (bookworm)2025
CVE-2025-3074 [MEDIUM] CVE-2025-3074: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.5... Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 135.0.7049.52-1~deb12u1) bullseye: open forky: resolved (fixed in 135.0.7049.52-1) sid: resolved (fixed in 135.0.7049.52-1) trixie: res
debian
CVE-2025-5281P4MEDIUMCVSS 5.4fixed in chromium 137.0.7151.55-3~deb12u1 (bookworm)2025
CVE-2025-5281 [MEDIUM] CVE-2025-5281: chromium - Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 ... Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1) bullseye: open forky: resolved (fixed in 137.0.7151.55-1) sid: resolved (fixed in 137.0.7151.
debian
CVE-2025-12906P4MEDIUMCVSS 5.4fixed in chromium 140.0.7339.80-1~deb12u1 (bookworm)2025
CVE-2025-12906 [MEDIUM] CVE-2025-12906: chromium - Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339... Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: resolved (fixed in 140.0.7339.80-1~deb12u1) bullseye: open forky: resolved (fixed in 140.0.7339.80-1) sid: resolved (fixed in 140.0.7339.80-1) trixie:
debian
CVE-2026-5890P4UNKNOWNfixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5890 CVE-2026-5890: chromium - Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attac... Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2021-21218P4MEDIUMCVSS 5.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21218 [MEDIUM] CVE-2021-21218: chromium - Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a re... Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file. Scope: local bookworm: resolved (fixed in 90.0.4430.72-1) bullseye: resolved (fixed in 90.0.4430.72-1) forky: resolved (fixed in 90.0.4430.72-1) sid: resolved (fixed in 90.0.4430.72-1
debian
CVE-2021-21219P4MEDIUMCVSS 5.5fixed in chromium 90.0.4430.72-1 (bookworm)2021
CVE-2021-21219 [MEDIUM] CVE-2021-21219: chromium - Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a re... Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file. Scope: local bookworm: resolved (fixed in 90.0.4430.72-1) bullseye: resolved (fixed in 90.0.4430.72-1) forky: resolved (fixed in 90.0.4430.72-1) sid: resolved (fixed in 90.0.4430.72-1
debian
CVE-2019-5823P4MEDIUMCVSS 5.4fixed in chromium 74.0.3729.108-1 (bookworm)2019
CVE-2019-5823 [MEDIUM] CVE-2019-5823: chromium - Insufficient policy enforcement in service workers in Google Chrome prior to 74.... Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 74.0.3729.108-1) bullseye: resolved (fixed in 74.0.3729.108-1) forky: resolved (fixed in 74.0.3729.108-1) sid: resolved (fixed in 74.0.3729.108-1) tr
debian
CVE-2021-37958P4MEDIUMCVSS 5.4fixed in chromium 97.0.4692.71-0.1 (bookworm)2021
CVE-2021-37958 [MEDIUM] CVE-2021-37958: chromium - Inappropriate implementation in Navigation in Google Chrome on Windows prior to ... Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page. Scope: local bookworm: resolved (fixed in 97.0.4692.71-0.1) bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1) forky: resolved (fixed in 97.0.4692.71-0.1) sid: resolved
debian
CVE-2019-13684P4MEDIUMCVSS 5.3fixed in chromium 72.0.3626.81-1 (bookworm)2019
CVE-2019-13684 [MEDIUM] CVE-2019-13684: chromium - Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.8... Inappropriate implementation in JavaScript in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 72.0.3626.81-1) bullseye: resolved (fixed in 72.0.3626.81-1) forky: resolved (fixed in 72.0.3626.81-1) sid: resolved (fixed in 72.0.3626.81-1) trixie: resolved (fix
debian
Debian Chromium vulnerabilities | cvebase