Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 94 of 107
CVE-2022-0112P4MEDIUMCVSS 4.3fixed in chromium 97.0.4692.71-0.1 (bookworm)2022
CVE-2022-0112 [MEDIUM] CVE-2022-0112: chromium - Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allow...
Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie
debian
CVE-2023-5850P4MEDIUMCVSS 4.3fixed in chromium 119.0.6045.105-1~deb12u1 (bookworm)2023
CVE-2023-5850 [MEDIUM] CVE-2023-5850: chromium - Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allo...
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 119.0.6045.105-1~deb12u1)
bullseye: resolved (fixed in 119.0.6045.105-1~deb11u1)
forky: resolved (fixed in 119.0.6045.105-1)
sid: re
debian
CVE-2023-2468P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2468 [MEDIUM] CVE-2023-2468: chromium - Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0...
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 113.0.5672.63-1)
bullseye: resolved (fixed in 113.0.5672.63-1~deb11u1)
forky: res
debian
CVE-2024-3845P4MEDIUMCVSS 4.3fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3845 [MEDIUM] CVE-2024-3845: chromium - Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60...
Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.60-1)
sid: resolved (fixed in 124.0.6367.60-1)
trix
debian
CVE-2023-4901P4MEDIUMCVSS 4.3fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-4901 [MEDIUM] CVE-2023-4901: chromium - Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 ...
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1)
forky: resolved (fixed in 117.0.5938.62-1)
si
debian
CVE-2023-4905P4MEDIUMCVSS 4.3fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-4905 [MEDIUM] CVE-2023-4905: chromium - Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 ...
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1)
forky: resolved (fixed in 117.0.5938.62-1)
sid: resolved
debian
CVE-2023-4902P4MEDIUMCVSS 4.3fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-4902 [MEDIUM] CVE-2023-4902: chromium - Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 al...
Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1)
forky: resolved (fixed in 117.0.5938.62-1)
sid: resolved (f
debian
CVE-2023-4906P4MEDIUMCVSS 4.3fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-4906 [MEDIUM] CVE-2023-4906: chromium - Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938...
Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1)
forky: resolved (fixed in 117.0.5938.62-1)
si
debian
CVE-2023-2941P4MEDIUMCVSS 4.3fixed in chromium 114.0.5735.90-2~deb12u1 (bookworm)2023
CVE-2023-2941 [MEDIUM] CVE-2023-2941: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 114.0.5...
Inappropriate implementation in Extensions API in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to spoof the contents of the UI via a crafted Chrome Extension. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.0.5735.9
debian
CVE-2023-4904P4MEDIUMCVSS 4.3fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-4904 [MEDIUM] CVE-2023-4904: chromium - Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.593...
Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1)
forky: resolved (fixed in 117.0.5
debian
CVE-2024-2628P4MEDIUMCVSS 4.3fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2628 [MEDIUM] CVE-2024-2628: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.5...
Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.58-1)
sid: resolved (fixed in 123.0.6312.58-1)
trixie: resolv
debian
CVE-2024-0811P4MEDIUMCVSS 4.3fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-0811 [MEDIUM] CVE-2024-0811: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6...
Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 121.0.
debian
CVE-2023-3740P4MEDIUMCVSS 4.3fixed in chromium 115.0.5790.98-1~deb12u1 (bookworm)2023
CVE-2023-3740 [MEDIUM] CVE-2023-3740: chromium - Insufficient validation of untrusted input in Themes in Google Chrome prior to 1...
Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content to a user via a crafted background URL. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 115.0.5790.98-1~deb12u1)
bullseye: resolved (fixed in 115.0.5790.98-1~deb11u1)
forky: resolve
debian
CVE-2023-5477P4MEDIUMCVSS 4.3fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5477 [MEDIUM] CVE-2023-5477: chromium - Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.7...
Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted command. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1)
forky: resolved (fixed in 118.0.5993.70-1)
debian
CVE-2023-1221P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1221 [MEDIUM] CVE-2023-1221: chromium - Insufficient policy enforcement in Extensions API in Google Chrome prior to 111....
Insufficient policy enforcement in Extensions API in Google Chrome prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.6
debian
CVE-2025-14373P4MEDIUMCVSS 4.3fixed in chromium 143.0.7499.109-1~deb12u1 (bookworm)2025
CVE-2025-14373 [MEDIUM] CVE-2025-14373: chromium - Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143...
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 143.0.7499.109-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.0.7499.109-1)
sid: resolved (fixed in 143.0.7
debian
CVE-2025-13637P4MEDIUMCVSS 4.3fixed in chromium 143.0.7499.40-1~deb12u1 (bookworm)2025
CVE-2025-13637 [MEDIUM] CVE-2025-13637: chromium - Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.4...
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass download protections via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 143.0.7499.40-1~deb12u1)
bullseye: open
forky: resolved (fixed in 143.
debian
CVE-2026-5880P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5880 [MEDIUM] CVE-2026-5880: chromium - Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.77...
Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: o
debian
CVE-2026-5887P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5887 [MEDIUM] CVE-2026-5887: chromium - Insufficient validation of untrusted input in Downloads in Google Chrome on Wind...
Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-3941P4MEDIUMCVSS 4.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3941 [MEDIUM] CVE-2026-3941: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680...
Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.71-1)
sid: resolved (fixed in 146.0.7680.71-1
debian