Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 95 of 107
CVE-2026-5911P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5911 [MEDIUM] CVE-2026-5911: chromium - Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed ...
Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5906P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5906 [MEDIUM] CVE-2026-5906: chromium - Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727...
Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5900P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5900 [MEDIUM] CVE-2026-5900: chromium - Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a rem...
Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5898P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5898 [MEDIUM] CVE-2026-5898: chromium - Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 ...
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-5897P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5897 [MEDIUM] CVE-2026-5897: chromium - Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allow...
Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2026-3928P4MEDIUMCVSS 4.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3928 [MEDIUM] CVE-2026-3928: chromium - Insufficient policy enforcement in Extensions in Google Chrome prior to 146.0.76...
Insufficient policy enforcement in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7
debian
CVE-2019-5860P4MEDIUMCVSS 5.5fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5860 [MEDIUM] CVE-2019-5860: chromium - Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote...
Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: resolved (fixed in 76.0.3809.87-1)
trixie: resolved (fixed in 76
debian
CVE-2019-13707P4MEDIUMCVSS 5.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13707 [MEDIUM] CVE-2019-13707: chromium - Insufficient validation of untrusted input in intents in Google Chrome on Androi...
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: re
debian
CVE-2026-5867P4LOWCVSS 3.1fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5867 [LOW] CVE-2026-5867: chromium - Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a ...
Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
debian
CVE-2020-16012P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16012 [MEDIUM] CVE-2020-16012: chromium - Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280...
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: res
debian
CVE-2020-6489P4MEDIUMCVSS 4.3fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6489 [MEDIUM] CVE-2020-6489: chromium - Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4...
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
fo
debian
CVE-2020-6531P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6531 [MEDIUM] CVE-2020-6531: chromium - Side-channel information leakage in scroll to text in Google Chrome prior to 84....
Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie:
debian
CVE-2020-6391P4MEDIUMCVSS 4.3fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6391 [MEDIUM] CVE-2020-6391: chromium - Insufficient validation of untrusted input in Blink in Google Chrome prior to 80...
Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
tri
debian
CVE-2020-15966P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15966 [MEDIUM] CVE-2020-15966: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.418...
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed
debian
CVE-2021-21185P4MEDIUMCVSS 4.3fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21185 [MEDIUM] CVE-2021-21185: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.438...
Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 89.0.4389.82-1)
bullseye: resolved (fixed in 89.0.4389.82-1)
forky: resolved (fixed in 89.0.4389.82-
debian
CVE-2020-6571P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6571 [MEDIUM] CVE-2020-6571: chromium - Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 a...
Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0
debian
CVE-2020-6529P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6529 [MEDIUM] CVE-2020-6529: chromium - Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 al...
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.
debian
CVE-2019-13759P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13759 [MEDIUM] CVE-2019-13759: chromium - Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 al...
Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (fixed
debian
CVE-2019-13756P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13756 [MEDIUM] CVE-2019-13756: chromium - Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed...
Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
trixie: resolved (fixed in 79
debian
CVE-2019-13758P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13758 [MEDIUM] CVE-2019-13758: chromium - Insufficient policy enforcement in navigation in Google Chrome on Android prior ...
Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 79.0.3945.79-1)
bullseye: resolved (fixed in 79.0.3945.79-1)
forky: resolved (fixed in 79.0.3945.79-1)
sid: resolved (fixed in 79.0.3945.79-1)
debian