cbcvebase.

Debian Chromium vulnerabilities

2,134 known vulnerabilities affecting debian/chromium.

Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8

Vulnerabilities

Page 95 of 107
CVE-2026-5911P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5911 [MEDIUM] CVE-2026-5911: chromium - Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed ... Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5906P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5906 [MEDIUM] CVE-2026-5906: chromium - Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727... Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5900P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5900 [MEDIUM] CVE-2026-5900: chromium - Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a rem... Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5898P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5898 [MEDIUM] CVE-2026-5898: chromium - Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 ... Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-5897P4MEDIUMCVSS 4.3fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5897 [MEDIUM] CVE-2026-5897: chromium - Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allow... Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2026-3928P4MEDIUMCVSS 4.3fixed in chromium 146.0.7680.71-1~deb12u1 (bookworm)2026
CVE-2026-3928 [MEDIUM] CVE-2026-3928: chromium - Insufficient policy enforcement in Extensions in Google Chrome prior to 146.0.76... Insufficient policy enforcement in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium) Scope: local bookworm: resolved (fixed in 146.0.7680.71-1~deb12u1) bullseye: open forky: resolved (fixed in 146.0.7
debian
CVE-2019-5860P4MEDIUMCVSS 5.5fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5860 [MEDIUM] CVE-2019-5860: chromium - Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote... Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Scope: local bookworm: resolved (fixed in 76.0.3809.87-1) bullseye: resolved (fixed in 76.0.3809.87-1) forky: resolved (fixed in 76.0.3809.87-1) sid: resolved (fixed in 76.0.3809.87-1) trixie: resolved (fixed in 76
debian
CVE-2019-13707P4MEDIUMCVSS 5.5fixed in chromium 78.0.3904.87-1 (bookworm)2019
CVE-2019-13707 [MEDIUM] CVE-2019-13707: chromium - Insufficient validation of untrusted input in intents in Google Chrome on Androi... Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application. Scope: local bookworm: resolved (fixed in 78.0.3904.87-1) bullseye: resolved (fixed in 78.0.3904.87-1) forky: resolved (fixed in 78.0.3904.87-1) sid: resolved (fixed in 78.0.3904.87-1) trixie: re
debian
CVE-2026-5867P4LOWCVSS 3.1fixed in chromium 147.0.7727.55-1 (sid)2026
CVE-2026-5867 [LOW] CVE-2026-5867: chromium - Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a ... Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) Scope: local bookworm: open bullseye: open forky: open sid: resolved (fixed in 147.0.7727.55-1) trixie: open
debian
CVE-2020-16012P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16012 [MEDIUM] CVE-2020-16012: chromium - Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280... Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: res
debian
CVE-2020-6489P4MEDIUMCVSS 4.3fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6489 [MEDIUM] CVE-2020-6489: chromium - Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4... Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page. Scope: local bookworm: resolved (fixed in 83.0.4103.83-1) bullseye: resolved (fixed in 83.0.4103.83-1) fo
debian
CVE-2020-6531P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6531 [MEDIUM] CVE-2020-6531: chromium - Side-channel information leakage in scroll to text in Google Chrome prior to 84.... Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie:
debian
CVE-2020-6391P4MEDIUMCVSS 4.3fixed in chromium 80.0.3987.106-1 (bookworm)2020
CVE-2020-6391 [MEDIUM] CVE-2020-6391: chromium - Insufficient validation of untrusted input in Blink in Google Chrome prior to 80... Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page. Scope: local bookworm: resolved (fixed in 80.0.3987.106-1) bullseye: resolved (fixed in 80.0.3987.106-1) forky: resolved (fixed in 80.0.3987.106-1) sid: resolved (fixed in 80.0.3987.106-1) tri
debian
CVE-2020-15966P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15966 [MEDIUM] CVE-2020-15966: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.418... Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed
debian
CVE-2021-21185P4MEDIUMCVSS 4.3fixed in chromium 89.0.4389.82-1 (bookworm)2021
CVE-2021-21185 [MEDIUM] CVE-2021-21185: chromium - Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.438... Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extension. Scope: local bookworm: resolved (fixed in 89.0.4389.82-1) bullseye: resolved (fixed in 89.0.4389.82-1) forky: resolved (fixed in 89.0.4389.82-
debian
CVE-2020-6571P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6571 [MEDIUM] CVE-2020-6571: chromium - Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 a... Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0
debian
CVE-2020-6529P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-6529 [MEDIUM] CVE-2020-6529: chromium - Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 al... Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.
debian
CVE-2019-13759P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13759 [MEDIUM] CVE-2019-13759: chromium - Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 al... Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fixed
debian
CVE-2019-13756P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13756 [MEDIUM] CVE-2019-13756: chromium - Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed... Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1) trixie: resolved (fixed in 79
debian
CVE-2019-13758P4MEDIUMCVSS 4.3fixed in chromium 79.0.3945.79-1 (bookworm)2019
CVE-2019-13758 [MEDIUM] CVE-2019-13758: chromium - Insufficient policy enforcement in navigation in Google Chrome on Android prior ... Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 79.0.3945.79-1) bullseye: resolved (fixed in 79.0.3945.79-1) forky: resolved (fixed in 79.0.3945.79-1) sid: resolved (fixed in 79.0.3945.79-1)
debian
Debian Chromium vulnerabilities | cvebase