Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 97 of 107
CVE-2019-5838P4MEDIUMCVSS 4.3fixed in chromium 75.0.3770.80-1 (bookworm)2019
CVE-2019-5838 [MEDIUM] CVE-2019-5838: chromium - Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0...
Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 75.0.3770.80-1)
bullseye: resolved (fixed in 75.0.3770.80-1)
forky: resolved (fixed in 75.0.37
debian
CVE-2023-5478P4MEDIUMCVSS 4.3fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5478 [MEDIUM] CVE-2023-5478: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70...
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1)
forky: resolved (fixed in 118.0.5993.70-1)
sid: resolv
debian
CVE-2022-4185P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4185 [MEDIUM] CVE-2022-4185: chromium - Inappropriate implementation in Navigation in Google Chrome on iOS prior to 108....
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 108.0.5359.71 allowed a remote attacker to spoof the contents of the modal dialogue via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
forky: resolved (fixed in 108.0.
debian
CVE-2022-3443P4MEDIUMCVSS 4.3fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3443 [MEDIUM] CVE-2022-3443: chromium - Insufficient data validation in File System API in Google Chrome prior to 106.0....
Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
forky: resolved (fixed in 106.0.5249.61-1)
sid
debian
CVE-2024-3846P4MEDIUMCVSS 4.3fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3846 [MEDIUM] CVE-2024-3846: chromium - Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 ...
Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.60-1)
debian
CVE-2020-16031P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16031 [MEDIUM] CVE-2020-16031: chromium - Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowe...
Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
debian
CVE-2022-3444P4MEDIUMCVSS 4.3fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3444 [MEDIUM] CVE-2022-3444: chromium - Insufficient data validation in File System API in Google Chrome prior to 106.0....
Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page and malicious file. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
forky: resolved (fixed in 1
debian
CVE-2023-5486P4MEDIUMCVSS 4.3fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5486 [MEDIUM] CVE-2023-5486: chromium - Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 al...
Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1)
forky: resolved (fixed in 118.0.5993.70-1)
sid: resolved (fixe
debian
CVE-2023-5485P4MEDIUMCVSS 4.3fixed in chromium 118.0.5993.70-1~deb12u1 (bookworm)2023
CVE-2023-5485 [MEDIUM] CVE-2023-5485: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70...
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 118.0.5993.70-1~deb12u1)
bullseye: resolved (fixed in 118.0.5993.70-1~deb11u1)
forky: resolved (fixed in 118.0.5993.70-1)
sid:
debian
CVE-2023-4907P4MEDIUMCVSS 4.3fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-4907 [MEDIUM] CVE-2023-4907: chromium - Inappropriate implementation in Intents in Google Chrome on Android prior to 117...
Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1)
forky: resolved (fixed in 117.0.5938.62-1)
si
debian
CVE-2023-4903P4MEDIUMCVSS 4.3fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-4903 [MEDIUM] CVE-2023-4903: chromium - Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android p...
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1)
forky: resolved (fixed in 117.0.593
debian
CVE-2023-4900P4MEDIUMCVSS 4.3fixed in chromium 117.0.5938.62-1~deb12u1 (bookworm)2023
CVE-2023-4900 [MEDIUM] CVE-2023-4900: chromium - Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to...
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1~deb12u1)
bullseye: resolved (fixed in 117.0.5938.62-1~deb11u1)
forky: resolved (fixed in 117.
debian
CVE-2023-4365P4MEDIUMCVSS 4.3fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4365 [MEDIUM] CVE-2023-4365: chromium - Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845....
Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky: resolved (fixed in 116.0.5845.96-1)
sid: re
debian
CVE-2023-4360P4MEDIUMCVSS 4.3fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4360 [MEDIUM] CVE-2023-4360: chromium - Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 al...
Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky: resolved (fixed in 116.0.5845.96-1)
sid: resolve
debian
CVE-2023-4364P4MEDIUMCVSS 4.3fixed in chromium 116.0.5845.96-1~deb12u1 (bookworm)2023
CVE-2023-4364 [MEDIUM] CVE-2023-4364: chromium - Inappropriate implementation in Permission Prompts in Google Chrome prior to 116...
Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 116.0.5845.96-1~deb12u1)
bullseye: resolved (fixed in 116.0.5845.96-1~deb11u1)
forky: resolved (fixed in 116.0.5845.96-1)
debian
CVE-2020-16032P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16032 [MEDIUM] CVE-2020-16032: chromium - Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 a...
Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-
debian
CVE-2024-2629P4MEDIUMCVSS 4.3fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2629 [MEDIUM] CVE-2024-2629: chromium - Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a r...
Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.58-1)
sid: resolved (fixed in 123.0.6312.58-1)
trixie: resolved (fix
debian
CVE-2024-3844P4MEDIUMCVSS 4.3fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-3844 [MEDIUM] CVE-2024-3844: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367....
Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.60-1)
sid: resolved (fixed in 124.0.6367.60-1)
tri
debian
CVE-2024-2631P4MEDIUMCVSS 4.3fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-2631 [MEDIUM] CVE-2024-2631: chromium - Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allo...
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.58-1)
sid: resolved (fixed in 123.0.6312.58-1)
trixie: resolved
debian
CVE-2023-2464P4MEDIUMCVSS 4.3fixed in chromium 113.0.5672.63-1 (bookworm)2023
CVE-2023-2464 [MEDIUM] CVE-2023-2464: chromium - Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0...
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 113.0.5672.63-1)
bullseye: resolved (fixed in 113.0.56
debian