Debian Chromium vulnerabilities
2,134 known vulnerabilities affecting debian/chromium.
Total CVEs
2,134
CISA KEV
63
actively exploited
Public exploits
37
Exploited in wild
71
Severity breakdown
CRITICAL102HIGH1256MEDIUM754LOW14UNKNOWN8
Vulnerabilities
Page 99 of 107
CVE-2022-4195P4MEDIUMCVSS 4.3fixed in chromium 108.0.5359.71-1 (bookworm)2022
CVE-2022-4195 [MEDIUM] CVE-2022-4195: chromium - Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0...
Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass Safe Browsing warnings via a malicious file. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 108.0.5359.71-1)
bullseye: resolved (fixed in 108.0.5359.71-2~deb11u1)
forky: resolved (fixed in 108.0.5359.71-1)
sid:
debian
CVE-2024-7003P4MEDIUMCVSS 4.3fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-7003 [MEDIUM] CVE-2024-7003: chromium - Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 al...
Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1)
s
debian
CVE-2019-5864P4MEDIUMCVSS 4.3fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5864 [MEDIUM] CVE-2019-5864: chromium - Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allo...
Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
Scope: local
bookworm: resolved (fixed in 76.0.3809.87-1)
bullseye: resolved (fixed in 76.0.3809.87-1)
forky: resolved (fixed in 76.0.3809.87-1)
sid: r
debian
CVE-2022-3318P4MEDIUMCVSS 4.3fixed in chromium 106.0.5249.61-1 (bookworm)2022
CVE-2022-3318 [MEDIUM] CVE-2022-3318: chromium - Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 1...
Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to reboot Chrome OS to potentially exploit heap corruption via UI interaction. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 106.0.5249.61-1)
bullseye: resolved (fixed in 106.0.5249.61-1~deb11u1)
f
debian
CVE-2024-7976P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-7976 [MEDIUM] CVE-2024-7976: chromium - Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 al...
Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.84-1)
trixie: reso
debian
CVE-2023-1224P4MEDIUMCVSS 4.3fixed in chromium 111.0.5563.64-1 (bookworm)2023
CVE-2023-1224 [MEDIUM] CVE-2023-1224: chromium - Insufficient policy enforcement in Web Payments API in Google Chrome prior to 11...
Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-
debian
CVE-2024-7001P4MEDIUMCVSS 4.3fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-7001 [MEDIUM] CVE-2024-7001: chromium - Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 all...
Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1)
debian
CVE-2024-6999P4MEDIUMCVSS 4.3fixed in chromium 127.0.6533.88-1~deb12u1 (bookworm)2024
CVE-2024-6999 [MEDIUM] CVE-2024-6999: chromium - Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 al...
Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1
debian
CVE-2024-8906P4MEDIUMCVSS 4.3fixed in chromium 129.0.6668.58-1~deb12u1 (bookworm)2024
CVE-2024-8906 [MEDIUM] CVE-2024-8906: chromium - Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allow...
Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 129.0.6668.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 129.0.6668.58-1)
s
debian
CVE-2024-8034P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-8034 [MEDIUM] CVE-2024-8034: chromium - Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to...
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.84-1
debian
CVE-2024-0809P4MEDIUMCVSS 4.3fixed in chromium 121.0.6167.85-1~deb12u1 (bookworm)2024
CVE-2024-0809 [MEDIUM] CVE-2024-0809: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85...
Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 121.0.6167.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 121.0.6167.85-1)
sid: resolved (fixed in 121.0.6167.85-1)
tri
debian
CVE-2024-7022P4MEDIUMCVSS 4.3fixed in chromium 123.0.6312.86-1~deb12u1 (bookworm)2024
CVE-2024-7022 [MEDIUM] CVE-2024-7022: chromium - Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote...
Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 123.0.6312.86-1~deb12u1)
bullseye: open
forky: resolved (fixed in 123.0.6312.58-1)
sid: resolved (fixed in 123.0.6312.58-1)
trixie: re
debian
CVE-2024-11111P4MEDIUMCVSS 4.3fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11111 [MEDIUM] CVE-2024-11111: chromium - Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69...
Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 131.0.6778
debian
CVE-2024-8035P4MEDIUMCVSS 4.3fixed in chromium 128.0.6613.84-1~deb12u1 (bookworm)2024
CVE-2024-8035 [MEDIUM] CVE-2024-8035: chromium - Inappropriate implementation in Extensions in Google Chrome on Windows prior to ...
Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 128.0.6613.84-1~deb12u1)
bullseye: open
forky: resolved (fixed in 128.0.6613.84-1)
sid: resolved (fixed in 128.0.6613.84-1)
debian
CVE-2024-11116P4MEDIUMCVSS 4.3fixed in chromium 131.0.6778.85-1~deb12u1 (bookworm)2024
CVE-2024-11116 [MEDIUM] CVE-2024-11116: chromium - Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 al...
Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 131.0.6778.85-1~deb12u1)
bullseye: open
forky: resolved (fixed in 131.0.6778.85
debian
CVE-2025-1922P4MEDIUMCVSS 4.3fixed in chromium 134.0.6998.35-1~deb12u1 (bookworm)2025
CVE-2025-1922 [MEDIUM] CVE-2025-1922: chromium - Inappropriate implementation in Selection in Google Chrome on Android prior to 1...
Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 134.0.6998.35-1~deb12u1)
bullseye: open
forky: resolved (fixed in 134
debian
CVE-2025-0446P4MEDIUMCVSS 4.3fixed in chromium 132.0.6834.83-1~deb12u1 (bookworm)2025
CVE-2025-0446 [MEDIUM] CVE-2025-0446: chromium - Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834....
Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 132.0.6834.83-1~deb12u1)
bullseye: open
forky: resolved (fixed in 132.0.
debian
CVE-2024-9958P4MEDIUMCVSS 4.3fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9958 [MEDIUM] CVE-2024-9958: chromium - Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0...
Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.6723.58-1)
sid: resolved (fixed in 130.0.6723.58-1)
t
debian
CVE-2024-9962P4MEDIUMCVSS 4.3fixed in chromium 130.0.6723.58-1~deb12u1 (bookworm)2024
CVE-2024-9962 [MEDIUM] CVE-2024-9962: chromium - Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723...
Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 130.0.6723.58-1~deb12u1)
bullseye: open
forky: resolved (fixed in 130.0.672
debian
CVE-2024-7019P4MEDIUMCVSS 4.3fixed in chromium 124.0.6367.60-1~deb12u1 (bookworm)2024
CVE-2024-7019 [MEDIUM] CVE-2024-7019: chromium - Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allow...
Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 124.0.6367.60-1~deb12u1)
bullseye: open
forky: resolved (fixed in 124.0.6367.60-1)
s
debian