apk package
wolfi/chromium
pkg:apk/wolfi/chromium
Vulnerabilities (2,281)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-13227 | Hig | 8.8 | < 142.0.7444.59-r0 | 142.0.7444.59-r0 | Nov 18, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2025-13226 | Hig | 8.8 | < 142.0.7444.59-r0 | 142.0.7444.59-r0 | Nov 18, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2025-13224 | Hig | 8.8 | < 142.0.7444.175-r0 | 142.0.7444.175-r0 | Nov 17, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2025-13223 | Hig | 8.8 | KEV | < 142.0.7444.175-r0 | 142.0.7444.175-r0 | Nov 17, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2025-9479 | Med | 4.3 | < 133.0.6943.141-r0 | 133.0.6943.141-r0 | Nov 14, 2025 | Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2025-13107 | Med | 4.3 | < 140.0.7339.80-r0 | 140.0.7339.80-r0 | Nov 14, 2025 | Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2025-13102 | Med | 4.3 | < 134.0.6998.35-r0 | 134.0.6998.35-r0 | Nov 14, 2025 | Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2025-13097 | Med | 5.4 | < 136.0.7103.48-r0 | 136.0.7103.48-r0 | Nov 14, 2025 | Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-9126 | Hig | 7.5 | < 127.0.6533.88-r0 | 127.0.6533.88-r0 | Nov 14, 2025 | Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a series of curated UI gestures. (Chromium security severity: Medium) | |
| CVE-2024-7021 | Med | 4.3 | < 124.0.6367.60-r0 | 124.0.6367.60-r0 | Nov 14, 2025 | Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-7017 | Hig | 7.5 | < 126.0.6478.182-r0 | 126.0.6478.182-r0 | Nov 14, 2025 | Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-13983 | Med | 6.3 | < 136.0.7103.59-r0 | 136.0.7103.59-r0 | Nov 14, 2025 | Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low) | |
| CVE-2024-13178 | Med | 4.3 | < 128.0.6613.84-r0 | 128.0.6613.84-r0 | Nov 14, 2025 | Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2024-11920 | Med | 4.3 | < 130.0.6723.92-r0 | 130.0.6723.92-r0 | Nov 14, 2025 | Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2024-11919 | Med | 4.3 | < 129.0.6668.58-r0 | 129.0.6668.58-r0 | Nov 14, 2025 | Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2025-13042 | Hig | 8.8 | < 142.0.7444.175-r0 | 142.0.7444.175-r0 | Nov 12, 2025 | Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2025-12729 | Med | 4.2 | < 142.0.7444.137-r0 | 142.0.7444.137-r0 | Nov 10, 2025 | Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2025-12728 | Med | 4.2 | < 142.0.7444.137-r0 | 142.0.7444.137-r0 | Nov 10, 2025 | Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2025-12727 | Hig | 8.8 | < 142.0.7444.137-r0 | 142.0.7444.137-r0 | Nov 10, 2025 | Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2025-12726 | Hig | 7.5 | < 142.0.7444.137-r0 | 142.0.7444.137-r0 | Nov 10, 2025 | Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) |
- affected < 142.0.7444.59-r0fixed 142.0.7444.59-r0
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 142.0.7444.59-r0fixed 142.0.7444.59-r0
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 142.0.7444.175-r0fixed 142.0.7444.175-r0
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 142.0.7444.175-r0fixed 142.0.7444.175-r0
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 133.0.6943.141-r0fixed 133.0.6943.141-r0
Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- affected < 140.0.7339.80-r0fixed 140.0.7339.80-r0
Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- affected < 134.0.6998.35-r0fixed 134.0.6998.35-r0
Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- affected < 136.0.7103.48-r0fixed 136.0.7103.48-r0
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
- affected < 127.0.6533.88-r0fixed 127.0.6533.88-r0
Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a series of curated UI gestures. (Chromium security severity: Medium)
- affected < 124.0.6367.60-r0fixed 124.0.6367.60-r0
Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- affected < 126.0.6478.182-r0fixed 126.0.6478.182-r0
Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- affected < 136.0.7103.59-r0fixed 136.0.7103.59-r0
Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low)
- affected < 128.0.6613.84-r0fixed 128.0.6613.84-r0
Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- affected < 130.0.6723.92-r0fixed 130.0.6723.92-r0
Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- affected < 129.0.6668.58-r0fixed 129.0.6668.58-r0
Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- affected < 142.0.7444.175-r0fixed 142.0.7444.175-r0
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 142.0.7444.137-r0fixed 142.0.7444.137-r0
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- affected < 142.0.7444.137-r0fixed 142.0.7444.137-r0
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- affected < 142.0.7444.137-r0fixed 142.0.7444.137-r0
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 142.0.7444.137-r0fixed 142.0.7444.137-r0
Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
Page 95 of 115