DSA-6364-1 chromium - security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6364-1
CSIRTS triage
- What
- Security issues in Chromium could allow execution of arbitrary code, denial of service, or information disclosure.
- Who is affected
- Deployments of Chromium are affected.
- Urgency
- Remediation is necessary due to the potential for serious security vulnerabilities.
- Action
- Apply the latest security update for Chromium.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chromium
Get an email when a new Chromium advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00275.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-130210.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130220.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130230.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130240.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130250.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130260.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130270.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130280.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130290.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-130300.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Microsoft Edge (June 29, 2026)cert-fr-avis
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Google Chrome (June 25, 2026)cert-fr-avis
- unknownCVE-2026-13035: Chromium: CVE-2026-13035 Use after free in Bluetoothmsrc
- unknownCVE-2026-13031: Chromium: CVE-2026-13031 Use after free in Blinkmsrc
- unknownCVE-2026-13038: Chromium: CVE-2026-13038 Use after free in Autofillmsrc
- unknownCVE-2026-13025: Chromium: CVE-2026-13025 Insufficient validation of untrusted input in DevToolsmsrc
- unknownCVE-2026-13026: Chromium: CVE-2026-13026 Use after free in Digital Credentialsmsrc
- unknownCVE-2026-13023: Chromium: CVE-2026-13023 Uninitialized Use in GPUmsrc
- unknownCVE-2026-13022: Chromium: CVE-2026-13022 Inappropriate implementation in Autofillmsrc
- unknownCVE-2026-13021: Chromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentialsmsrc
- unknownCVE-2026-13036: Chromium: CVE-2026-13036 Use after free in Blinkmsrc
More from Debian Security Advisories
- unknownDSA-6464-1 erlang - security update2026-08-25
- unknownDSA-6465-1 openssl - security update2026-08-25
- unknownDSA-6466-1 linux - security update2026-08-25
- unknownDSA-6462-1 zfs-linux - security update2026-08-24
- unknownDSA-6463-1 webkit2gtk - security update2026-08-24