DSA-6387-1 chromium - security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6387-1
CSIRTS triage
- What
- Security issues could result in the execution of arbitrary code, denial of service, or information disclosure.
- Who is affected
- Deployments of Chromium are affected.
- Urgency
- Remediation is urgent due to the potential for arbitrary code execution and denial of service.
- Action
- Apply the latest security update for Chromium.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chromium
Get an email when a new Chromium advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00298.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-151070.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-151080.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-151090.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-151100.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-151110.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-151120.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-151130.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all scored CVEs.
- Low exploitation riskCVE-2026-151140.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
- Low exploitation riskCVE-2026-151150.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-151160.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- unknownMultiple Vulnerabilities in Microsoft Edge (July 29, 2026)cert-fr-avis
- unknownCVE-2026-15110: Chromium: CVE-2026-15110 Use after free in Extensionsmsrc
- unknownCVE-2026-15123: Chromium: CVE-2026-15123 Insufficient data validation in DOMmsrc
- unknownCVE-2026-15132: Chromium: CVE-2026-15132 Uninitialized Use in V8msrc
- unknownCVE-2026-15127: Chromium: CVE-2026-15127 Inappropriate implementation in WebGLmsrc
- unknownCVE-2026-15107: Chromium: CVE-2026-15107 Use after free in IndexedDBmsrc
- unknownCVE-2026-15126: Chromium: CVE-2026-15126 Use after free in Formsmsrc
- unknownCVE-2026-15121: Chromium: CVE-2026-15121 Use after free in WebRTCmsrc
- unknownCVE-2026-15122: Chromium: CVE-2026-15122 Insufficient validation of untrusted input in Codecsmsrc
- unknownCVE-2026-15116: Chromium: CVE-2026-15116 Use after free in Actormsrc
- unknownCVE-2026-15112: Chromium: CVE-2026-15112 Use after free in Ozonemsrc
More from Debian Security Advisories
- unknownDSA-6409-1 libgd2 - security update2026-08-01
- unknownDSA-6408-1 chromium - security update2026-07-31
- unknownDSA-6405-1 linux - security update2026-07-31
- unknownDSA-6407-1 incus - security update2026-07-31
- unknownDSA-6406-1 php8.4 - security update2026-07-31