DSA-6390-1 chromium - security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6390-1
CSIRTS triage
- What
- Security issues in Chromium could result in the execution of arbitrary code, denial of service, or information disclosure.
- Who is affected
- Users of Chromium are affected by these security issues.
- Urgency
- Remediation is urgent due to the potential for arbitrary code execution and denial of service, which are critical security concerns.
- Action
- Apply the latest security update for Chromium to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chromium
Get an email when a new Chromium advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00301.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-157640.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Low exploitation riskCVE-2026-157650.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Low exploitation riskCVE-2026-157660.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-157670.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-157680.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-157690.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-157700.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-157710.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-157720.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-157730.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15764 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15765 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15766 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15767 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15768 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15769 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15770 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15771 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15772 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15773 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15774 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15775 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15776 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15777 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15778 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple Vulnerabilities in Microsoft Edge (July 29, 2026)cert-fr-avis
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Microsoft Edge (July 20, 2026)cert-fr-avis
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Google Chrome (July 15, 2026)cert-fr-avis
- mediumCVE-2026-15778: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.…nvd
- highCVE-2026-15777: Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attack…nvd
- highCVE-2026-15776: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote a…nvd
- mediumCVE-2026-15775: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote a…nvd
- highCVE-2026-15774: Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who …nvd
- criticalCVE-2026-15773: Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote at…nvd
More from Debian Security Advisories
- unknownDSA-6409-1 libgd2 - security update2026-08-01
- unknownDSA-6408-1 chromium - security update2026-07-31
- unknownDSA-6405-1 linux - security update2026-07-31
- unknownDSA-6407-1 incus - security update2026-07-31
- unknownDSA-6406-1 php8.4 - security update2026-07-31