DSA-6396-1 chromium - security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6396-1
CSIRTS triage
- What
- Security issues in Chromium could lead to arbitrary code execution, denial of service, or information disclosure.
- Who is affected
- Users of Chromium are affected by these vulnerabilities.
- Urgency
- Remediation is urgent due to the potential for severe exploitation.
- Action
- Update to the latest version of Chromium to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chromium
Get an email when a new Chromium advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00307.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-158990.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-159000.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-159010.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-159020.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-159030.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-159040.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-159050.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-164130.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-164140.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all scored CVEs.
- Low exploitation riskCVE-2026-164150.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Google Chrome: Multiple vulnerabilities allow unspecified attackcert-bund
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Microsoft Edge (July 24, 2026)cert-fr-avis
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Google Chrome (July 22, 2026)cert-fr-avis
- criticalCVE-2026-16424: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote att…nvd
- highCVE-2026-16423: Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who co…nvd
- highCVE-2026-16422: Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 1…nvd
- highCVE-2026-16421: Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a re…nvd
- highCVE-2026-16420: Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker …nvd
- criticalCVE-2026-16419: Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allo…nvd
More from Debian Security Advisories
- unknownDSA-6409-1 libgd2 - security update2026-08-01
- unknownDSA-6408-1 chromium - security update2026-07-31
- unknownDSA-6405-1 linux - security update2026-07-31
- unknownDSA-6406-1 php8.4 - security update2026-07-31
- unknownDSA-6407-1 incus - security update2026-07-31