DSA-6408-1 chromium - security update
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6408-1
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00319.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-168040.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-168050.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-168060.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-168070.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-176500.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-176510.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-176520.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-176530.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-176540.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
- Low exploitation riskCVE-2026-176550.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- highCVE-2026-17705: Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker t…nvd
- criticalCVE-2026-17704: Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who …nvd
- mediumCVE-2026-17703: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.…nvd
- lowCVE-2026-17702: Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote …nvd
- criticalCVE-2026-17701: Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.792…nvd
- mediumCVE-2026-17700: Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 al…nvd
- highCVE-2026-17699: Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to po…nvd
- highCVE-2026-17698: Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.79…nvd
- criticalCVE-2026-17697: Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to p…nvd
- mediumCVE-2026-17696: Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a re…nvd
More from Debian Security Advisories
- unknownDSA-6409-1 libgd2 - security update2026-08-01
- unknownDSA-6405-1 linux - security update2026-07-31
- unknownDSA-6406-1 php8.4 - security update2026-07-31
- unknownDSA-6407-1 incus - security update2026-07-31
- unknownDSA-6404-1 expat - security update2026-07-30