DSA-6484-1 chromium - security update
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6484-1
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00395.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-850420.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850430.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850440.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850450.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-85046Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 65% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850470.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850480.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850490.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850500.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850510.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-85042 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85043 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85044 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85045 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85046 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85047 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85048 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85049 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85050 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85051 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85052 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85053 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [hoch] Google Chrome / Microsoft Edge: Mehrere Schwachstellencert-bund
- unknownexploitedCVE-2026-85046: Chromium: CVE-2026-85046 Type confusion in V8msrc
- unknownexploitedGoogle security advisory (AV26-883) – Update 1cccs
- unknownexploitedNCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google Chromencsc-nl
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- unknownexploitedGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownexploitedMultiples vulnérabilités dans Google Chrome (04 septembre 2026)cert-fr-avis
- criticalexploitedCVE-2026-85046: Google Chromium V8 Type Confusion Vulnerabilitycisa-kev
- highCVE-2026-85053: Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a r…nvd
- lowCVE-2026-85052: Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote …nvd
- highCVE-2026-85051: Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacke…nvd
- criticalCVE-2026-85050: Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a r…nvd
More from Debian Security Advisories
- unknownDSA-6491-1 slurm-wlm - security update2026-09-09
- unknownDSA-6489-1 gst-plugins-base1.0 - security update2026-09-08
- unknownDSA-6490-1 fort-validator - security update2026-09-08
- unknownDSA-6488-1 jbig2dec - security update2026-09-07
- unknownDSA-6487-1 strongswan - security update2026-09-07