Debian dsa-6171 : chromium - security update

high Nessus Plugin ID 303234

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 12 / 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6171 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6171-1 [email protected] https://www.debian.org/security/ Andres Salomon March 20, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium CVE ID : CVE-2026-4439 CVE-2026-4440 CVE-2026-4441 CVE-2026-4442 CVE-2026-4443 CVE-2026-4444 CVE-2026-4445 CVE-2026-4446 CVE-2026-4447 CVE-2026-4448 CVE-2026-4449 CVE-2026-4450 CVE-2026-4451 CVE-2026-4452 CVE-2026-4453 CVE-2026-4454 CVE-2026-4455 CVE-2026-4456 CVE-2026-4457 CVE-2026-4458 CVE-2026-4459 CVE-2026-4460 CVE-2026-4461 CVE-2026-4462 CVE-2026-4463 CVE-2026-4464

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.153-1~deb12u1.

For the stable distribution (trixie), these problems have been fixed in version 146.0.7680.153-1~deb13u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the chromium packages.

See Also

https://security-tracker.debian.org/tracker/source-package/chromium

https://security-tracker.debian.org/tracker/CVE-2026-4439

https://security-tracker.debian.org/tracker/CVE-2026-4440

https://security-tracker.debian.org/tracker/CVE-2026-4441

https://security-tracker.debian.org/tracker/CVE-2026-4442

https://security-tracker.debian.org/tracker/CVE-2026-4443

https://security-tracker.debian.org/tracker/CVE-2026-4444

https://security-tracker.debian.org/tracker/CVE-2026-4445

https://security-tracker.debian.org/tracker/CVE-2026-4446

https://security-tracker.debian.org/tracker/CVE-2026-4447

https://security-tracker.debian.org/tracker/CVE-2026-4448

https://security-tracker.debian.org/tracker/CVE-2026-4449

https://security-tracker.debian.org/tracker/CVE-2026-4450

https://security-tracker.debian.org/tracker/CVE-2026-4451

https://security-tracker.debian.org/tracker/CVE-2026-4452

https://security-tracker.debian.org/tracker/CVE-2026-4453

https://security-tracker.debian.org/tracker/CVE-2026-4454

https://security-tracker.debian.org/tracker/CVE-2026-4455

https://security-tracker.debian.org/tracker/CVE-2026-4456

https://security-tracker.debian.org/tracker/CVE-2026-4457

https://security-tracker.debian.org/tracker/CVE-2026-4458

https://security-tracker.debian.org/tracker/CVE-2026-4459

https://security-tracker.debian.org/tracker/CVE-2026-4460

https://security-tracker.debian.org/tracker/CVE-2026-4461

https://security-tracker.debian.org/tracker/CVE-2026-4462

https://security-tracker.debian.org/tracker/CVE-2026-4463

https://security-tracker.debian.org/tracker/CVE-2026-4464

https://packages.debian.org/source/bookworm/chromium

https://packages.debian.org/source/trixie/chromium

Plugin Details

Severity: High

ID: 303234

File Name: debian_DSA-6171.nasl

Version: 1.1

Type: local

Agent: unix

Published: 3/20/2026

Updated: 3/20/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-4442

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:chromium-common, p-cpe:/a:debian:debian_linux:chromium-l10n, p-cpe:/a:debian:debian_linux:chromium-shell, p-cpe:/a:debian:debian_linux:chromium, cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:chromium-headless-shell, p-cpe:/a:debian:debian_linux:chromium-sandbox, p-cpe:/a:debian:debian_linux:chromium-driver, cpe:/o:debian:debian_linux:13.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 3/20/2026

Vulnerability Publication Date: 3/18/2026

Reference Information

CVE: CVE-2026-4439, CVE-2026-4440, CVE-2026-4441, CVE-2026-4442, CVE-2026-4443, CVE-2026-4444, CVE-2026-4445, CVE-2026-4446, CVE-2026-4447, CVE-2026-4448, CVE-2026-4449, CVE-2026-4450, CVE-2026-4451, CVE-2026-4452, CVE-2026-4453, CVE-2026-4454, CVE-2026-4455, CVE-2026-4456, CVE-2026-4457, CVE-2026-4458, CVE-2026-4459, CVE-2026-4460, CVE-2026-4461, CVE-2026-4462, CVE-2026-4463, CVE-2026-4464