Debian dsa-6351 : chromium - security update

critical Nessus Plugin ID 321738

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 12 / 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6351 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6351-1 [email protected] https://www.debian.org/security/ Andres Salomon June 18, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium CVE ID : CVE-2026-12437 CVE-2026-12438 CVE-2026-12439 CVE-2026-12440 CVE-2026-12441 CVE-2026-12442 CVE-2026-12443 CVE-2026-12444 CVE-2026-12445 CVE-2026-12446 CVE-2026-12447 CVE-2026-12448 CVE-2026-12449 CVE-2026-12450 CVE-2026-12451 CVE-2026-12452 CVE-2026-12453 CVE-2026-12454 CVE-2026-12455 CVE-2026-12456 CVE-2026-12457 CVE-2026-12458 CVE-2026-12459 CVE-2026-12460 CVE-2026-12461 CVE-2026-12462 CVE-2026-12463 CVE-2026-12464 CVE-2026-12465 CVE-2026-12466 CVE-2026-12467 CVE-2026-12468 CVE-2026-12469

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

For the stable distribution (trixie), these problems have been fixed in version 149.0.7827.155-1~deb13u1.

For the oldstable distribution (bookworm), these problems have been fixed in version 149.0.7827.155-1~deb12u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the chromium packages.

See Also

https://security-tracker.debian.org/tracker/source-package/chromium

https://packages.debian.org/source/bookworm/chromium

https://packages.debian.org/source/trixie/chromium

https://security-tracker.debian.org/tracker/CVE-2026-12437

https://security-tracker.debian.org/tracker/CVE-2026-12438

https://security-tracker.debian.org/tracker/CVE-2026-12439

https://security-tracker.debian.org/tracker/CVE-2026-12443

https://security-tracker.debian.org/tracker/CVE-2026-12444

https://security-tracker.debian.org/tracker/CVE-2026-12445

https://security-tracker.debian.org/tracker/CVE-2026-12446

https://security-tracker.debian.org/tracker/CVE-2026-12447

https://security-tracker.debian.org/tracker/CVE-2026-12448

https://security-tracker.debian.org/tracker/CVE-2026-12449

https://security-tracker.debian.org/tracker/CVE-2026-12450

https://security-tracker.debian.org/tracker/CVE-2026-12452

https://security-tracker.debian.org/tracker/CVE-2026-12453

https://security-tracker.debian.org/tracker/CVE-2026-12454

https://security-tracker.debian.org/tracker/CVE-2026-12456

https://security-tracker.debian.org/tracker/CVE-2026-12457

https://security-tracker.debian.org/tracker/CVE-2026-12458

https://security-tracker.debian.org/tracker/CVE-2026-12459

https://security-tracker.debian.org/tracker/CVE-2026-12460

https://security-tracker.debian.org/tracker/CVE-2026-12461

https://security-tracker.debian.org/tracker/CVE-2026-12463

https://security-tracker.debian.org/tracker/CVE-2026-12464

https://security-tracker.debian.org/tracker/CVE-2026-12465

https://security-tracker.debian.org/tracker/CVE-2026-12466

https://security-tracker.debian.org/tracker/CVE-2026-12468

https://security-tracker.debian.org/tracker/CVE-2026-12469

https://security-tracker.debian.org/tracker/CVE-2026-12440

https://security-tracker.debian.org/tracker/CVE-2026-12441

https://security-tracker.debian.org/tracker/CVE-2026-12442

https://security-tracker.debian.org/tracker/CVE-2026-12451

https://security-tracker.debian.org/tracker/CVE-2026-12455

https://security-tracker.debian.org/tracker/CVE-2026-12462

https://security-tracker.debian.org/tracker/CVE-2026-12467

Plugin Details

Severity: Critical

ID: 321738

File Name: debian_DSA-6351.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 6/20/2026

Updated: 6/20/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-12466

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-12440

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:chromium-common, p-cpe:/a:debian:debian_linux:chromium-l10n, p-cpe:/a:debian:debian_linux:chromium-shell, p-cpe:/a:debian:debian_linux:chromium, cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:chromium-headless-shell, p-cpe:/a:debian:debian_linux:chromium-sandbox, p-cpe:/a:debian:debian_linux:chromium-driver

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 6/18/2026

Vulnerability Publication Date: 6/15/2026

Reference Information

CVE: CVE-2026-12437, CVE-2026-12438, CVE-2026-12439, CVE-2026-12440, CVE-2026-12441, CVE-2026-12442, CVE-2026-12443, CVE-2026-12444, CVE-2026-12445, CVE-2026-12446, CVE-2026-12447, CVE-2026-12448, CVE-2026-12449, CVE-2026-12450, CVE-2026-12451, CVE-2026-12452, CVE-2026-12453, CVE-2026-12454, CVE-2026-12455, CVE-2026-12456, CVE-2026-12457, CVE-2026-12458, CVE-2026-12459, CVE-2026-12460, CVE-2026-12461, CVE-2026-12462, CVE-2026-12463, CVE-2026-12464, CVE-2026-12465, CVE-2026-12466, CVE-2026-12467, CVE-2026-12468, CVE-2026-12469