Debian dsa-6422 : chromium - security update

critical Nessus Plugin ID 333540

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6422 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6422-1 [email protected] https://www.debian.org/security/ Andres Salomon August 08, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium CVE ID : CVE-2026-19137 CVE-2026-19138 CVE-2026-19139 CVE-2026-19140 CVE-2026-19141 CVE-2026-19142 CVE-2026-19143 CVE-2026-19144 CVE-2026-19145 CVE-2026-19146 CVE-2026-19147 CVE-2026-19148 CVE-2026-19149 CVE-2026-19150 CVE-2026-19151 CVE-2026-19152 CVE-2026-19153 CVE-2026-19154 CVE-2026-19155 CVE-2026-19156 CVE-2026-19157 CVE-2026-19158 CVE-2026-19159 CVE-2026-19160 CVE-2026-19161 CVE-2026-19162 CVE-2026-19163 CVE-2026-19164 CVE-2026-19165 CVE-2026-19166 CVE-2026-19167 CVE-2026-19168 CVE-2026-19169 CVE-2026-19170 CVE-2026-19171 CVE-2026-19172 CVE-2026-19173 CVE-2026-19174 CVE-2026-19175 CVE-2026-19176 CVE-2026-19177

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

For the stable distribution (trixie), these problems have been fixed in version 151.0.7922.108-1~deb13u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the chromium packages.

See Also

https://packages.debian.org/source/trixie/chromium

https://security-tracker.debian.org/tracker/CVE-2026-19137

https://security-tracker.debian.org/tracker/CVE-2026-19138

https://security-tracker.debian.org/tracker/CVE-2026-19139

https://security-tracker.debian.org/tracker/CVE-2026-19140

https://security-tracker.debian.org/tracker/CVE-2026-19141

https://security-tracker.debian.org/tracker/CVE-2026-19142

https://security-tracker.debian.org/tracker/CVE-2026-19143

https://security-tracker.debian.org/tracker/CVE-2026-19144

https://security-tracker.debian.org/tracker/CVE-2026-19145

https://security-tracker.debian.org/tracker/CVE-2026-19146

https://security-tracker.debian.org/tracker/CVE-2026-19147

https://security-tracker.debian.org/tracker/CVE-2026-19148

https://security-tracker.debian.org/tracker/CVE-2026-19149

https://security-tracker.debian.org/tracker/CVE-2026-19150

https://security-tracker.debian.org/tracker/CVE-2026-19151

https://security-tracker.debian.org/tracker/CVE-2026-19152

https://security-tracker.debian.org/tracker/CVE-2026-19153

https://security-tracker.debian.org/tracker/CVE-2026-19154

https://security-tracker.debian.org/tracker/CVE-2026-19155

https://security-tracker.debian.org/tracker/CVE-2026-19156

https://security-tracker.debian.org/tracker/CVE-2026-19157

https://security-tracker.debian.org/tracker/CVE-2026-19158

https://security-tracker.debian.org/tracker/CVE-2026-19159

https://security-tracker.debian.org/tracker/CVE-2026-19160

https://security-tracker.debian.org/tracker/CVE-2026-19161

https://security-tracker.debian.org/tracker/CVE-2026-19162

https://security-tracker.debian.org/tracker/CVE-2026-19163

https://security-tracker.debian.org/tracker/CVE-2026-19164

https://security-tracker.debian.org/tracker/CVE-2026-19165

https://security-tracker.debian.org/tracker/CVE-2026-19166

https://security-tracker.debian.org/tracker/CVE-2026-19167

https://security-tracker.debian.org/tracker/CVE-2026-19168

https://security-tracker.debian.org/tracker/CVE-2026-19169

https://security-tracker.debian.org/tracker/CVE-2026-19170

https://security-tracker.debian.org/tracker/CVE-2026-19171

https://security-tracker.debian.org/tracker/CVE-2026-19172

https://security-tracker.debian.org/tracker/CVE-2026-19173

https://security-tracker.debian.org/tracker/CVE-2026-19174

https://security-tracker.debian.org/tracker/CVE-2026-19175

https://security-tracker.debian.org/tracker/CVE-2026-19176

https://security-tracker.debian.org/tracker/CVE-2026-19177

https://security-tracker.debian.org/tracker/source-package/chromium

Plugin Details

Severity: Critical

ID: 333540

File Name: debian_DSA-6422.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/9/2026

Updated: 8/9/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.89

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-19175

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:chromium-common, p-cpe:/a:debian:debian_linux:chromium-driver, p-cpe:/a:debian:debian_linux:chromium-headless-shell, p-cpe:/a:debian:debian_linux:chromium-l10n, p-cpe:/a:debian:debian_linux:chromium-sandbox, p-cpe:/a:debian:debian_linux:chromium-shell, p-cpe:/a:debian:debian_linux:chromium

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 8/8/2026

Vulnerability Publication Date: 8/6/2026

Reference Information

CVE: CVE-2026-19137, CVE-2026-19138, CVE-2026-19139, CVE-2026-19140, CVE-2026-19141, CVE-2026-19142, CVE-2026-19143, CVE-2026-19144, CVE-2026-19145, CVE-2026-19146, CVE-2026-19147, CVE-2026-19148, CVE-2026-19149, CVE-2026-19150, CVE-2026-19151, CVE-2026-19152, CVE-2026-19153, CVE-2026-19154, CVE-2026-19155, CVE-2026-19156, CVE-2026-19157, CVE-2026-19158, CVE-2026-19159, CVE-2026-19160, CVE-2026-19161, CVE-2026-19162, CVE-2026-19163, CVE-2026-19164, CVE-2026-19165, CVE-2026-19166, CVE-2026-19167, CVE-2026-19168, CVE-2026-19169, CVE-2026-19170, CVE-2026-19171, CVE-2026-19172, CVE-2026-19173, CVE-2026-19174, CVE-2026-19175, CVE-2026-19176, CVE-2026-19177