Debian dsa-6508 : chromium - security update

critical Nessus Plugin ID 348573

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6508 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6508-1 [email protected] https://www.debian.org/security/ Andres Salomon September 19, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium CVE ID : CVE-2026-93372 CVE-2026-93373 CVE-2026-93374 CVE-2026-93375 CVE-2026-93376 CVE-2026-93377 CVE-2026-93378 CVE-2026-93379 CVE-2026-93380 CVE-2026-93381 CVE-2026-93382 CVE-2026-93383 CVE-2026-93384 CVE-2026-93385 CVE-2026-93386 CVE-2026-93387

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

For the stable distribution (trixie), these problems have been fixed in version 153.0.8010.52-1~deb13u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the chromium packages.

See Also

https://packages.debian.org/source/trixie/chromium

https://security-tracker.debian.org/tracker/CVE-2026-93372

https://security-tracker.debian.org/tracker/CVE-2026-93373

https://security-tracker.debian.org/tracker/CVE-2026-93374

https://security-tracker.debian.org/tracker/CVE-2026-93375

https://security-tracker.debian.org/tracker/CVE-2026-93376

https://security-tracker.debian.org/tracker/CVE-2026-93377

https://security-tracker.debian.org/tracker/CVE-2026-93378

https://security-tracker.debian.org/tracker/CVE-2026-93379

https://security-tracker.debian.org/tracker/CVE-2026-93380

https://security-tracker.debian.org/tracker/CVE-2026-93381

https://security-tracker.debian.org/tracker/CVE-2026-93382

https://security-tracker.debian.org/tracker/CVE-2026-93383

https://security-tracker.debian.org/tracker/CVE-2026-93384

https://security-tracker.debian.org/tracker/CVE-2026-93385

https://security-tracker.debian.org/tracker/CVE-2026-93386

https://security-tracker.debian.org/tracker/CVE-2026-93387

https://security-tracker.debian.org/tracker/source-package/chromium

Plugin Details

Severity: Critical

ID: 348573

File Name: debian_DSA-6508.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/21/2026

Updated: 9/21/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.3

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-93382

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-93374

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:chromium-common, p-cpe:/a:debian:debian_linux:chromium-driver, p-cpe:/a:debian:debian_linux:chromium-headless-shell, p-cpe:/a:debian:debian_linux:chromium-l10n, p-cpe:/a:debian:debian_linux:chromium-sandbox, p-cpe:/a:debian:debian_linux:chromium-shell, p-cpe:/a:debian:debian_linux:chromium

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 9/19/2026

Vulnerability Publication Date: 9/17/2026

Reference Information

CVE: CVE-2026-93372, CVE-2026-93373, CVE-2026-93374, CVE-2026-93375, CVE-2026-93376, CVE-2026-93377, CVE-2026-93378, CVE-2026-93379, CVE-2026-93380, CVE-2026-93381, CVE-2026-93382, CVE-2026-93383, CVE-2026-93384, CVE-2026-93385, CVE-2026-93386, CVE-2026-93387