Debian dsa-6513 : chromium - security update

high Nessus Plugin ID 350697

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6513 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6513-1 [email protected] https://www.debian.org/security/ Andres Salomon September 25, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium CVE ID : CVE-2026-95274 CVE-2026-95275 CVE-2026-95276 CVE-2026-95277 CVE-2026-95278 CVE-2026-95279 CVE-2026-95280 CVE-2026-95281 CVE-2026-95282 CVE-2026-95283 CVE-2026-95284 CVE-2026-95285 CVE-2026-95286 CVE-2026-95287 CVE-2026-95288 CVE-2026-95289 CVE-2026-95290 CVE-2026-95291 CVE-2026-95292 CVE-2026-95293 CVE-2026-95294 CVE-2026-95295 CVE-2026-95296 CVE-2026-95297 CVE-2026-95298 CVE-2026-95299 CVE-2026-95300 CVE-2026-95301 CVE-2026-95302 CVE-2026-95303 CVE-2026-95304 CVE-2026-95305 CVE-2026-95306 CVE-2026-95307 CVE-2026-95308 CVE-2026-95309 CVE-2026-95310 CVE-2026-95311 CVE-2026-95312 CVE-2026-95313 CVE-2026-95314 CVE-2026-95315 CVE-2026-95316 CVE-2026-95317 CVE-2026-95318 CVE-2026-95319 CVE-2026-95320 CVE-2026-95321 CVE-2026-95322 CVE-2026-95323 CVE-2026-95324 CVE-2026-95325 CVE-2026-95326 CVE-2026-95327 CVE-2026-95328 CVE-2026-95329 CVE-2026-95330 CVE-2026-95331 CVE-2026-95332 CVE-2026-95333 CVE-2026-95334 CVE-2026-95335 CVE-2026-95336 CVE-2026-95337 CVE-2026-95338 CVE-2026-95339 CVE-2026-95340 CVE-2026-95341 CVE-2026-95342 CVE-2026-95343 CVE-2026-95344 CVE-2026-95345 CVE-2026-95346 CVE-2026-95347 CVE-2026-95348 CVE-2026-95349 CVE-2026-95350 CVE-2026-95351 CVE-2026-95352 CVE-2026-95353 CVE-2026-95354 CVE-2026-95355 CVE-2026-95356 CVE-2026-95357 CVE-2026-95358 CVE-2026-95359 CVE-2026-95360 CVE-2026-95361 CVE-2026-95362 CVE-2026-95363 CVE-2026-95364 CVE-2026-95365 CVE-2026-95366 CVE-2026-95367 CVE-2026-95368 CVE-2026-95369 CVE-2026-95370 CVE-2026-95371 CVE-2026-95372 CVE-2026-95373 CVE-2026-95374 CVE-2026-95375 CVE-2026-95376 CVE-2026-95380 CVE-2026-95381 CVE-2026-95382 CVE-2026-95384 CVE-2026-95385

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

For the stable distribution (trixie), these problems have been fixed in version 154.0.8037.57-1~deb13u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the chromium packages.

See Also

https://packages.debian.org/source/trixie/chromium

https://security-tracker.debian.org/tracker/CVE-2026-95274

https://security-tracker.debian.org/tracker/CVE-2026-95275

https://security-tracker.debian.org/tracker/CVE-2026-95276

https://security-tracker.debian.org/tracker/CVE-2026-95277

https://security-tracker.debian.org/tracker/CVE-2026-95278

https://security-tracker.debian.org/tracker/CVE-2026-95279

https://security-tracker.debian.org/tracker/CVE-2026-95280

https://security-tracker.debian.org/tracker/CVE-2026-95281

https://security-tracker.debian.org/tracker/CVE-2026-95282

https://security-tracker.debian.org/tracker/CVE-2026-95283

https://security-tracker.debian.org/tracker/CVE-2026-95284

https://security-tracker.debian.org/tracker/CVE-2026-95285

https://security-tracker.debian.org/tracker/CVE-2026-95286

https://security-tracker.debian.org/tracker/CVE-2026-95287

https://security-tracker.debian.org/tracker/CVE-2026-95288

https://security-tracker.debian.org/tracker/CVE-2026-95289

https://security-tracker.debian.org/tracker/CVE-2026-95290

https://security-tracker.debian.org/tracker/CVE-2026-95291

https://security-tracker.debian.org/tracker/CVE-2026-95292

https://security-tracker.debian.org/tracker/CVE-2026-95293

https://security-tracker.debian.org/tracker/CVE-2026-95294

https://security-tracker.debian.org/tracker/CVE-2026-95295

https://security-tracker.debian.org/tracker/CVE-2026-95296

https://security-tracker.debian.org/tracker/CVE-2026-95297

https://security-tracker.debian.org/tracker/CVE-2026-95298

https://security-tracker.debian.org/tracker/CVE-2026-95299

https://security-tracker.debian.org/tracker/CVE-2026-95300

https://security-tracker.debian.org/tracker/CVE-2026-95301

https://security-tracker.debian.org/tracker/CVE-2026-95302

https://security-tracker.debian.org/tracker/CVE-2026-95303

https://security-tracker.debian.org/tracker/CVE-2026-95304

https://security-tracker.debian.org/tracker/CVE-2026-95305

https://security-tracker.debian.org/tracker/CVE-2026-95306

https://security-tracker.debian.org/tracker/CVE-2026-95307

https://security-tracker.debian.org/tracker/CVE-2026-95308

https://security-tracker.debian.org/tracker/CVE-2026-95309

https://security-tracker.debian.org/tracker/CVE-2026-95310

https://security-tracker.debian.org/tracker/CVE-2026-95311

https://security-tracker.debian.org/tracker/CVE-2026-95312

https://security-tracker.debian.org/tracker/CVE-2026-95313

https://security-tracker.debian.org/tracker/CVE-2026-95314

https://security-tracker.debian.org/tracker/CVE-2026-95315

https://security-tracker.debian.org/tracker/CVE-2026-95316

https://security-tracker.debian.org/tracker/CVE-2026-95317

https://security-tracker.debian.org/tracker/CVE-2026-95318

https://security-tracker.debian.org/tracker/CVE-2026-95319

https://security-tracker.debian.org/tracker/CVE-2026-95320

https://security-tracker.debian.org/tracker/CVE-2026-95321

https://security-tracker.debian.org/tracker/CVE-2026-95322

https://security-tracker.debian.org/tracker/CVE-2026-95323

https://security-tracker.debian.org/tracker/CVE-2026-95324

https://security-tracker.debian.org/tracker/CVE-2026-95325

https://security-tracker.debian.org/tracker/CVE-2026-95326

https://security-tracker.debian.org/tracker/CVE-2026-95327

https://security-tracker.debian.org/tracker/CVE-2026-95328

https://security-tracker.debian.org/tracker/CVE-2026-95329

https://security-tracker.debian.org/tracker/CVE-2026-95330

https://security-tracker.debian.org/tracker/CVE-2026-95331

https://security-tracker.debian.org/tracker/CVE-2026-95332

https://security-tracker.debian.org/tracker/CVE-2026-95333

https://security-tracker.debian.org/tracker/CVE-2026-95334

https://security-tracker.debian.org/tracker/CVE-2026-95335

https://security-tracker.debian.org/tracker/CVE-2026-95336

https://security-tracker.debian.org/tracker/CVE-2026-95337

https://security-tracker.debian.org/tracker/CVE-2026-95338

https://security-tracker.debian.org/tracker/CVE-2026-95339

https://security-tracker.debian.org/tracker/CVE-2026-95340

https://security-tracker.debian.org/tracker/CVE-2026-95341

https://security-tracker.debian.org/tracker/CVE-2026-95342

https://security-tracker.debian.org/tracker/CVE-2026-95343

https://security-tracker.debian.org/tracker/CVE-2026-95344

https://security-tracker.debian.org/tracker/CVE-2026-95345

https://security-tracker.debian.org/tracker/CVE-2026-95346

https://security-tracker.debian.org/tracker/CVE-2026-95347

https://security-tracker.debian.org/tracker/CVE-2026-95348

https://security-tracker.debian.org/tracker/CVE-2026-95349

https://security-tracker.debian.org/tracker/CVE-2026-95350

https://security-tracker.debian.org/tracker/CVE-2026-95351

https://security-tracker.debian.org/tracker/CVE-2026-95352

https://security-tracker.debian.org/tracker/CVE-2026-95353

https://security-tracker.debian.org/tracker/CVE-2026-95354

https://security-tracker.debian.org/tracker/CVE-2026-95355

https://security-tracker.debian.org/tracker/CVE-2026-95356

https://security-tracker.debian.org/tracker/CVE-2026-95357

https://security-tracker.debian.org/tracker/CVE-2026-95358

https://security-tracker.debian.org/tracker/CVE-2026-95359

https://security-tracker.debian.org/tracker/CVE-2026-95360

https://security-tracker.debian.org/tracker/CVE-2026-95361

https://security-tracker.debian.org/tracker/CVE-2026-95362

https://security-tracker.debian.org/tracker/CVE-2026-95363

https://security-tracker.debian.org/tracker/CVE-2026-95364

https://security-tracker.debian.org/tracker/CVE-2026-95365

https://security-tracker.debian.org/tracker/CVE-2026-95366

https://security-tracker.debian.org/tracker/CVE-2026-95367

https://security-tracker.debian.org/tracker/CVE-2026-95368

https://security-tracker.debian.org/tracker/CVE-2026-95369

https://security-tracker.debian.org/tracker/CVE-2026-95370

https://security-tracker.debian.org/tracker/CVE-2026-95371

https://security-tracker.debian.org/tracker/CVE-2026-95372

https://security-tracker.debian.org/tracker/CVE-2026-95373

https://security-tracker.debian.org/tracker/CVE-2026-95374

https://security-tracker.debian.org/tracker/CVE-2026-95375

https://security-tracker.debian.org/tracker/CVE-2026-95376

https://security-tracker.debian.org/tracker/CVE-2026-95380

https://security-tracker.debian.org/tracker/CVE-2026-95381

https://security-tracker.debian.org/tracker/CVE-2026-95382

https://security-tracker.debian.org/tracker/CVE-2026-95384

https://security-tracker.debian.org/tracker/CVE-2026-95385

https://security-tracker.debian.org/tracker/source-package/chromium

Plugin Details

Severity: High

ID: 350697

File Name: debian_DSA-6513.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/25/2026

Updated: 9/25/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.51

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-95362

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:chromium-common, p-cpe:/a:debian:debian_linux:chromium-driver, p-cpe:/a:debian:debian_linux:chromium-headless-shell, p-cpe:/a:debian:debian_linux:chromium-l10n, p-cpe:/a:debian:debian_linux:chromium-sandbox, p-cpe:/a:debian:debian_linux:chromium-shell, p-cpe:/a:debian:debian_linux:chromium

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 9/25/2026

Vulnerability Publication Date: 9/22/2026

Reference Information

CVE: CVE-2026-95274, CVE-2026-95275, CVE-2026-95276, CVE-2026-95277, CVE-2026-95278, CVE-2026-95279, CVE-2026-95280, CVE-2026-95281, CVE-2026-95282, CVE-2026-95283, CVE-2026-95284, CVE-2026-95285, CVE-2026-95286, CVE-2026-95287, CVE-2026-95288, CVE-2026-95289, CVE-2026-95290, CVE-2026-95291, CVE-2026-95292, CVE-2026-95293, CVE-2026-95294, CVE-2026-95295, CVE-2026-95296, CVE-2026-95297, CVE-2026-95298, CVE-2026-95299, CVE-2026-95300, CVE-2026-95301, CVE-2026-95302, CVE-2026-95303, CVE-2026-95304, CVE-2026-95305, CVE-2026-95306, CVE-2026-95307, CVE-2026-95308, CVE-2026-95309, CVE-2026-95310, CVE-2026-95311, CVE-2026-95312, CVE-2026-95313, CVE-2026-95314, CVE-2026-95315, CVE-2026-95316, CVE-2026-95317, CVE-2026-95318, CVE-2026-95319, CVE-2026-95320, CVE-2026-95321, CVE-2026-95322, CVE-2026-95323, CVE-2026-95324, CVE-2026-95325, CVE-2026-95326, CVE-2026-95327, CVE-2026-95328, CVE-2026-95329, CVE-2026-95330, CVE-2026-95331, CVE-2026-95332, CVE-2026-95333, CVE-2026-95334, CVE-2026-95335, CVE-2026-95336, CVE-2026-95337, CVE-2026-95338, CVE-2026-95339, CVE-2026-95340, CVE-2026-95341, CVE-2026-95342, CVE-2026-95343, CVE-2026-95344, CVE-2026-95345, CVE-2026-95346, CVE-2026-95347, CVE-2026-95348, CVE-2026-95349, CVE-2026-95350, CVE-2026-95351, CVE-2026-95352, CVE-2026-95353, CVE-2026-95354, CVE-2026-95355, CVE-2026-95356, CVE-2026-95357, CVE-2026-95358, CVE-2026-95359, CVE-2026-95360, CVE-2026-95361, CVE-2026-95362, CVE-2026-95363, CVE-2026-95364, CVE-2026-95365, CVE-2026-95366, CVE-2026-95367, CVE-2026-95368, CVE-2026-95369, CVE-2026-95370, CVE-2026-95371, CVE-2026-95372, CVE-2026-95373, CVE-2026-95374, CVE-2026-95375, CVE-2026-95376, CVE-2026-95380, CVE-2026-95381, CVE-2026-95382, CVE-2026-95384, CVE-2026-95385