Debian Chromium Update Fixes 16 Security Vulnerabilities

P1 — VALIDATE AND UPDATECVSS: NOT PROVIDEDEXPLOITATION: NOT STATED

Quick Answer

Debian published DSA-6508-1 for Chromium in Debian stable (trixie), addressing 16 CVEs that Debian says could result in arbitrary code execution, denial of service, or information disclosure. Debian fixes the issues in 153.0.8010.52-1~deb13u1 and recommends upgrading the Chromium packages.

Update The Debian Chromium Package

What to do now: Identify Debian trixie endpoints and managed browser images with Chromium, record the installed package and running browser processes, apply Debian's supported update to 153.0.8010.52-1~deb13u1, restart affected browser sessions, and verify the resulting version.

Open the authoritative advisory

Last verified: 2026-09-20 UTC. Recheck the Debian Security Advisory and package repository before changing production.

Scope And Authority

Product scopeChromium in Debian stable (trixie)
AdvisoryDSA-6508-1
CVEsCVE-2026-93372, CVE-2026-93373, CVE-2026-93374, CVE-2026-93375, CVE-2026-93376, CVE-2026-93377, CVE-2026-93378, CVE-2026-93379, CVE-2026-93380, CVE-2026-93381, CVE-2026-93382, CVE-2026-93383, CVE-2026-93384, CVE-2026-93385, CVE-2026-93386, CVE-2026-93387
Authoritative release date2026-09-20 00:03:09 UTC; advisory dated 2026-09-19
Authority revision date2026-09-19
Fixed version153.0.8010.52-1~deb13u1
Authority severityNot provided by the authority
CVSS base scoreNot provided by the authority
CVSS severityNot provided by the authority
Exploitation statusNot stated by Debian; no exploitation claim is inferred.

What Debian Changed

The Debian package update addresses the 16 identifiers listed below. Debian describes the possible outcomes collectively and does not assign a CVSS score, severity, or exploitation status in the cited advisory. This notice preserves those boundaries rather than assigning scores from unrelated records.

What To Validate Now

  1. Inventory. Identify Debian trixie systems, managed browser images, kiosk or automation workloads, and the exact installed Chromium package.
  2. Remediate. Upgrade through approved Debian repositories to 153.0.8010.52-1~deb13u1 or the current supported superseding build.
  3. Restart. Close or restart Chromium processes so running sessions do not continue to use old binaries; coordinate kiosk, VDI, and automated-browser workloads.
  4. Validate. Confirm package and runtime versions, browser launch, enterprise policies, extensions, authentication, certificate handling, and representative web applications.
  5. Preserve. Retain the affected-system list, version evidence, repository transaction, restart evidence, validation results, and documented exceptions.

Operational Cautions

Browser restarts can interrupt active sessions and managed workflows. Coordinate deployment waves, confirm policy and extension compatibility, and verify that offline or rarely connected endpoints receive the supported package. A downloaded package is not proof that every running process has changed.

Evidence To Retain

  • Asset, service, environment, and owner identifiers used for the applicability decision.
  • UTC timestamps and before-and-after package or dependency versions.
  • Change approval, package-manager or build output, validation results, and any exception or rollback record.
  • The authoritative advisory and security-tracker evidence used at the time of the decision.

Related TechGeeks Resources

Authoritative References

Correction policy: If Debian changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.