Debian Chromium Update Fixes 16 Security Vulnerabilities
Quick Answer
Debian published DSA-6508-1 for Chromium in Debian stable (trixie), addressing 16 CVEs that Debian says could result in arbitrary code execution, denial of service, or information disclosure. Debian fixes the issues in 153.0.8010.52-1~deb13u1 and recommends upgrading the Chromium packages.
Update The Debian Chromium Package
What to do now: Identify Debian trixie endpoints and managed browser images with Chromium, record the installed package and running browser processes, apply Debian's supported update to 153.0.8010.52-1~deb13u1, restart affected browser sessions, and verify the resulting version.
Last verified: 2026-09-20 UTC. Recheck the Debian Security Advisory and package repository before changing production.
Scope And Authority
| Product scope | Chromium in Debian stable (trixie) |
|---|---|
| Advisory | DSA-6508-1 |
| CVEs | CVE-2026-93372, CVE-2026-93373, CVE-2026-93374, CVE-2026-93375, CVE-2026-93376, CVE-2026-93377, CVE-2026-93378, CVE-2026-93379, CVE-2026-93380, CVE-2026-93381, CVE-2026-93382, CVE-2026-93383, CVE-2026-93384, CVE-2026-93385, CVE-2026-93386, CVE-2026-93387 |
| Authoritative release date | 2026-09-20 00:03:09 UTC; advisory dated 2026-09-19 |
| Authority revision date | 2026-09-19 |
| Fixed version | 153.0.8010.52-1~deb13u1 |
| Authority severity | Not provided by the authority |
| CVSS base score | Not provided by the authority |
| CVSS severity | Not provided by the authority |
| Exploitation status | Not stated by Debian; no exploitation claim is inferred. |
What Debian Changed
The Debian package update addresses the 16 identifiers listed below. Debian describes the possible outcomes collectively and does not assign a CVSS score, severity, or exploitation status in the cited advisory. This notice preserves those boundaries rather than assigning scores from unrelated records.
What To Validate Now
- Inventory. Identify Debian trixie systems, managed browser images, kiosk or automation workloads, and the exact installed Chromium package.
- Remediate. Upgrade through approved Debian repositories to
153.0.8010.52-1~deb13u1or the current supported superseding build. - Restart. Close or restart Chromium processes so running sessions do not continue to use old binaries; coordinate kiosk, VDI, and automated-browser workloads.
- Validate. Confirm package and runtime versions, browser launch, enterprise policies, extensions, authentication, certificate handling, and representative web applications.
- Preserve. Retain the affected-system list, version evidence, repository transaction, restart evidence, validation results, and documented exceptions.
Operational Cautions
Browser restarts can interrupt active sessions and managed workflows. Coordinate deployment waves, confirm policy and extension compatibility, and verify that offline or rarely connected endpoints receive the supported package. A downloaded package is not proof that every running process has changed.
Evidence To Retain
- Asset, service, environment, and owner identifiers used for the applicability decision.
- UTC timestamps and before-and-after package or dependency versions.
- Change approval, package-manager or build output, validation results, and any exception or rollback record.
- The authoritative advisory and security-tracker evidence used at the time of the decision.
Related TechGeeks Resources
Authoritative References
Correction policy: If Debian changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

