Skip to main content
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisory

Debian Issued Multiple Chromium Security Updates

Updated 2mo agoFirst seen Mar 21, 20264 sources

Debian published two separate security advisories for Chromium, identified as DSA-6171-1 and DSA-6177-1, indicating that the browser required repeated package updates to address security issues. The advisories were released through Debian's security announcement channel and point to ongoing remediation work for vulnerabilities affecting the Chromium package in supported Debian environments.

The back-to-back notices suggest administrators should verify that Chromium has been updated to the latest Debian-provided build across desktops, virtual workstations, and any systems where the browser is installed. Because the advisories do not include a public synopsis in the referenced notices, defenders should treat the updates as important browser security fixes and prioritize patch deployment to reduce exposure to web-based compromise.

Share:
Debian Issued Multiple Chromium Security Updates
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 17, 20262mo ago

Debian releases DSA 6214-1 chromium security update

Debian published security advisory DSA 6214-1 for chromium, announcing another security update for the package following the earlier March and April advisories.

[SECURITY] [DSA 6214-1] chromium security update
Apr 3, 20262mo ago

Debian releases DSA 6192-1 chromium security update

Debian published security advisory DSA 6192-1 for chromium, announcing another security update for the package following the March advisories.

[SECURITY] [DSA 6192-1] chromium security update
Mar 25, 20263mo ago

Debian releases DSA 6177-1 chromium security update

Debian published a second chromium security advisory, DSA 6177-1, indicating another security update for the package days after the prior advisory.

Mar 20, 20263mo ago

Debian releases DSA 6171-1 chromium security update

Debian published security advisory DSA 6171-1 for chromium, announcing a security update for the package.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

88 LINKEDOpen in app
Vulnerabilities
86 linked
Type Confusion in Chrome TurbofanUse-after-free in Google Chrome CodecsHeap buffer overflow in PDFium in Google ChromeHeap buffer overflow in Skia in Google ChromeSandbox escape via out-of-bounds write in Chrome GPUUse-after-free in Google Chrome XR on AndroidUse-after-free in Google Chrome for Android PermissionsUse-after-free in Google Chrome CSSUse-after-free in Google Chrome FormsUse-after-free in Google Chrome FileSystemType Confusion in V8 in Google ChromeInsufficient policy enforcement in CORS in Google ChromeUse-after-free in Google Chrome CodecsCross-origin data leak in Google Chrome Passwords policy enforcementSandbox escape in Google Chrome Accessibility on WindowsUse-after-free in Google Chrome CastUse-after-free in Google Chrome Video on WindowsHeap buffer overflow in PDFium in Google ChromeSandbox escape use-after-free in Graphite in Google ChromeUse-after-free in Google Chrome CodecsHeap Buffer Overflow in ANGLE in Google ChromeOut-of-bounds Read in Google Chrome MediaUse-after-free in Google Chrome PrerenderType Confusion in Google Chrome TurbofanHeap Buffer Overflow in PDFium in Google ChromeUse-after-free in Google Chrome ProxyUse-after-free in Google Chrome VideoOut-of-bounds read in Skia in Google ChromeSandbox escape use-after-free in Google Chrome VizUse-after-free in Google Chrome Payments on AndroidSandbox escape use-after-free in Dawn in Google ChromeInteger Overflow in ANGLE in Google ChromeUse-after-free in Google Chrome NetworkInappropriate implementation in V8 in Google ChromeHeap buffer overflow in WebRTC in Google ChromeUse-after-free in Google Chrome Digital Credentials APIHeap Buffer Overflow in Google Chrome WebAudioUse-after-free in Google Chrome BaseOut-of-bounds read in Blink in Google ChromeHeap buffer overflow in CSS in Google ChromeSandbox escape in Google Chrome NavigationUse-after-free in WebRTC in Google ChromeOut-of-bounds read/write in Chrome WebAudioType Confusion in V8 in Google ChromeOut-of-bounds read in Skia in Google ChromeHeap Buffer Overflow in PDFium in Google ChromeUse-after-free in Blink in Google ChromeStack buffer overflow in WebRTC in Google ChromeInappropriate implementation in V8 in Google ChromeOut-of-bounds memory access in WebGL in Google Chrome on AndroidInteger overflow in Dawn in Google ChromeOut-of-bounds write in V8 in Google ChromeHeap buffer overflow in ANGLE in Google ChromeUse-after-free in Google Chrome ExtensionsUse-after-free in WebRTC in Google ChromeInteger overflow in ANGLE in Google ChromeOut-of-bounds read/write in Chrome WebGL ANGLE Vulkan backendOut-of-bounds read in Google Chrome WebAudioUse-after-free in FedCM in Google ChromeOut-of-bounds read in Google Chrome CSSInteger overflow in Google Chrome FontsHeap buffer overflow in Chrome WebGLUse-after-free in Dawn in Google ChromeHeap buffer overflow in Google Chrome WebAudioUse-after-free in Google Chrome WebGPUUse-after-free in Google Chrome DawnUse-after-free in Google Chrome CSSHeap Buffer Overflow in Google Chrome GPUHeap buffer overflow in ANGLE in Google ChromeInteger overflow in ANGLE in Google ChromeUse-after-free in Dawn in Google ChromeInformation disclosure in Google Chrome WebGLInformation disclosure in Google Chrome WebUSB policy enforcementCross-origin data leak in ANGLE in Google ChromeUse-after-free in Google Chrome WebGLUse-after-free in Google Chrome Navigation sandbox escapeUse-after-free in Google Chrome Web MIDI on AndroidUse-after-free in Google Chrome WebCodecsUse-after-free in Google Chrome CompositingObject corruption in V8 in Google ChromeUse-after-free in Dawn in Google ChromeOut-of-bounds read in Google Chrome WebCodecsInteger overflow in Google Chrome CodecsUse-after-free in Google Chrome PDFOut-of-bounds read in Google Chrome WebCodecsUse-after-free in WebView in Google Chrome on Android
Affected products
1 linked
Organizations
1 linked
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.