#1145043 chromium: 11 unresolved CVEs in Debian Trixie (2 Critical, 9 High)

Package:
chromium
Source:
chromium
Description:
web browser
Submitter:
Prasad, Ayush
Date:
2026-08-22 08:49:02 UTC
Severity:
normal
Tags:
#1145043#5
Date:
2026-08-21 17:47:24 UTC
From:
To:
Hi Team,

I am reporting 11 unresolved CVEs affecting the chromium, chromium-common, and chromium-sandbox packages on Debian Trixie (Debian 13), identified via a container image security scan (Prisma).

#1145043#10
Date:
2026-08-22 00:32:10 UTC
From:
To:
Hi,

These bugs are already fixed in Debian 13. If your company needs further
assistance in identifying and managing chromium security issues, I'm
happy to send over my consulting rate and discuss how many hours of work
you'll need.

Thanks,
Andres

#1145043#15
Date:
2026-08-22 08:31:05 UTC
From:
To:
I'd say in great many cases auto tools report false positives. Maybe 80% in my experience....
21 August 2026, 20:49:09, by "Prasad, Ayush" <ayush.a.prasad@accenture.com>:
Package: chromium
Version: <output of: apt-cache policy chromium | grep Installed>
Severity: grave
Tags: security
Hi Team,
I am reporting 11 unresolved CVEs affecting the chromium, chromium-common, and chromium-sandbox packages on Debian Trixie (Debian 13), identified via a container image security scan (Prisma).
-- CVE Details --
Critical:
- CVE-2026-76035
- CVE-2026-76036
High:
- CVE-2026-76034
- CVE-2026-76037
- CVE-2026-76038
- CVE-2026-76040
- CVE-2026-76043
- CVE-2026-76044
- CVE-2026-76045
- CVE-2026-76046
- CVE-2026-76047
Base Image: debian:trixie
Affected Packages: chromium, chromium-common, chromium-sandbox
Installation Method: apt-get install chromium
Scan Tool: Prisma (container image layer scan)
Please advise on the availability of patched versions of the above packages in Debian Trixie's apt repository, and the expected timeline for patch inclusion if not yet available.
Thanks & Regards,
Ayush Prasad
Software Prod & Plat Eng Team Lead
NEU Life Sciences – Product Engineering
Advanced Technology Centres India (ATCI)
Mobile +91 9123774187
This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security, AI-powered support capabilities, and assessment of internal compliance with Accenture policy. Your privacy is important to us. Accenture uses your personal data only in compliance with data protection laws. For further information on how Accenture processes your personal data, please see our privacy statement at https://www.accenture.com/us-en/privacy-policy. ______________________________________________________________________________________
www.accenture.com

#1145043#20
Date:
2026-08-22 08:31:05 UTC
From:
To:
I'd say in great many cases auto tools report false positives. Maybe 80% in my experience....
21 August 2026, 20:49:09, by "Prasad, Ayush" <ayush.a.prasad@accenture.com>:
Package: chromium
Version: <output of: apt-cache policy chromium | grep Installed>
Severity: grave
Tags: security
Hi Team,
I am reporting 11 unresolved CVEs affecting the chromium, chromium-common, and chromium-sandbox packages on Debian Trixie (Debian 13), identified via a container image security scan (Prisma).
-- CVE Details --
Critical:
- CVE-2026-76035
- CVE-2026-76036
High:
- CVE-2026-76034
- CVE-2026-76037
- CVE-2026-76038
- CVE-2026-76040
- CVE-2026-76043
- CVE-2026-76044
- CVE-2026-76045
- CVE-2026-76046
- CVE-2026-76047
Base Image: debian:trixie
Affected Packages: chromium, chromium-common, chromium-sandbox
Installation Method: apt-get install chromium
Scan Tool: Prisma (container image layer scan)
Please advise on the availability of patched versions of the above packages in Debian Trixie's apt repository, and the expected timeline for patch inclusion if not yet available.
Thanks & Regards,
Ayush Prasad
Software Prod & Plat Eng Team Lead
NEU Life Sciences – Product Engineering
Advanced Technology Centres India (ATCI)
Mobile +91 9123774187
This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security, AI-powered support capabilities, and assessment of internal compliance with Accenture policy. Your privacy is important to us. Accenture uses your personal data only in compliance with data protection laws. For further information on how Accenture processes your personal data, please see our privacy statement at https://www.accenture.com/us-en/privacy-policy. ______________________________________________________________________________________
www.accenture.com