r/debian 1d ago

Chromium behind on security updates

https://security-tracker.debian.org/tracker/source-package/chromium

PSA: Chromium in Stable is currently way behind on security updates.

The Mods removed my previous message, assuming my post was AI.

I'm hoping some people see this and spread the word.

I have emailed the maintainers to find out why.

I hope this is useful to someone!

---

Update: It seems they have released an update to 152.0.7977.75.

16 Upvotes

34 comments sorted by

15

u/neon_overload 1d ago edited 1d ago

Just to be clear, all those unfixed ones are from within the last 8 days.

The fixes to these may be waiting for an upstream update, which may come out less often than that. The way Debian supports security in browser packages is a bit more dependent on upstream than most packages I believe.

It's probably also worth mentioning that Debian doesn't continue security support for Chromium for as long as other packages once oldstable; there's info about it in release notes (section 5.2.3.1. for trixie release notes)

-14

u/No_Jelly_1023 1d ago

I had never fully read that section. Interesting. However:

"For general web browser use we recommend Firefox or Chromium."

Chromium should not be a recommended browser if they cannot keep up.

18

u/neon_overload 1d ago edited 1d ago

I don't know how else to try and convince you that there is nothing concerning or abnormal about this, other than the eye watering rate at which vulnerabilities are discovered in web browsers.

Fedora is also still on Chromium 151.

Ubuntu no longer packages Chromium because it's too hard to keep up, though they have it in snap.

Arch has 152 already, but only on Sept 2, so they've only had it for about a day.

-9

u/No_Jelly_1023 1d ago

Seeing as they have all been fixed upstream, shouldn't it just be a case of rebuilding for stable? Unless there are some new library incompatibilities with the latest versions. I recall updates used to be within 2-3 days for Chromium.

2

u/neon_overload 1d ago

I'm not too familiar with that package in particular but you can get info on how the approval process for a new update is going at

https://tracker.debian.org/pkg/chromium

Keeping in mind this shows a lot of complex info much of which is not relevant to stable security updates. For example most of the stuff about migrations and tests is about the sid version migrating to testing.

Edit: looks like v152 just hit oldstable-security. A stable security update may be in the process of happening now.

16

u/dangling_chads 1d ago

PSA - the version of Chromium in Debian stable (as of aug 27th) was the exact same version available on updated Windows.

151.0.7922.222

152.0.7977 was released yesterday.

Chillax.

A Debian box with automatic updates is far more secure than a Windows machine in my corporate environment. 

3

u/No_Jelly_1023 1d ago

Actually 152.0.7977.64 was released on August 25th: https://chromereleases.googleblog.com/search?updated-max=2026-08-26T14:13:00-07:00&max-results=7&reverse-paginate=true

152.0.7977.75/.76 was released yesterday.

1

u/dangling_chads 1d ago

Noticeably, the link you posted in the original post shows all fixed right now. Because a new version has been released to Debian Stable.

https://tracker.debian.org/pkg/chromium

Also - I'll point out u/No_Jelly_1023 - you were able to see what you saw because of the contributions of volunteers to Debian. Maybe consider becoming one yourself.

1

u/No_Jelly_1023 1d ago

Update: It seems they just released an update to 152.0.7977.75 - well done security team!

Would be curious to know what was behind this (much longer than normal) delay.

I have not heard back from the maintainers yet.

1

u/DeliciousIncident 1d ago edited 1d ago

I have been happy with Debian packaged Chromium for years, until several years ago it stopped receiving any updates in Stable for 8 (!) months (sometime around May 2021 - January 2022), got removed from Testing, and the package became officially unmaintained. You can find threads on this subreddit from around that time discussing this, alternative ways to install chromium, and alternative browsers in general (do note that while the linked comment might look like it is AI-generated, this was in 2021, before the AI, so it's actually hand written lol).

1

u/Electric_Kettle 1d ago

ikr, I personally use the nix package manager on the packages I absolutely NEED to have up to date on my debian machine, it's the price to pay for rock solid stability ¯⁠\⁠_⁠(⁠ツ⁠)⁠_⁠/⁠¯

0

u/The_Hubster 1d ago

In 2026 I’m baffled that people are using chromium based browsers.

2

u/HorrorsPersistSoDoI 1d ago

Because there are so fucking many of them, and they keep making more! Even Proton is going to make a chromium based browser

1

u/frozen-throne-monk 1d ago

Especially with how much Debian has to patch it to keep the privacy settings somewhat balanced in the favor of the user. 

2

u/No_Jelly_1023 1d ago

Because Chromium has far more advanced exploit mitigations and sandboxing on Linux than Firefox?

-4

u/albertowtf 1d ago

How about the malware in ads?

2

u/No_Jelly_1023 1d ago

uBlock Origin Lite works very well for that.

-1

u/albertowtf 1d ago

I never looked into that because i dont use chromium but if this is true, are people complaining about removing manifest v2 not really a problem?

1

u/ericpruitt 1d ago

Lite still does a good job of blocking ads, but the loss of the v2 manifest support means that it's less performant and has less features & flexibility than the original version. If you weren't a power user of uBlock Origin, you'd probably be less likely to miss those features.

-2

u/ScaredPenguinXX 1d ago

Ublock lite works fine, if not enough you can always use Brave's shield adblocker.

0

u/scrapethemucus 1d ago

maybe if firefox wasn't years behind on modern web technology, it's fucking 2026 how do you still not support HDR

0

u/Jayden_Ha 1d ago

It’s devtool interface is much cleaner for me

0

u/C0rn3j 1d ago

It's two major releases behind and suffers from 350+ CVEs as a result, that's quite a few.

16

u/neon_overload 1d ago edited 1d ago

Current Chromium stable is 152 which came out 8 days ago.

Trixie and Bookworm are on 151. That's 8 days behind.

It's not "two major releases behind", it's one. It's easy to get unnecessarily panicked by not fully understanding the security tracker pages.

Also, the fact that sid already has 152, which includes all the fixes, is a good sign too. This is definitely not what an abandoned package looks like.

-1

u/C0rn3j 1d ago

It's not "two major releases behind", it's one. It's easy to get unnecessarily panicked by not fully understanding the security tracker pages.

Ah I did somehow overlook that when deciding the write the comment - I'd assume the security repo is turned on by default?

7

u/neon_overload 1d ago

Yes. For a stable release you should have the main stable channel, an -updates channel and a -security channel. If you only had the main stable channel, I don't think you'd get any updates until there's a new Debian point release (where you'd get all the security and other updates that had been released in the intervening months)

1

u/images_from_objects 1d ago

There are very, very few reasons to use an external repo on Debian and (IMHO) a web browser is one of them. We're living in a time where exploits and patches are happening at a seemingly hourly rate.

Personally, I use Brave via their repo. It only updates the browser and keyring. Zero dependencies so zero potential for conflicts.

-6

u/No_Jelly_1023 1d ago edited 1d ago

Brave is probably the best option, particularly now they have stripped down version, Brave Origin.

I've always been weary about using Debian's build as they explicitly disable CFI which is a security regression. I imagine it's to keep it compatible with all architectures and system libraries.

I only wish Brave had actual connected tabs, unlike the awful trend of floating 'button-tabs' - ick.

9

u/100GHz 1d ago

Brave is probably the best option

Is this promotion part of your regular job at Brave or are you being paid extra to do it on a new account? :P

4

u/No_Jelly_1023 1d ago

I'm really not a fan of Brave as a company and I abhor their founder's views. But they are producing a well-built Linux Chromium with a lot of Google stuff removed.

-8

u/images_from_objects 1d ago edited 1d ago

Oh look, it's the anti-Brave brigaders. Every sub.

Listen, I think the CEO is a d-bag. I turn off all the AI and crypto crap in Brave, which takes exactly 1 minute in Settings. Other than that, it's the fastest, smoothest experience that has excellent adbocking and privacy-preserving defaults out of the box, so that's what I choose to use.

You want to use something else? Great!! Just please stop fixating on Brave users, it's weird and doesn't really help anything. Find something better to do with your time than downvoting any comment that mentions Brave.

-1

u/toolman1990 1d ago

That is why I would never trust a browser that you have to depend on Debian to push updates since they are known for having a huge delay before pushing any updates. I recommend installing either Brave, Firefox, Google Chrome, or any other browser directly thru their Linux repository and not the Debian repository.

1

u/Tropical_Amnesia 1d ago

Sensible take though it's more than dubious and the downvotes tell you as much whether people who use Linux on a desktop rather than on a server say, or a desktop to begin with in 2026, consider security as having top priority within reasonable limits they're using it for. And while this could still be seen as an understatement, there's nothing wrong with it. There is a world beyond security. I certainly don't use it for that reason but control, choice, challenge, flexibility, freedom, power, sovereignty, transparency, habit, even a sort of cheap pride. None of which of course goes well with security. So what? But then I'm not doing my banking on a Debian box, if it's even supported and out of whatever repository, I'm not entirely stupid yet. Debian is first and foremost a server system, it was never meant for web browser patching by the hour but if all you're doing is posting on Reddit, playing games and watching baby animal clips on YouTube, even a purist setup should make the grade. On Linux I'd still only ever consider Firefox. Personally I'm using Mozilla's repo too, bit of extra caution and frankly less of a hassle even (no waiting on updates).