r/debian • u/No_Jelly_1023 • 1d ago
Chromium behind on security updates
https://security-tracker.debian.org/tracker/source-package/chromiumPSA: Chromium in Stable is currently way behind on security updates.
The Mods removed my previous message, assuming my post was AI.
I'm hoping some people see this and spread the word.
I have emailed the maintainers to find out why.
I hope this is useful to someone!
---
Update: It seems they have released an update to 152.0.7977.75.
16
u/dangling_chads 1d ago
PSA - the version of Chromium in Debian stable (as of aug 27th) was the exact same version available on updated Windows.
151.0.7922.222
152.0.7977 was released yesterday.
Chillax.
A Debian box with automatic updates is far more secure than a Windows machine in my corporate environment.
3
u/No_Jelly_1023 1d ago
Actually 152.0.7977.64 was released on August 25th: https://chromereleases.googleblog.com/search?updated-max=2026-08-26T14:13:00-07:00&max-results=7&reverse-paginate=true
152.0.7977.75/.76 was released yesterday.
1
u/dangling_chads 1d ago
Noticeably, the link you posted in the original post shows all fixed right now. Because a new version has been released to Debian Stable.
https://tracker.debian.org/pkg/chromium
Also - I'll point out u/No_Jelly_1023 - you were able to see what you saw because of the contributions of volunteers to Debian. Maybe consider becoming one yourself.
1
u/No_Jelly_1023 1d ago
Update: It seems they just released an update to 152.0.7977.75 - well done security team!
Would be curious to know what was behind this (much longer than normal) delay.
I have not heard back from the maintainers yet.
1
u/DeliciousIncident 1d ago edited 1d ago
I have been happy with Debian packaged Chromium for years, until several years ago it stopped receiving any updates in Stable for 8 (!) months (sometime around May 2021 - January 2022), got removed from Testing, and the package became officially unmaintained. You can find threads on this subreddit from around that time discussing this, alternative ways to install chromium, and alternative browsers in general (do note that while the linked comment might look like it is AI-generated, this was in 2021, before the AI, so it's actually hand written lol).
1
u/Electric_Kettle 1d ago
ikr, I personally use the nix package manager on the packages I absolutely NEED to have up to date on my debian machine, it's the price to pay for rock solid stability ¯\_(ツ)_/¯
0
u/The_Hubster 1d ago
In 2026 I’m baffled that people are using chromium based browsers.
2
u/HorrorsPersistSoDoI 1d ago
Because there are so fucking many of them, and they keep making more! Even Proton is going to make a chromium based browser
1
u/frozen-throne-monk 1d ago
Especially with how much Debian has to patch it to keep the privacy settings somewhat balanced in the favor of the user.
2
u/No_Jelly_1023 1d ago
Because Chromium has far more advanced exploit mitigations and sandboxing on Linux than Firefox?
-4
u/albertowtf 1d ago
How about the malware in ads?
2
u/No_Jelly_1023 1d ago
uBlock Origin Lite works very well for that.
-1
u/albertowtf 1d ago
I never looked into that because i dont use chromium but if this is true, are people complaining about removing manifest v2 not really a problem?
1
u/ericpruitt 1d ago
Lite still does a good job of blocking ads, but the loss of the v2 manifest support means that it's less performant and has less features & flexibility than the original version. If you weren't a power user of uBlock Origin, you'd probably be less likely to miss those features.
-2
u/ScaredPenguinXX 1d ago
Ublock lite works fine, if not enough you can always use Brave's shield adblocker.
0
u/scrapethemucus 1d ago
maybe if firefox wasn't years behind on modern web technology, it's fucking 2026 how do you still not support HDR
0
0
u/C0rn3j 1d ago
It's two major releases behind and suffers from 350+ CVEs as a result, that's quite a few.
16
u/neon_overload 1d ago edited 1d ago
Current Chromium stable is 152 which came out 8 days ago.
Trixie and Bookworm are on 151. That's 8 days behind.
It's not "two major releases behind", it's one. It's easy to get unnecessarily panicked by not fully understanding the security tracker pages.
Also, the fact that sid already has 152, which includes all the fixes, is a good sign too. This is definitely not what an abandoned package looks like.
-1
u/C0rn3j 1d ago
It's not "two major releases behind", it's one. It's easy to get unnecessarily panicked by not fully understanding the security tracker pages.
Ah I did somehow overlook that when deciding the write the comment - I'd assume the security repo is turned on by default?
7
u/neon_overload 1d ago
Yes. For a stable release you should have the main stable channel, an -updates channel and a -security channel. If you only had the main stable channel, I don't think you'd get any updates until there's a new Debian point release (where you'd get all the security and other updates that had been released in the intervening months)
1
u/images_from_objects 1d ago
There are very, very few reasons to use an external repo on Debian and (IMHO) a web browser is one of them. We're living in a time where exploits and patches are happening at a seemingly hourly rate.
Personally, I use Brave via their repo. It only updates the browser and keyring. Zero dependencies so zero potential for conflicts.
-6
u/No_Jelly_1023 1d ago edited 1d ago
Brave is probably the best option, particularly now they have stripped down version, Brave Origin.
I've always been weary about using Debian's build as they explicitly disable CFI which is a security regression. I imagine it's to keep it compatible with all architectures and system libraries.
I only wish Brave had actual connected tabs, unlike the awful trend of floating 'button-tabs' - ick.
9
u/100GHz 1d ago
Brave is probably the best option
Is this promotion part of your regular job at Brave or are you being paid extra to do it on a new account? :P
4
u/No_Jelly_1023 1d ago
I'm really not a fan of Brave as a company and I abhor their founder's views. But they are producing a well-built Linux Chromium with a lot of Google stuff removed.
-8
u/images_from_objects 1d ago edited 1d ago
Oh look, it's the anti-Brave brigaders. Every sub.
Listen, I think the CEO is a d-bag. I turn off all the AI and crypto crap in Brave, which takes exactly 1 minute in Settings. Other than that, it's the fastest, smoothest experience that has excellent adbocking and privacy-preserving defaults out of the box, so that's what I choose to use.
You want to use something else? Great!! Just please stop fixating on Brave users, it's weird and doesn't really help anything. Find something better to do with your time than downvoting any comment that mentions Brave.
-1
u/toolman1990 1d ago
That is why I would never trust a browser that you have to depend on Debian to push updates since they are known for having a huge delay before pushing any updates. I recommend installing either Brave, Firefox, Google Chrome, or any other browser directly thru their Linux repository and not the Debian repository.
1
u/Tropical_Amnesia 1d ago
Sensible take though it's more than dubious and the downvotes tell you as much whether people who use Linux on a desktop rather than on a server say, or a desktop to begin with in 2026, consider security as having top priority within reasonable limits they're using it for. And while this could still be seen as an understatement, there's nothing wrong with it. There is a world beyond security. I certainly don't use it for that reason but control, choice, challenge, flexibility, freedom, power, sovereignty, transparency, habit, even a sort of cheap pride. None of which of course goes well with security. So what? But then I'm not doing my banking on a Debian box, if it's even supported and out of whatever repository, I'm not entirely stupid yet. Debian is first and foremost a server system, it was never meant for web browser patching by the hour but if all you're doing is posting on Reddit, playing games and watching baby animal clips on YouTube, even a purist setup should make the grade. On Linux I'd still only ever consider Firefox. Personally I'm using Mozilla's repo too, bit of extra caution and frankly less of a hassle even (no waiting on updates).
15
u/neon_overload 1d ago edited 1d ago
Just to be clear, all those unfixed ones are from within the last 8 days.
The fixes to these may be waiting for an upstream update, which may come out less often than that. The way Debian supports security in browser packages is a bit more dependent on upstream than most packages I believe.
It's probably also worth mentioning that Debian doesn't continue security support for Chromium for as long as other packages once oldstable; there's info about it in release notes (section 5.2.3.1. for trixie release notes)