-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 23 Sep 2025 16:50:58 -0400 Source: chromium Architecture: source Version: 140.0.7339.207-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: Debian Chromium Team <chromium@packages.debian.org> Changed-By: Andres Salomon <dilinger@debian.org> Changes: chromium (140.0.7339.207-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2025-10890: Side-channel information leakage in V8. Reported by Mate Marjanović (SharpEdged). - CVE-2025-10891: Integer overflow in V8. Reported by Google Big Sleep. - CVE-2025-10892: Integer overflow in V8. Reported by Google Big Sleep. Checksums-Sha1: 77c539465091d70b3fd05f4261f26375e114d239 4063 chromium_140.0.7339.207-1~deb12u1.dsc 86bd2445b36de5d1d6e5b3cc47e471d248d832a8 993803584 chromium_140.0.7339.207.orig.tar.xz 0567261e7e4bff5ca22142dd37e5575ff8afca3b 8501612 chromium_140.0.7339.207-1~deb12u1.debian.tar.xz 42b7dde2518b149db0481fbe152c8762914dc392 26765 chromium_140.0.7339.207-1~deb12u1_source.buildinfo Checksums-Sha256: 7d380c2c7f150c6d280400d3cc083c82bec1345c62d9d076b1c43a65b41ebfb9 4063 chromium_140.0.7339.207-1~deb12u1.dsc 38b0d4dfb3a839f0cf6d7e05ddc55f3d73bcdf519e2211fa0d3d797824b548d0 993803584 chromium_140.0.7339.207.orig.tar.xz 2ee1c8179dfe77a5a76e273e756811716cd49682d8edd12dc205eb967f70e7d6 8501612 chromium_140.0.7339.207-1~deb12u1.debian.tar.xz 8ddd80e8b27f7be11429a261abb99e98ccaad9fc1c1505c2c5486a859fee2cd0 26765 chromium_140.0.7339.207-1~deb12u1_source.buildinfo Files: c5089c65858923686197c1c1701b8282 4063 web optional chromium_140.0.7339.207-1~deb12u1.dsc 2d18b4e91e7ad24cc5b42f7cc42a87f8 993803584 web optional chromium_140.0.7339.207.orig.tar.xz 09d139aed49efb229fc284bcdc5d44ed 8501612 web optional chromium_140.0.7339.207-1~deb12u1.debian.tar.xz fbcd385f92833735bf11c55cc23ad1a7 26765 web optional chromium_140.0.7339.207-1~deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmjUG4QUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8NudjdSFxAAsU9fmWt3D/ZGU8fKnVZSJUHC8NSa bEVHwPkrBtlmzdsmAleGFtvsDnSPE+bi2o+VzbqWIyZrPq1Q58Tx+NNCy/n3vbTJ JcvHyCvNOrx5sEhugNhfxCq2BgdFiTh5/aY8BZ0Dsoe0rH0htZIFm/TyBw+ewvno 2tHN1F5HUyyckMyzXmmBXiDiwdui8cJT06wqEyRI9qdqixXI6p3ijhGTAZqXTCRT 1EONJrHhv7TZOCAHET0TEqFyvjOBVqwpneFd3b+MoMDpVMuIuueJaR+NDn/fpEl6 jedXTenNIobOiBNpMkco1G+Gc8hQ1HbkgN8B+I7w0oBs56T6Crd/WPo71O9jjFTF 8g4HLrxh2VXK+yGqN2BRlKRD2hF7ikAoeyn/Q9CQnX2cphLwcNouLgcddpiRxd/a QkCkPveKFT3lPowQwAsoWEtSpBCeNXEOL3F3JdkzSY588o4rUPiQxjSCnyCzTJcQ pqU4pMV7ihZ38fi27qYaPmufGYC0p7g9py43ZpWjwtWKlWL7XStebemqnsf5iSju GJ/KqFZo/FjsU3dYD4tMB10v3y0nbBfc19GBkeznASEA88DdryOaOkf0PfRALIYU 1y0tAKSnJZnBVN0s+mjbzzNH06nvAl1YJxOeNbmyl16EEPgaHQqL/f1LaY+q1u4k YPmd7VUEw26U5K4= =fQoh -----END PGP SIGNATURE-----