-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 07 Oct 2025 20:11:58 -0400 Source: chromium Architecture: source Version: 141.0.7390.65-1 Distribution: unstable Urgency: high Maintainer: Debian Chromium Team <chromium@packages.debian.org> Changed-By: Andres Salomon <dilinger@debian.org> Changes: chromium (141.0.7390.65-1) unstable; urgency=high . * New upstream security release. - CVE-2025-11458: Heap buffer overflow in Sync. Reported by raven at KunLun lab. - CVE-2025-11460: Use after free in Storage. Reported by Sombra. - CVE-2025-11211: Out of bounds read in WebCodecs. Reported by Jakob Košir. Checksums-Sha1: 05b97ea9d8f4a148061cd954a53cc3b3274f93a7 3991 chromium_141.0.7390.65-1.dsc d53e0f1b05daf0cb3d0d28fd1ba3466f91ffc1a2 1001790556 chromium_141.0.7390.65.orig.tar.xz c86b4868646ece2a496b316533d015ca92de5617 415116 chromium_141.0.7390.65-1.debian.tar.xz 4bf469118fc1702a051b239b1ff343123d34846f 26252 chromium_141.0.7390.65-1_source.buildinfo Checksums-Sha256: 9fe5ddc4a89eb99eda38861c296f69b3c5d5295e79225b17f5f925a66b9151f1 3991 chromium_141.0.7390.65-1.dsc ca4812bc3533ee988bb26b30fe095bd9335cd0652cc2a3ad8fac31bd59a2ff5d 1001790556 chromium_141.0.7390.65.orig.tar.xz d2d120527ca75400375064d52f640fe9a4128513a5a3d68d698ac2a09d40e6c7 415116 chromium_141.0.7390.65-1.debian.tar.xz ad4fd516399c25b0841ace69be46373dec838f0231f043e5cd598f5c1e82c043 26252 chromium_141.0.7390.65-1_source.buildinfo Files: 866461bd1c472bbd9582117bd3be8448 3991 web optional chromium_141.0.7390.65-1.dsc 85d4e6ca2e19d14bf7d3cd1a7d202227 1001790556 web optional chromium_141.0.7390.65.orig.tar.xz 662dd1e788cb012d50bb7bd0bf01461a 415116 web optional chromium_141.0.7390.65-1.debian.tar.xz 5edf35592ada499d1f5e6eb4cb1a7529 26252 web optional chromium_141.0.7390.65-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmjmD88UHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8NudjevWw//YMEItDreOD0bukr911LYq/1Vck5e vKMP8+16BucaIyl4rILjynwjTFCS2uePAzIl/I9HrXboKGnqfa5jgaSHBjUM1OMJ G3t24AFNysfTkqKEUTwse4/R6N++MGIwQiWLXfEdXTP2MFJVDhwEN1MLYKba08z1 srvlin3b6bfXUPxpUuoPhWrsDExgcHynhb06KHTOwi11LM4bywNpcF/orm7w8PON UImXf5GYp+4Ic5m1n8kafD8gRIH340rAQ8xuFHwjD/6ViENGsOw/o0cBoVHMvWi5 71K7YyHgWn03Ixv2sTt2ykaTcB7izuM3NUFhpAKI0A4F6MU7Jd+WdAeLI0fPvtCg 9CuJbNkrXQFo7h1gP4mEAIhpzc2doKBv/MBASHuBZg/JtQDNbD/xqevx02jD+PHC CoxQDaLc9JrAvgheSHe4ZGSdaGtrFcWafxpLjAUgwqQ5ip9tyJlQ3SHTsSnQSWXT FwdYlU1yIqko2zltVg4kIiYUe/Y0KEqWQI2Nl+xjc6vQgKqAjAN3dXMkVxV7FmDl X+HkniMOKeohbkdbyRytYbzoghyWNvVRxJ5jDy3bz+RLvYI3D1Ma/7TQ09LtPbBi ULG5i3XInMUNiE+mFVzPP35RIolC7+cbK5yTttZhOL88S7OJOLmLyGFUsRTJIo8G Xs0p9jnxl9J9iPk= =gptQ -----END PGP SIGNATURE-----