-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 07 Oct 2025 20:11:58 -0400 Source: chromium Architecture: source Version: 141.0.7390.65-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: Debian Chromium Team <chromium@packages.debian.org> Changed-By: Andres Salomon <dilinger@debian.org> Changes: chromium (141.0.7390.65-1~deb13u1) trixie-security; urgency=high . * New upstream security release. - CVE-2025-11458: Heap buffer overflow in Sync. Reported by raven at KunLun lab. - CVE-2025-11460: Use after free in Storage. Reported by Sombra. - CVE-2025-11211: Out of bounds read in WebCodecs. Reported by Jakob Košir. Checksums-Sha1: 33b7d67e9e2edb7f8a2defd0fd6490786f5c3a71 4023 chromium_141.0.7390.65-1~deb13u1.dsc d53e0f1b05daf0cb3d0d28fd1ba3466f91ffc1a2 1001790556 chromium_141.0.7390.65.orig.tar.xz 6d7f2088ec22b16066fe77bf85ba074e3e77c150 414896 chromium_141.0.7390.65-1~deb13u1.debian.tar.xz c55e8c43353e0bb18ebcdc5ebc1163235d562238 26513 chromium_141.0.7390.65-1~deb13u1_source.buildinfo Checksums-Sha256: 8e423c93d5eca43293cac9957947079899f492577ad6232fc92a42e7d81b3be5 4023 chromium_141.0.7390.65-1~deb13u1.dsc ca4812bc3533ee988bb26b30fe095bd9335cd0652cc2a3ad8fac31bd59a2ff5d 1001790556 chromium_141.0.7390.65.orig.tar.xz 33b526fd8409ddaae7e111c65cd6a4b01f66c7185bfd672e989011dc6e056c6a 414896 chromium_141.0.7390.65-1~deb13u1.debian.tar.xz 979fb6005ccc862c9306d44bb68c3f19024c2af26a71b9e0e2a721d9f3639a97 26513 chromium_141.0.7390.65-1~deb13u1_source.buildinfo Files: b0de526a7ffe7a8b8c165d385ab3adcf 4023 web optional chromium_141.0.7390.65-1~deb13u1.dsc 85d4e6ca2e19d14bf7d3cd1a7d202227 1001790556 web optional chromium_141.0.7390.65.orig.tar.xz 56990a08eb14615063490e156c21e071 414896 web optional chromium_141.0.7390.65-1~deb13u1.debian.tar.xz 04aba0a2f1fd6bdb1573ff245a4b7603 26513 web optional chromium_141.0.7390.65-1~deb13u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmjmDvIUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8NudjdpYxAAu+T9EfjYbpcQDU5M2t0zsqqk/9Wm TQm0T8YqpFUV50DaQwxfFyPm8qoGsi/fLYtv2j3xULbH8AwtIDnPhtzUVqKoINja v1wIAnlaWOLgqAyU5Kl56NL8ieAGPuLbuaCK8IOjAnr9aPSw3RmWoe7c2Z9Mbojl gFtGDL2bN5A5zOBiG8wgnkEkHAD/2p79NBV4Tc5vFmixzqbv0GkC19W30ZCDqkgP 2bG6+eb9nKcFyS2+RrqIpjXtruGhh2zErMa061bHF9jFfEE0bj3dLrOyOdMQ9qEM eGDOF9VwIXxvZZugMMUrwfWMx5h/CeC3X65yRbGCFP5Bi4+xk1cZN2oai4XVpHGM hzmOTgd2bd8/PFwBjyLyJYA4EDCUbhZGH2xLlCtkoJ5xXiIQvDhOX+U44FejRoeU 3rXExJy4oS1xZ9z1TPsEV4mIewjYioXCEHmLagfV6JlwnuV5dWGagp/4q8eDUDaT qHWWQLqErWFALTIHVYzTqQHvKxFrfnm6Lo1bGiWmssNvf/O6vUm2drs8gu05ycSa ktK12RtGH93zdVq4j3lnlqp1EY8o7N2B12AlWBOR1dPWxUONbccIhvsfOhAr+OsJ lW6unQZVyyH6Y1n6jkbY146eBP7zziuNWKUJtxqFLlYgTMVOA64mW78H6N7bZETk MoksskM3JVqlQTo= =MfxR -----END PGP SIGNATURE-----