-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 07 Oct 2025 20:11:58 -0400 Source: chromium Architecture: source Version: 141.0.7390.65-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: Debian Chromium Team <chromium@packages.debian.org> Changed-By: Andres Salomon <dilinger@debian.org> Changes: chromium (141.0.7390.65-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2025-11458: Heap buffer overflow in Sync. Reported by raven at KunLun lab. - CVE-2025-11460: Use after free in Storage. Reported by Sombra. - CVE-2025-11211: Out of bounds read in WebCodecs. Reported by Jakob Košir. Checksums-Sha1: 213be1b57f33ca7a487f397cb1e51721476c3e4d 4059 chromium_141.0.7390.65-1~deb12u1.dsc d53e0f1b05daf0cb3d0d28fd1ba3466f91ffc1a2 1001790556 chromium_141.0.7390.65.orig.tar.xz 9cdd0b0dd22418f82240f1f485d9ddda901a6a8b 8502760 chromium_141.0.7390.65-1~deb12u1.debian.tar.xz 4cc85a6368200409297580a0e7be8ab0e868aea6 26768 chromium_141.0.7390.65-1~deb12u1_source.buildinfo Checksums-Sha256: bf49f42839429ce2f6a648a68bbecc4c99db670ba2ff3494d911870cf7990c15 4059 chromium_141.0.7390.65-1~deb12u1.dsc ca4812bc3533ee988bb26b30fe095bd9335cd0652cc2a3ad8fac31bd59a2ff5d 1001790556 chromium_141.0.7390.65.orig.tar.xz 41f30c900ec21cb17c59ea22aa079cbb1772844106fccb248ec5c9e423a34c5f 8502760 chromium_141.0.7390.65-1~deb12u1.debian.tar.xz 6b8177b66c228e854f2983b874c5453813c795b6b92ef4c8c721f65a828526cb 26768 chromium_141.0.7390.65-1~deb12u1_source.buildinfo Files: 97b7c9f3a6aca4cd9f9d06bb1d1d8473 4059 web optional chromium_141.0.7390.65-1~deb12u1.dsc 85d4e6ca2e19d14bf7d3cd1a7d202227 1001790556 web optional chromium_141.0.7390.65.orig.tar.xz d1a63d7d2af3c4f0fb194b297f37b2a9 8502760 web optional chromium_141.0.7390.65-1~deb12u1.debian.tar.xz fb1a97e0d2bd26025c380b7f810808f1 26768 web optional chromium_141.0.7390.65-1~deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmjmj80UHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8Nudjd78A//aEEImhW741O31gXeM4/L8ImtGKsH p8Am4dm4O6GnwZ8wM5JcdcurvtSu+igOuD6+e98+6dc3gzKOgBBp8kO2CZwZ47EJ xXG0/yvF+egHkMFwqrNgDwhvpupg4zfLdx8Zhp9RjNEyzbsZTEJbTsQbKZ22H+0U H09kgJeKV/56wgWsI/zxrUz3sr4HuxgSLDh8J3AEPvfCXGqfDFfATNBabWaDL3AL jbbq5Nad9NG3XQGxbDpS+jhRBfaVyULnf3jL0lSJjVVL69lzyl3GneEOPwRX5G6f rdXE8TWfoo2qrzYYCI/k+F5ZGTm4b+eDSPPydLiZ4/UgDycd55MB4PCxiOkhh7vO LMBG4KYDmsoHZ77NnCUpRO3sI9Ywrzaq66XJqAs8b5Y/Dt1ynprrsy9kuvBPfanF srOkqvtxleJrTPZRbiRLFzsXaiE/8MTfgmT9sXqb6V2QT7exqhQLKBX7Q080gP7r /auiq8+GUO+skiV8F0wLe6E4JM1INu+K64HVJ3WwMiPP6UCQ31V4MYK7R7SkciDU R8cAFkMRUYZVlUwNwKVdfk2XzMy+m/PSQcjAlfE2sOJ9zyH8z/b7AkXbf923o4sw 7aENFiR4yGbU+39sYStlRL4JHiWnUXNF4ysGVBsFamUtc8ot+3Tc+/00qFJJ8zn4 4W/coN4AJ/VKfD0= =ADWb -----END PGP SIGNATURE-----