-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Wed, 11 Mar 2026 20:01:51 -0400
Source: chromium
Architecture: source
Version: 146.0.7680.71-1
Distribution: unstable
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (146.0.7680.71-1) unstable; urgency=high
.
[ Andres Salomon ]
* New upstream stable release.
- CVE-2026-3913: Heap buffer overflow in WebML. Reported by Tobias Wienand
- CVE-2026-3914: Integer overflow in WebML. Reported by cinzinga.
- CVE-2026-3915: Heap buffer overflow in WebML. Reported by Tobias Wienand
- CVE-2026-3916: Out of bounds read in Web Speech.
Reported by Grischa Hauser.
- CVE-2026-3917: Use after free in Agents. Reported by Syn4pse.
- CVE-2026-3918: Use after free in WebMCP. Reported by Syn4pse.
- CVE-2026-3919: Use after free in Extensions. Reported by Huinian Yang
(@vmth6) of Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd
- CVE-2026-3920: Out of bounds memory access in WebML. Reported by Google.
- CVE-2026-3921: Use after free in TextEncoding.
Reported by Pranamya Keshkamat & Cantina.xyz.
- CVE-2026-3922: Use after free in MediaStream.
Reported by c6eed09fc8b174b0f3eebedcceb1e792.
- CVE-2026-3923: Use after free in WebMIDI.
Reported by c6eed09fc8b174b0f3eebedcceb1e792.
- CVE-2026-3924: Use after free in WindowDialog.
Reported by c6eed09fc8b174b0f3eebedcceb1e792.
- CVE-2026-3925: Incorrect security UI in LookalikeChecks.
Reported by NDevTK and Alesandro Ortiz.
- CVE-2026-3926: Out of bounds read in V8. Reported by qymag1c.
- CVE-2026-3927: Incorrect security UI in PictureInPicture.
Reported by Barath Stalin K.
- CVE-2026-3928: Insufficient policy enforcement in Extensions.
Reported by portsniffer443.
- CVE-2026-3929: Side-channel information leakage in ResourceTiming.
Reported by Povcfe of Tencent Security Xuanwu Lab.
- CVE-2026-3930: Unsafe navigation in Navigation.
Reported by Povcfe of Tencent Security Xuanwu Lab.
- CVE-2026-3931: Heap buffer overflow in Skia. Reported by Huinian Yang
(@vmth6) of Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd
- CVE-2026-3932: Insufficient policy enforcement in PDF.
Reported by Ayato Shitomi.
- CVE-2026-3934: Insufficient policy enforcement in ChromeDriver.
Reported by Povcfe of Tencent Security Xuanwu Lab.
- CVE-2026-3935: Incorrect security UI in WebAppInstalls.
Reported by Barath Stalin K.
- CVE-2026-3936: Use after free in WebView. Reported by Am4deu$.
- CVE-2026-3937: Incorrect security UI in Downloads.
Reported by Abhishek Kumar.
- CVE-2026-3938: Insufficient policy enforcement in Clipboard.
Reported by vicevirus.
- CVE-2026-3939: Insufficient policy enforcement in PDF. Reported by NDevTK
- CVE-2026-3940: Insufficient policy enforcement in DevTools.
Reported by Jorian Woltjer, Mian, bug_blitzer.
- CVE-2026-3941: Insufficient policy enforcement in DevTools.
Reported by Lyra Rebane (rebane2001).
- CVE-2026-3942: Incorrect security UI in PictureInPicture.
Reported by Barath Stalin K.
* d/rules: update rustc version string for new upstream expectations of
no spaces.
* d/patches:
- upstream/disable-unrar.patch: drop, merged upstream.
- disable/signin.patch: drop part of the patch. This patch should be
reviewed in the future and coordinated w/ ungoogled-chromium, since
it originally came from them.
- disable/glic.patch: add a bunch more glic removals.
- disable/license-headless-shell.patch: refresh.
- disable/unrar.patch: refresh.
- system/rollup.patch: refresh.
- bookworm/foreach.patch: refresh.
- ungoogled/disable-privacy-sandbox.patch: sync from ungoogled-chromium.
- disable/catapult.patch: update to remove some more catapult deps.
- fixes/force-rust-nightly.patch: drop, no longer needed.
- llvm-22/ignore-for-ubsan.patch: add a build fix for a compiler
flag/feature added to llvm-23.
- fixes/bytemuck.patch: add rust build fix in bytemuck.
- llvm-19/clang-19-crash.patch: add build fix; delete code that makes
clang-19++ crash.
- llvm-19/keyfactory.patch: add build fix for what I suspect is a clang-19
issue.
- loongarch64/0018-fix-study-crash.patch: refresh.
- ppc64le/breakpad/0001-Implement-support-for-ppc64-on-Linux.patch:
refresh.
- ppc64le/fixes/fix-study-crash.patch: refresh.
- llvm-19/clone-traits.patch: add patch to remove a static assertion.
- llvm-19/octal.patch: add patch to work around 0o666 vs 0666 support.
- upstream/profile.patch: add header inclusion build fix from upstream.
- trixie/value-or.patch: move to llvm-19/ directory & also add another
place that clang-19 gets confused during build.
- rust-1.85/jxl-features.patch: refresh [trixie, bookworm].
- rust-1.85/jxl-simd-avx512.patch: update for (numerous) upstream
changes, and added unsafe{} blocks to the macro definitions to shrink
this patch in the future [trixie, bookworm].
- fixes/missing-dep.patch: add patch for dependency-related build failure
that only happens sometimes.
.
[ Timothy Pearson ]
* d/patches/ppc64le:
- third_party/0001-Add-PPC64-support-for-boringssl.patch: refresh
for upstream changes
- third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch:
refresh for upstream changes
.
[ Daniel Richard G. ]
* d/patches:
- disable/lint.patch: New patch to disable CSS/JS linting tools.
- bookworm/node18-compat.patch: New patch to fix various compatibility
issues with nodejs 18 [bookworm].
- trixie/gn-len.patch: Zap another instance of len() for older GN
[trixie, bookworm].
Checksums-Sha1:
4ad3790b63fdb8effcb1f7dc19a9b72df40956e8 4058 chromium_146.0.7680.71-1.dsc
14703cccb2cc8cb6c98847a167cfff5b58fd9b08 786527720 chromium_146.0.7680.71.orig.tar.xz
5a9bbb96bb2e5c0bced6ec409c9d6f56b1e8f0cf 465292 chromium_146.0.7680.71-1.debian.tar.xz
faca518e1d8792c971f3d71fa56dfe0a7cb8efc7 27935 chromium_146.0.7680.71-1_source.buildinfo
Checksums-Sha256:
47e0efc6ddd4f672bd2eeec2d42a400c1e7b62d85ee2bedf907941675a3baee5 4058 chromium_146.0.7680.71-1.dsc
15fda8dbd2866c18cc483782d54aa83b19cb8d4bc1b12b3cc5feef6022b70fa7 786527720 chromium_146.0.7680.71.orig.tar.xz
8d30b184a4b0678544d6489323fa14dccb648769af1e30435578aab30efcbb6d 465292 chromium_146.0.7680.71-1.debian.tar.xz
3ce9d4e7b23e78846c5d4aba65e988e8846b22b16fd61c4ddd788051b8ed94b6 27935 chromium_146.0.7680.71-1_source.buildinfo
Files:
85d35fc9a2907b15f34dc3a6c9f0e68a 4058 web optional chromium_146.0.7680.71-1.dsc
c7a4cfa9a116b60cfa014323b6d9e3bc 786527720 web optional chromium_146.0.7680.71.orig.tar.xz
a166154764b2a3f8de15626946bb031e 465292 web optional chromium_146.0.7680.71-1.debian.tar.xz
316d3a295f96452f058c3d989f0a7bfa 27935 web optional chromium_146.0.7680.71-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmmyESEUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjfRBg//VjUBY5s7BImF/nsXMqBFN7j5cgH4
MRDlng57kLPHtPUvoqBkMUFM4ep46z97niT4BpbWec+iwpTTACgt9eH3b5IShKm2
uKQ/Ql/C4cbx2na0IJvEdAijm3Ql7cYEWMXro+lC1x7QbeqzJ38UUaed9LEPyVqj
aA5WDc3g+6ApB9FW2u5nn0AQg5pR2iTnF9aDJWWpEO4LnCN36XLGAVBusksM6oPX
lAbthVstrISspDQLtPGau5x3yzDNFrPdCemY0Ih2oFyD7SCLHAltrYBN4ocFqbBz
B/QIF5JRwlBHeIWzrXkVApXOPrpEkTOJ2KK4ECjTZ3Yzp+BtvTCwTJV2aK3JBQ6h
X2BgdPHWNm6vOWVG8tstq+9Z4QAT2QBBNdep+P7lYbaMLgsQofRtqFwRpnhsbZkx
JZ79kZ2veR1xDXxn7VGy080zsWmFrcdv+J55eufO4e6/nB5gknEgUbOKwUlemeHh
6yBWOm8LhwzGo8jVD8FFZZx9fNj7AopmwoYOJ8RHZH+3E9eT53LK9HSPUwsq72zs
Ul40NVsFpz0FaA+fRb/GpNMC8Ud1pGHAODSQlwcJad/DSbbGTbFwjkM/fJ0z/zg/
Jkr7I77AtAqWXU1kzKjBbZZ50LRh29l0KoqKcUJmNQ8dSXr/qI241OWTN2fQOuaZ
O3JqawAqrxqjOxU=
=PbW6
-----END PGP SIGNATURE-----