-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Mon, 23 Mar 2026 21:26:56 -0400
Source: chromium
Architecture: source
Version: 146.0.7680.164-1
Distribution: unstable
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (146.0.7680.164-1) unstable; urgency=high
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-4673: Heap buffer overflow in WebAudio.
Reported by c6eed09fc8b174b0f3eebedcceb1e792.
- CVE-2026-4674: Out of bounds read in CSS. Reported by Syn4pse.
- CVE-2026-4675: Heap buffer overflow in WebGL.
Reported by 86ac1f1587b71893ed2ad792cd7dde32.
- CVE-2026-4676: Use after free in Dawn.
Reported by 86ac1f1587b71893ed2ad792cd7dde32.
- CVE-2026-4677: Out of bounds read in WebAudio.
Reported by c6eed09fc8b174b0f3eebedcceb1e792.
- CVE-2026-4678: Use after free in WebGPU. Reported by Google.
- CVE-2026-4679: Integer overflow in Fonts.
Reported by GF, Un3xploitable Of DeadSec.
- CVE-2026-4680: Use after free in FedCM. Reported by Shaheen Fazim.
Checksums-Sha1:
e618ce9aec1bf0639e4068af7b74d784a90ade52 4065 chromium_146.0.7680.164-1.dsc
81568bbb0ee129752f5f284021a07ea56001cd1a 786076372 chromium_146.0.7680.164.orig.tar.xz
4c5f6b01105a9ac5d4efc45e7831be196671a2ae 467220 chromium_146.0.7680.164-1.debian.tar.xz
d5450e161b428d520727e70847b018001587bbc0 27898 chromium_146.0.7680.164-1_source.buildinfo
Checksums-Sha256:
7e4d42e90d561fc1ead00c50363a4ceeb6f8f5473aeeac73bbd5c8c176696b7e 4065 chromium_146.0.7680.164-1.dsc
c59484b91103cbf1751799f86e37f02aad179a2f34933b8887ffe05a55d2c8e3 786076372 chromium_146.0.7680.164.orig.tar.xz
218fb85e3a075f04745a80ea4e93811da8c091957b9bad3fcec1802f178548bf 467220 chromium_146.0.7680.164-1.debian.tar.xz
7be0ef61776ad5d4d0ac8cd865e5b930088c29b916b562f5c605bb7a724b0212 27898 chromium_146.0.7680.164-1_source.buildinfo
Files:
a10e64e3edf448f46c95189fe78eb992 4065 web optional chromium_146.0.7680.164-1.dsc
f5a8a6a5e83b01ff359ae4a651668dd8 786076372 web optional chromium_146.0.7680.164.orig.tar.xz
ba367cf74b5e74a703a4260ad6f31dc1 467220 web optional chromium_146.0.7680.164-1.debian.tar.xz
a0943942a806af7a7db1253d4f516bae 27898 web optional chromium_146.0.7680.164-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmnCIooUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjdcCxAAgezbMSAY+9Wj/FZdUnH0oOBNQtnr
tnnflMj7QjkUUnhyXtTXZ4z5rL8+A7AKeqZ6eYe3n943AacwzPSVzGVjk0t1B4oo
icV7C3/wBUIo8yp0HJvpEsi8H8IOjIaOSHskc1PQJwaGEVhr53bsxEmlpe0mgQFX
Ij3xeSRZM7j5xo8J+ZyENNAGId96dN93r5LO1Vq3lWgnbp7u1IzJxTtIyu19LvtW
ad6r8PkhfiVIaFCYdfAxy4izVxHeuunIf4xsScqDeTJL1piWmBs3wCWgh3p/RiF2
uUqSDHnI2gsImRZyUb3ReVYayb2OByWDLqdLbZzUnlYh8umGSt9Pq0rRv6hnn3OW
Sz1ykx+AsnRufdkIO+ogLU8PA0Ha+BkU+IoHBDbp63Vv5ob5YrVM/7yttw/tFaEV
Y25TwaB5VDntcVIKDOUPo+7r14mlZjiM9L7UgE28XEITsQBJoioxQtXGG4FsiZLv
YliejBgI6nwjELMP12O6yXFsrM7zgSiK7eOGJUBp424HRBQaRIgpE8VJTa+At7ze
n0nkNsKRk5NsmYhAUu/xPBmWXM04KDEjb32JJI5ac+nLB3VFWVY3GAd3scxEg+GT
H2viQqMh2PKDP+YSUh+JsR3D/fszSIwAeDqnZSxr1zGIfNpBTvbXon8kSC5r82iw
qg1TgogOblCPUVM=
=Y26v
-----END PGP SIGNATURE-----