-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Fri, 10 Jul 2026 01:45:42 -0400
Source: chromium
Architecture: source
Version: 150.0.7871.114-1~deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (150.0.7871.114-1~deb12u1) bookworm-security; urgency=high
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-15112: Use after free in Ozone. Reported by Google.
- CVE-2026-15129: Use after free in Views. Reported by Google.
- CVE-2026-15132: Uninitialized Use in V8.
Reported by Pierre Langlois from Arm.
- CVE-2026-15133: Use after free in InterestGroups. Reported by Jihyeon
Jeong (Compsec Lab, Seoul National University / Research Intern).
- CVE-2026-15108: Integer overflow in Extensions API. Reported by Google.
- CVE-2026-15109: Uninitialized Use in ANGLE. Reported by Google.
- CVE-2026-15110: Use after free in Extensions. Reported by Google.
- CVE-2026-15111: Use after free in Views. Reported by Google.
- CVE-2026-15113: Use after free in Autofill. Reported by Google.
- CVE-2026-15114: Out of bounds read and write in Codecs.
Reported by Google.
- CVE-2026-15115: Insufficient validation of untrusted input in
WebAppInstalls. Reported by Google.
- CVE-2026-15116: Use after free in Actor. Reported by Google.
- CVE-2026-15117: Use after free in Payments. Reported by Google.
- CVE-2026-15118: Use after free in Input. Reported by Google.
- CVE-2026-15119: Inappropriate implementation in GetUserMedia.
Reported by Google.
- CVE-2026-15120: Use after free in Core. Reported by Google.
- CVE-2026-15121: Use after free in WebRTC. Reported by Google.
- CVE-2026-15122: Insufficient validation of untrusted input in Codecs.
Reported by Google.
- CVE-2026-15123: Insufficient data validation in DOM. Reported by Google
- CVE-2026-15124: Insufficient policy enforcement in Passwords.
Reported by Google.
- CVE-2026-15125: Inappropriate implementation in Forms.
Reported by Google.
- CVE-2026-15126: Use after free in Forms. Reported by Google.
- CVE-2026-15127: Inappropriate implementation in WebGL.
Reported by Google.
- CVE-2026-15128: Inappropriate implementation in Forms.
Reported by Google.
- CVE-2026-15130: Insufficient policy enforcement in Navigation.
Reported by Google.
- CVE-2026-15107: Use after free in IndexedDB.
Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab.
- CVE-2026-15131: Insufficient data validation in Navigation.
Reported by Google.
Checksums-Sha1:
27d8cf8c7a50a8e7738d8604005a3cea166ccbb4 4068 chromium_150.0.7871.114-1~deb12u1.dsc
c2c182e9cc5cfe314511c0c9eea26df406edc4a8 941382260 chromium_150.0.7871.114.orig.tar.xz
bce350f1ca5ad19ff61a5a379e6e9a14f0b80611 8623376 chromium_150.0.7871.114-1~deb12u1.debian.tar.xz
3642734413b5c6b829544a05e080b15eef47711e 26997 chromium_150.0.7871.114-1~deb12u1_source.buildinfo
Checksums-Sha256:
f378f56193b464b75f6e431e4bd9345f3fcaaa45c2586b8bf3b6427dca7a5b7c 4068 chromium_150.0.7871.114-1~deb12u1.dsc
962917b028794a608ac57c260312e8a1c47ee244c5f88d585fa4645383593453 941382260 chromium_150.0.7871.114.orig.tar.xz
2931f24158b0a8d55a52fb70d6bece1f99b34c621a0bf21019e2655909c643fa 8623376 chromium_150.0.7871.114-1~deb12u1.debian.tar.xz
9499a10377ef8873c6402da0927e6941e8838bccfa0539522655a62cebe47d63 26997 chromium_150.0.7871.114-1~deb12u1_source.buildinfo
Files:
fa64eeba19c36eea8736255957c6c354 4068 web optional chromium_150.0.7871.114-1~deb12u1.dsc
84472f0596f14b31b83e88a698f2f9cd 941382260 web optional chromium_150.0.7871.114.orig.tar.xz
ad0f420d9d2f99aff60560e9f1ea3c91 8623376 web optional chromium_150.0.7871.114-1~deb12u1.debian.tar.xz
1325f7286ccc938b1397e4703c15645e 26997 web optional chromium_150.0.7871.114-1~deb12u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmpRbGkUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjfYIBAAg7Hns/kvVb7eWGvfEXxPjHh4G6yP
Il9UHOnNHcI6BIuS/TdTfsbAW8HucdOhjEECXSqO7m157den/icczaWdzTOH4CyY
fgykRbuEtNSl50TosTh3GS92XtqGIgy+d4IumxPMt3lzgPYLLACDPShFdm4yCvwN
dai3503w2Hd/J96bWvghRSa4TlZcRzIBLX2Z0v/sh9xhJVhnScy/hd2oGq+TYnI5
PUbJdSfic4hh6J69A1s4dxVYR7SPpfsKJ6FSHkD6c4QL5AtRiKhzb61RLTih+58O
Y4Bf0qj4Z75742VU0xWUH5t2PUU2k8rzVmaQ/U4It6xJ5yvj7bvZJNhqTfZhFq7C
+VMTgMbwlPmUFtUYObNkNVsL5zHvYn6Fykja+HpY4gLF8MkSZWWrMu0PWlROfpeQ
KUWhsuPkNle7c8nphkhMi7YBWdOaa+62Ku0OMvbgT42aw52ogBo8OpxdtPLuOHW/
ElUg1ipFSdeDo2kkESzGs7SBScLTWFI9gENcF3Ta99CAELY0ofku/d/S+BXCRYKC
iH7558Ij6Q9/P37aeKl0penjBiirY/Ur2xFpb3a7rc/K/KUyGd8EVmGB48XKeZxK
y+Xqqhs+EWg36bmItEPGkFUM9jc5m3C4vfo/aIG/wLtRRMwNP+bRTyO4m4J03mqh
E2bjrQehlZLv7Tw=
=dCZK
-----END PGP SIGNATURE-----