-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Thu, 30 Jul 2026 11:05:35 -0400
Source: chromium
Architecture: source
Version: 151.0.7922.71-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (151.0.7922.71-1~deb13u1) trixie-security; urgency=high
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-17650: Use after free in Compositing. Reported by Google.
- CVE-2026-17651: Insufficient validation of untrusted input in Dawn.
Reported by Google.
- CVE-2026-17652: Use after free in Views. Reported by Google.
- CVE-2026-17653: Use after free in Skia. Reported by Google.
- CVE-2026-17654: Race in Updater. Reported by Google.
- CVE-2026-17655: Insufficient validation of untrusted input in ANGLE.
Reported by Google.
- CVE-2026-17656: Use after free in Ozone. Reported by Google.
- CVE-2026-17657: Use after free in Navigation.
Reported by c6eed09fc8b174b0f3eebedcceb1e792.
- CVE-2026-17658: Use after free in V8. Reported by
Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security.
- CVE-2026-17659: Inappropriate implementation in SiteIsolation.
Reported by Google.
- CVE-2026-17660: Insufficient validation of untrusted input in Network.
Reported by Google.
- CVE-2026-17661: Use after free in Loader. Reported by Google.
- CVE-2026-17662: Insufficient policy enforcement in Prefetch.
Reported by Google.
- CVE-2026-17663: Insufficient validation of untrusted input in GPU.
Reported by Google.
- CVE-2026-17664: Insufficient validation of untrusted input in Loader.
Reported by Google.
- CVE-2026-17665: Use after free in V8. Reported by Google.
- CVE-2026-17666: Cryptographic Flaw in Enterprise. Reported by Google.
- CVE-2026-17667: Uninitialized Use in ANGLE. Reported by Google.
- CVE-2026-17668: Uninitialized Use in ANGLE. Reported by Google.
- CVE-2026-17669: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17670: Use after free in Views. Reported by Google.
- CVE-2026-17671: Insufficient validation of untrusted input in ANGLE.
Reported by Google.
- CVE-2026-17672: Insufficient validation of untrusted input in
Chromecast. Reported by Google.
- CVE-2026-17673: Integer overflow in QUIC. Reported by Google.
- CVE-2026-17674: Inappropriate implementation in HTML.
Reported by Google.
- CVE-2026-17675: Out of bounds write in ANGLE. Reported by Google.
- CVE-2026-17676: Inappropriate implementation in ANGLE.
Reported by Google.
- CVE-2026-17677: Inappropriate implementation in ANGLE.
Reported by Google.
- CVE-2026-17678: Out of bounds read in ANGLE. Reported by Google.
- CVE-2026-17679: Insufficient validation of untrusted input in
Print Preview. Reported by Google.
- CVE-2026-17680: Heap buffer overflow in Color. Reported by Google.
- CVE-2026-17681: Insufficient validation of untrusted input in
Web Authentication. Reported by Google.
- CVE-2026-17682: Integer overflow in ANGLE. Reported by Google.
- CVE-2026-17683: Inappropriate implementation in ANGLE.
Reported by Google.
- CVE-2026-17684: Insufficient validation of untrusted input in
Chrome for iOS. Reported by Google.
- CVE-2026-17685: Use after free in Autofill. Reported by Google.
- CVE-2026-17686: Insufficient validation of untrusted input in
Passwords. Reported by Google.
- CVE-2026-17687: Type Confusion in ANGLE. Reported by Google.
- CVE-2026-17688: Use after free in Input. Reported by Google.
- CVE-2026-17689: Uninitialized Use in ANGLE. Reported by Google.
- CVE-2026-17690: Insufficient validation of untrusted input in PDF.
Reported by Google.
- CVE-2026-17691: Out of bounds write in ANGLE. Reported by Google.
- CVE-2026-17692: Use after free in DataTransfer. Reported by Google.
- CVE-2026-17693: Inappropriate implementation in FileSystem.
Reported by Google.
- CVE-2026-17694: Use after free in DOM. Reported by Google.
- CVE-2026-17695: Inappropriate implementation in ANGLE.
Reported by Google.
- CVE-2026-17696: Side-channel information leakage in Media.
Reported by Google.
- CVE-2026-17697: Type Confusion in ANGLE. Reported by Google.
- CVE-2026-17698: Insufficient validation of untrusted input in UI.
Reported by Google.
- CVE-2026-17699: Use after free in Views. Reported by Google.
- CVE-2026-17700: Insufficient validation of untrusted input in Actor.
Reported by Google.
- CVE-2026-17701: Out of bounds read in ANGLE. Reported by Google.
- CVE-2026-17702: Inappropriate implementation in Skia.
Reported by Google.
- CVE-2026-17703: Policy bypass in Chrome for iOS. Reported by Google.
- CVE-2026-17704: Use after free in ANGLE. Reported by Google.
- CVE-2026-17705: Integer overflow in libxml.
Reported by ebassi of Igalia.
- CVE-2026-17706: Insufficient validation of untrusted input in Media.
Reported by Google.
- CVE-2026-17707: Uninitialized Use in Media. Reported by Google.
- CVE-2026-17708: Use after free in Audio. Reported by Google.
- CVE-2026-17709: Race in Downloads. Reported by Google.
- CVE-2026-17710: Inappropriate implementation in MHTML.
Reported by Google.
- CVE-2026-17711: Race in Downloads. Reported by Google.
- CVE-2026-17712: Race in Skia. Reported by Google.
- CVE-2026-17713: Insufficient validation of untrusted input
in Accessibility. Reported by Google.
- CVE-2026-17714: Uninitialized Use in ANGLE. Reported by Google.
- CVE-2026-17715: Inappropriate implementation in Passwords.
Reported by Google.
- CVE-2026-17716: Use after free in Updater. Reported by Google.
- CVE-2026-17717: Integer overflow in ANGLE. Reported by Google.
- CVE-2026-17718: Use after free in ANGLE. Reported by Google.
- CVE-2026-17719: Use after free in Input. Reported by Google.
- CVE-2026-17720: Insufficient policy enforcement in Passwords.
Reported by Google.
- CVE-2026-17721: Out of bounds write in ANGLE. Reported by Google.
- CVE-2026-17722: Object lifecycle issue in WebView. Reported by Google.
- CVE-2026-17723: Use after free in Media. Reported by Google.
- CVE-2026-17724: Race in Chrome for iOS. Reported by Google.
- CVE-2026-17725: Type Confusion in V8. Reported by nh.dev2022.
- CVE-2026-17726: Integer overflow in WebGL. Reported by Google.
- CVE-2026-17727: Out of bounds write in WebGL. Reported by Google.
- CVE-2026-17728: Inappropriate implementation in Extensions.
Reported by Suhas S P.
- CVE-2026-17758: Heap buffer overflow in Dawn.
Reported by Hyeonjun Ahn (@_deayzl).
- CVE-2026-17732: Inappropriate implementation in SVG.
Reported by Lyra Rebane (rebane2001).
- CVE-2026-17729: Use after free in V8. Reported by wang1r && lhfff.
- CVE-2026-17730: Side-channel information leakage in Autofill.
Reported by Google.
- CVE-2026-17731: Inappropriate implementation in Autofill. Reported by
Manojkumar Jaganathan Aka TheWhiteEvil with HackerBro Technologies.
- CVE-2026-17733: Inappropriate implementation in QUIC.
Reported by Google.
- CVE-2026-17734: Inappropriate implementation in Autofill.
Reported by Google.
- CVE-2026-17735: Insufficient validation of untrusted input in BFCache.
Reported by Google.
- CVE-2026-17736: Insufficient validation of untrusted input in WebView.
Reported by Google.
- CVE-2026-17737: Use after free in Bluetooth. Reported by Google.
- CVE-2026-17738: Insufficient validation of untrusted input in
Payments. Reported by Google.
- CVE-2026-17739: Insufficient policy enforcement in Extensions.
Reported by Google.
- CVE-2026-17740: Uninitialized Use in ANGLE. Reported by Google.
- CVE-2026-17741: Insufficient validation of untrusted input in WebView.
Reported by Google.
- CVE-2026-17742: Insufficient policy enforcement in Payments.
Reported by Google.
- CVE-2026-17743: Insufficient policy enforcement in ControlledFrame.
Reported by Google.
- CVE-2026-17744: Inappropriate implementation in File Input.
Reported by Google.
- CVE-2026-17745: Out of bounds read in Skia. Reported by Google.
- CVE-2026-17746: Use after free in GPU. Reported by Google.
- CVE-2026-17747: Insufficient validation of untrusted input in
Payments. Reported by Google.
- CVE-2026-17748: Inappropriate implementation in Extensions.
Reported by Google.
- CVE-2026-17749: Insufficient validation of untrusted input in
Extensions. Reported by Google.
- CVE-2026-17750: Use after free in ANGLE. Reported by Google.
- CVE-2026-17751: Inappropriate implementation in AdFilter.
Reported by Google.
- CVE-2026-17752: Use after free in Views. Reported by Google.
- CVE-2026-17753: Inappropriate implementation in Autofill.
Reported by Google.
- CVE-2026-17754: Inappropriate implementation in Blink.
Reported by Google.
- CVE-2026-17755: Incorrect security UI in Extensions.
Reported by Google.
- CVE-2026-17756: Insufficient policy enforcement in Presentation.
Reported by Google.
- CVE-2026-17757: Uninitialized Use in Skia. Reported by Google.
- CVE-2026-17759: Uninitialized Use in Codecs. Reported by Google.
- CVE-2026-17760: Side-channel information leakage in NoStatePrefetch.
Reported by Google.
- CVE-2026-17761: Insufficient validation of untrusted input in
Chrome for iOS. Reported by Google.
- CVE-2026-17762: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17763: Inappropriate implementation in GPU.
Reported by Google.
- CVE-2026-17764: Inappropriate implementation in FedCM.
Reported by Google.
- CVE-2026-17765: Inappropriate implementation in WebProtect.
Reported by Google.
- CVE-2026-17766: Insufficient validation of untrusted input in
Clipboard. Reported by Google.
- CVE-2026-17767: Insufficient validation of untrusted input in WebView.
Reported by Google.
- CVE-2026-17768: Insufficient validation of untrusted input in
WebSockets. Reported by Google.
- CVE-2026-17769: Insufficient validation of untrusted input in Cast.
Reported by Google.
- CVE-2026-17770: Out of bounds read in Media. Reported by Google.
- CVE-2026-17771: Uninitialized Use in Skia. Reported by Google.
- CVE-2026-17772: Out of bounds read in WebGL. Reported by Google.
- CVE-2026-17773: Insufficient validation of untrusted input in Cast.
Reported by Google.
- CVE-2026-17774: Insufficient validation of untrusted input in
Variations. Reported by Google.
- CVE-2026-17775: Inappropriate implementation in PresentationAPI.
Reported by Google.
- CVE-2026-17776: Policy bypass in Receiver. Reported by Google.
- CVE-2026-17777: Inappropriate implementation in Autofill.
Reported by Google.
- CVE-2026-17778: Use after free in Extensions. Reported by Google.
- CVE-2026-17779: Inappropriate implementation in Site Isolation.
Reported by Google.
- CVE-2026-17780: Inappropriate implementation in Isolated Web Apps.
Reported by Google.
- CVE-2026-17781: Inappropriate implementation in Extensions.
Reported by Google.
- CVE-2026-17782: Incorrect security UI in Chrome for iOS.
Reported by Google.
- CVE-2026-17783: Inappropriate implementation in Loader.
Reported by Google.
- CVE-2026-17784: Use after free in Audio. Reported by Google.
- CVE-2026-17785: Uninitialized Use in ANGLE. Reported by Google.
- CVE-2026-17786: Insufficient validation of untrusted input in DevTools.
Reported by Google.
- CVE-2026-17787: Inappropriate implementation in DevTools.
Reported by Google.
- CVE-2026-17788: Inappropriate implementation in Blink.
Reported by Google.
- CVE-2026-17789: Insufficient validation of untrusted input in
Chrome for iOS. Reported by Google.
- CVE-2026-17790: Uninitialized Use in ANGLE. Reported by Google.
- CVE-2026-17791: Insufficient validation of untrusted input in Payments.
Reported by Google.
- CVE-2026-17792: Inappropriate implementation in Credential Management.
Reported by Google.
- CVE-2026-17793: Inappropriate implementation in Messages.
Reported by Google.
- CVE-2026-17794: Insufficient validation of untrusted input in Mobile.
Reported by Google.
- CVE-2026-17795: Insufficient validation of untrusted input in
GetUserMedia. Reported by Mihnea Nicolau.
- CVE-2026-17796: Side-channel information leakage in WebXR.
Reported by Google.
- CVE-2026-17797: Inappropriate implementation in CSS. Reported by Google
- CVE-2026-17798: Inappropriate implementation in Cast.
Reported by Google.
- CVE-2026-17799: Insufficient validation of untrusted input in
Safe Browsing. Reported by Google.
- CVE-2026-17800: Side-channel information leakage in MediaRecording.
Reported by Google.
- CVE-2026-17801: Out of bounds memory access in ANGLE.
Reported by Google.
- CVE-2026-17802: Side-channel information leakage in GPU.
Reported by Google.
- CVE-2026-17803: Insufficient validation of untrusted input in
Save to Drive. Reported by Google.
- CVE-2026-17804: Use after free in Media. Reported by Google.
- CVE-2026-17805: Insufficient policy enforcement in Glic.
Reported by Google.
- CVE-2026-17806: Insufficient validation of untrusted input in
Extensions. Reported by Google.
- CVE-2026-17807: Use after free in V8. Reported by Google.
- CVE-2026-17808: Uninitialized Use in WebGL. Reported by Google.
- CVE-2026-17809: Insufficient validation of untrusted input in
Extensions. Reported by Google.
- CVE-2026-17810: Uninitialized Use in Dawn. Reported by Google.
- CVE-2026-17811: Use after free in ANGLE. Reported by Google.
- CVE-2026-17812: Inappropriate implementation in DigitalCredentials.
Reported by Google.
- CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS.
Reported by Google.
- CVE-2026-17814: Insufficient validation of untrusted input in
Chrome for iOS. Reported by Google.
- CVE-2026-17815: Insufficient policy enforcement in GuestView.
Reported by Google.
- CVE-2026-17816: Inappropriate implementation in Speech.
Reported by Google.
- CVE-2026-17817: Inappropriate implementation in ReportingAndNEL.
Reported by Google.
- CVE-2026-17818: Inappropriate implementation in Network.
Reported by Google.
- CVE-2026-17819: Inappropriate implementation in WebAppInstalls.
Reported by Google.
- CVE-2026-17820: Insufficient policy enforcement in Autofill.
Reported by Google.
- CVE-2026-17821: Insufficient policy enforcement in Extensions.
Reported by Google.
- CVE-2026-17822: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17823: Insufficient policy enforcement in WebXR.
Reported by Google.
- CVE-2026-17824: Insufficient policy enforcement in ServiceWorker.
Reported by Google.
- CVE-2026-17825: Insufficient policy enforcement in Passwords.
Reported by Google.
- CVE-2026-17826: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17827: Inappropriate implementation in CSS. Reported by Google
- CVE-2026-17828: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17829: Insufficient policy enforcement in Passwords.
Reported by Google.
- CVE-2026-17830: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17831: Insufficient validation of untrusted input in
Passwords. Reported by Google.
- CVE-2026-17832: Use after free in ANGLE. Reported by Google.
- CVE-2026-17833: Inappropriate implementation in Passwords.
Reported by Google.
- CVE-2026-17834: Inappropriate implementation in Passwords.
Reported by Google.
- CVE-2026-17835: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17836: Use after free in V8. Reported by yupyon.itome.
- CVE-2026-17837: Insufficient validation of untrusted input in
DevTools. Reported by Google.
- CVE-2026-17838: Incorrect security UI in Chrome for iOS.
Reported by Google.
- CVE-2026-17839: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17840: Incorrect security UI in Passwords. Reported by Google
- CVE-2026-17841: Race in Chrome for iOS. Reported by Google.
- CVE-2026-17842: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17843: Inappropriate implementation in CSS. Reported by Google
- CVE-2026-17844: Insufficient validation of untrusted input in Cast.
Reported by Google.
- CVE-2026-17845: Inappropriate implementation in CSS. Reported by Google
- CVE-2026-17846: Inappropriate implementation in Media.
Reported by Google.
- CVE-2026-17847: Insufficient validation of untrusted input in ANGLE.
Reported by Google.
- CVE-2026-17848: Insufficient validation of untrusted input in Codecs.
Reported by Ameen Basha M K.
- CVE-2026-17849: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17850: Inappropriate implementation in Permissions.
Reported by Tech Division (@taiphung) - Mobifone Digital Payment.
- CVE-2026-17851: Side-channel information leakage in Autofill.
Reported by Google.
- CVE-2026-17852: Inappropriate implementation in Media Router.
Reported by Google.
- CVE-2026-17853: Inappropriate implementation in DevTools.
Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team.
- CVE-2026-17854: Insufficient policy enforcement in WebMCP.
Reported by Google.
- CVE-2026-17855: Race in DevTools. Reported by Google.
- CVE-2026-17856: Inappropriate implementation in Network.
Reported by Google.
- CVE-2026-17857: Inappropriate implementation in Network.
Reported by Google.
- CVE-2026-17858: Uninitialized Use in WebNN. Reported by Google.
- CVE-2026-17859: Side-channel information leakage in Favicons.
Reported by Google.
- CVE-2026-17860: Insufficient validation of untrusted input in Mobile.
Reported by Google.
- CVE-2026-17861: Insufficient validation of untrusted input in Updater.
Reported by Google.
- CVE-2026-17862: Use after free in Tracing. Reported by Google.
- CVE-2026-17863: Inappropriate implementation in Browser.
Reported by Google.
- CVE-2026-17864: Inappropriate implementation in Updater.
Reported by Google.
- CVE-2026-17865: Inappropriate implementation in Crypto.
Reported by Google.
- CVE-2026-17866: Type Confusion in Tab. Reported by Google.
- CVE-2026-17867: Insufficient validation of untrusted input in Dawn.
Reported by Google.
- CVE-2026-17868: Insufficient policy enforcement in USB.
Reported by Ariel Simon.
- CVE-2026-17869: Out of bounds read in WebXR. Reported by Google.
- CVE-2026-17870: Insufficient validation of untrusted input in Cast.
Reported by Google.
- CVE-2026-17871: Inappropriate implementation in Passwords.
Reported by Google.
- CVE-2026-17872: Cryptographic Flaw in WebAppInstalls.
Reported by Google.
- CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS.
Reported by Google.
- CVE-2026-17874: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17875: Use after free in PDFium. Reported by Google.
- CVE-2026-17876: Inappropriate implementation in Payments.
Reported by Google.
- CVE-2026-17877: Inappropriate implementation in Chromoting.
Reported by Google.
- CVE-2026-17878: Inappropriate implementation in CSS. Reported by Google
- CVE-2026-17879: Inappropriate implementation in Autofill.
Reported by Google.
- CVE-2026-17880: Inappropriate implementation in Autofill.
Reported by Google.
- CVE-2026-17881: Use after free in WebXR. Reported by Google.
- CVE-2026-17882: Policy bypass in Extensions. Reported by Google.
- CVE-2026-17883: Inappropriate implementation in Headless.
Reported by Google.
- CVE-2026-17884: Object lifecycle issue in WebRTC. Reported by Google.
- CVE-2026-17885: Inappropriate implementation in Paint.
Reported by Google.
- CVE-2026-17886: Use after free in Enterprise. Reported by Google.
- CVE-2026-17887: Use after free in TabStrip. Reported by Google.
- CVE-2026-17888: Insufficient validation of untrusted input in WebUI.
Reported by Google.
- CVE-2026-17889: Uninitialized Use in WebXR. Reported by Google.
- CVE-2026-17890: Insufficient validation of untrusted input in DevTools.
Reported by Google.
- CVE-2026-17891: Use after free in ANGLE. Reported by Google.
- CVE-2026-17892: Inappropriate implementation in WebXR.
Reported by Google.
- CVE-2026-17893: Insufficient validation of untrusted input in Updater.
Reported by Google.
- CVE-2026-17894: Use after free in Views. Reported by Google.
- CVE-2026-17895: Inappropriate implementation in DataTransfer.
Reported by hongan@calif.io.
- CVE-2026-17896: Use after free in DevTools. Reported by Google.
- CVE-2026-17897: Inappropriate implementation in ORB.
Reported by Sharkkcode.
- CVE-2026-17898: Use after free in DevTools. Reported by Syn4pse.
- CVE-2026-17899: Insufficient policy enforcement in DevTools.
Reported by asnine.
- CVE-2026-17900: Inappropriate implementation in Enterprise.
Reported by Google.
- CVE-2026-17901: Inappropriate implementation in Sharing.
Reported by Google.
- CVE-2026-17902: Inappropriate implementation in Editing.
Reported by Google.
- CVE-2026-17903: Insufficient policy enforcement in Chromecast.
Reported by Google.
- CVE-2026-17904: Insufficient policy enforcement in NFC.
Reported by Google.
- CVE-2026-17905: Inappropriate implementation in SurfaceCapture.
Reported by Google.
- CVE-2026-17906: Insufficient validation of untrusted input in
Bluetooth. Reported by Google.
- CVE-2026-17907: Side-channel information leakage in Network.
Reported by Google.
- CVE-2026-17908: Insufficient validation of untrusted input in
Printing. Reported by Google.
- CVE-2026-17909: Insufficient validation of untrusted input in
Isolated Web Apps. Reported by Google.
- CVE-2026-17910: Insufficient policy enforcement in NFC.
Reported by Google.
- CVE-2026-17911: Insufficient policy enforcement in SVG.
Reported by Google.
- CVE-2026-17912: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17913: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17914: Side-channel information leakage in Skia.
Reported by Google.
- CVE-2026-17915: Inappropriate implementation in WebView.
Reported by Google.
- CVE-2026-17916: Insufficient policy enforcement in Settings.
Reported by Itzik Chimino.
- CVE-2026-17917: Policy bypass in Chrome for iOS. Reported by Google.
- CVE-2026-17918: Use after free in Sync. Reported by Google.
- CVE-2026-17919: Insufficient policy enforcement in Enterprise.
Reported by Google.
- CVE-2026-17920: Use after free in V8. Reported by Google.
- CVE-2026-17921: Insufficient validation of untrusted input in
Navigation. Reported by Google.
- CVE-2026-17922: Inappropriate implementation in Enterprise.
Reported by Google.
- CVE-2026-17923: Policy bypass in Enterprise. Reported by Google.
- CVE-2026-17924: Use after free in DNS. Reported by Google.
- CVE-2026-17925: Inappropriate implementation in Cast.
Reported by Google.
- CVE-2026-17926: Insufficient validation of untrusted input in
DevTools. Reported by Google.
- CVE-2026-17927: Insufficient policy enforcement in DevTools.
Reported by Google.
- CVE-2026-17928: Inappropriate implementation in DataTransfer.
Reported by Google.
- CVE-2026-17929: Insufficient validation of untrusted input in
DevTools. Reported by Google.
- CVE-2026-17930: Insufficient validation of untrusted input in
Extensions. Reported by Google.
- CVE-2026-17931: Inappropriate implementation in DevTools.
Reported by Google.
- CVE-2026-17932: Use after free in DataTransfer. Reported by Google.
- CVE-2026-17933: Inappropriate implementation in DOMStorage.
Reported by Google.
- CVE-2026-17934: Insufficient validation of untrusted input in
DevTools. Reported by Google.
- CVE-2026-17935: Heap buffer overflow in Codecs. Reported by Google.
- CVE-2026-17936: Inappropriate implementation in DevTools.
Reported by Google.
- CVE-2026-17937: Inappropriate implementation in DevTools.
Reported by Google.
- CVE-2026-17938: Inappropriate implementation in FullScreen.
Reported by Google.
- CVE-2026-17939: Inappropriate implementation in Passwords.
Reported by Google.
- CVE-2026-17940: Insufficient validation of untrusted input in
Picture-in-Picture. Reported by Google.
- CVE-2026-17941: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17942: Side-channel information leakage in SVG.
Reported by Google.
- CVE-2026-17943: Inappropriate implementation in Parser.
Reported by Google.
- CVE-2026-17944: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17945: Inappropriate implementation in Navigation.
Reported by Google.
- CVE-2026-17946: Uninitialized Use in Dawn. Reported by Google.
- CVE-2026-17947: Use after free in WebSockets. Reported by Google.
- CVE-2026-17948: Type Confusion in V8. Reported by Google.
- CVE-2026-17949: Uninitialized Use in GPU. Reported by Google.
- CVE-2026-17950: Policy bypass in Safebrowsing. Reported by Google.
- CVE-2026-17951: Heap buffer overflow in WebRTC. Reported by Google.
- CVE-2026-17952: Inappropriate implementation in V8. Reported by Google
- CVE-2026-17953: Insufficient policy enforcement in WebView.
Reported by Google.
- CVE-2026-17954: Policy bypass in MHTML. Reported by Google.
- CVE-2026-17955: Insufficient validation of untrusted input in
Payments. Reported by Google.
- CVE-2026-17956: Inappropriate implementation in Scheduling.
Reported by Google.
- CVE-2026-17957: Inappropriate implementation in CORS.
Reported by Google.
- CVE-2026-17958: Inappropriate implementation in Views.
Reported by Google.
- CVE-2026-17959: Inappropriate implementation in Network.
Reported by Google.
- CVE-2026-17960: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17961: Inappropriate implementation in Session.
Reported by Google.
- CVE-2026-17962: Inappropriate implementation in Blink.
Reported by Google.
- CVE-2026-17963: Inappropriate implementation in SVG. Reported by Google
- CVE-2026-17964: Incorrect security UI in UI. Reported by Google.
- CVE-2026-17965: Incorrect security UI in Chrome for iOS.
Reported by Google.
- CVE-2026-17966: Inappropriate implementation in Views.
Reported by Google.
- CVE-2026-17967: Use after free in Chrome for iOS. Reported by Google.
- CVE-2026-17968: Uninitialized Use in WebXR. Reported by Google.
- CVE-2026-17969: Inappropriate implementation in Passwords.
Reported by Google.
- CVE-2026-17970: Insufficient validation of untrusted input in
Passwords. Reported by Google.
- CVE-2026-17971: Inappropriate implementation in Frame.
Reported by Google.
- CVE-2026-17972: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-17973: Inappropriate implementation in Views.
Reported by Google.
- CVE-2026-17974: Insufficient policy enforcement in DevTools.
Reported by Google.
- CVE-2026-17975: Inappropriate implementation in IME. Reported by Google
- CVE-2026-17976: Policy bypass in Extensions. Reported by Google.
- CVE-2026-17977: Policy bypass in CSS. Reported by Google.
- CVE-2026-17978: Side-channel information leakage in WebCodecs.
Reported by Google.
- CVE-2026-17979: Race in V8. Reported by Google.
- CVE-2026-17980: Inappropriate implementation in UI. Reported by Google
- CVE-2026-17981: Inappropriate implementation in Blink.
Reported by Google.
- CVE-2026-17982: Insufficient validation of untrusted input in Cast.
Reported by Google.
- CVE-2026-17983: Incorrect security UI in Global Media Controls.
Reported by Google.
- CVE-2026-17984: Inappropriate implementation in Browser.
Reported by Google.
- CVE-2026-17985: Insufficient policy enforcement in Speech.
Reported by Google.
- CVE-2026-17986: Insufficient policy enforcement in Bluetooth.
Reported by Google.
- CVE-2026-17987: Insufficient validation of untrusted input in
Notifications. Reported by Google.
- CVE-2026-17988: Insufficient validation of untrusted input in
Navigation. Reported by Google.
- CVE-2026-17989: Type Confusion in V8. Reported by Google.
- CVE-2026-17990: Insufficient validation of untrusted input in
WebAuthn. Reported by Google.
- CVE-2026-17991: Insufficient validation of untrusted input in AI.
Reported by Google.
- CVE-2026-17992: Uninitialized Use in Skia. Reported by Google.
- CVE-2026-17993: Race in Updater. Reported by Google.
- CVE-2026-17994: Inappropriate implementation in Media.
Reported by Google.
- CVE-2026-17995: Out of bounds read in Dawn. Reported by sm1ee, ksw9722
- CVE-2026-17996: Inappropriate implementation in Browser.
Reported by Google.
- CVE-2026-17997: Inappropriate implementation in Passwords.
Reported by Google.
- CVE-2026-17998: Incorrect security UI in Extensions. Reported by Google
- CVE-2026-17999: Incorrect security UI in PictureInPicture.
Reported by Google.
- CVE-2026-18000: Insufficient policy enforcement in USB.
Reported by Google.
- CVE-2026-18001: Inappropriate implementation in WebGL.
Reported by Google.
- CVE-2026-18002: Insufficient validation of untrusted input in
Google Lens. Reported by Google.
- CVE-2026-18003: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-18004: Insufficient policy enforcement in Speech.
Reported by Google.
- CVE-2026-18005: Inappropriate implementation in WebXR.
Reported by Google.
- CVE-2026-18006: Inappropriate implementation in Google Lens.
Reported by Google.
- CVE-2026-18007: Inappropriate implementation in Input.
Reported by Google.
- CVE-2026-18008: Inappropriate implementation in Settings.
Reported by Google.
- CVE-2026-18009: Insufficient validation of untrusted input in
Passwords. Reported by Google.
- CVE-2026-18010: Inappropriate implementation in Passwords.
Reported by Google.
- CVE-2026-18011: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-18012: Use after free in PDFium. Reported by Google.
- CVE-2026-18013: Inappropriate implementation in Chrome for iOS.
Reported by Google.
- CVE-2026-18014: Insufficient validation of untrusted input in
DevTools. Reported by Google.
- CVE-2026-18015: Inappropriate implementation in Tint.
Reported by Google.
- CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS.
Reported by Google.
- CVE-2026-18017: Use after free in Dawn. Reported by Google.
- CVE-2026-18018: Inappropriate implementation in Updater.
Reported by Google.
- CVE-2026-18019: Side-channel information leakage in Media.
Reported by Google.
- CVE-2026-16807: Out of bounds write in Codecs. Reported by Google.
- CVE-2026-16806: Use after free in WebMCP. Reported by Google.
- CVE-2026-16805: Use after free in Blink. Reported by Google.
- CVE-2026-16804: Use after free in Input. Reported by Google.
.
[ Timothy Pearson ]
* d/patches/ppc64le:
- core/baseline-isa-3-0.patch: refresh for upstream changes
.
chromium (151.0.7922.47-1) unstable; urgency=high
.
[ Andres Salomon ]
* New upstream stable release.
* d/patches:
- upstream/sysroot.patch: drop, merged upstream.
- upstream/ar-path1.patch: drop, merged upstream.
- upstream/ar-path2.patch: drop, merged upstream.
- fixes/widevine-locations.patch: refresh.
- fixes/material-utils.patch: refresh for lots of upstream changes.
- disable/catapult.patch: refresh and add another build fix.
- disable/widevine-cdm-cu.patch: fix this - it broke at some point.
- system/jpeg.patch: refresh.
- llvm-19/clang19.patch: refresh.
- trixie/gn-inputs.patch: refresh.
- ungoogled/disable-ai.patch: sync from u-c.
- ungoogled/disable-privacy-sandbox.patch: sync from u-c.
- system/golang.patch: add patch to build using packaged golang instead of
bundled go binary.
- llvm-19/privatefriends.patch: add yet another clang-19 workaround, this
one for the compiler ignoring class friend declarations.
- llvm-19/constexpr.patch: add clang-19 constexpr workaround.
- trixie/nodejs-set-intersection.patch: drop, now that we've got the
pre-gen stuff.
- trixie/nodejs-main.patch: drop, now that we've got the pre-gen stuff
[trixie, bookworm].
- trixie/node20-compat.patch: drop, now that we've got the pre-gen
stuff [trixie, bookworm].
- trixie/bindgen-boringssl.patch: drop, now that we've got the pre-gen
stuff [trixie, bookworm].
- rust-1.85/let-chains.patch: add another build fix for older rustc
[trixie, bookworm].
- bookworm/freetype-COLRV1.patch: refresh [bookworm].
- bookworm/bindgen.patch: drop, now that we've got pre-gen [bookworm].
- bookworm/node18-compat.patch: drop, now that we've got pre-gen
[bookworm].
* d/control: add build-dep on golang.
.
[ Daniel Richard G. ]
* d/patches:
- bookworm/gn-absl.patch: Refresh [bookworm].
- bookworm/gn-funcs.patch: Refresh, adjust indentation, and fix new call
to filter_labels_include() [bookworm].
- bookworm/gn-revert-path-exists.patch: Add fix for new call to
path_exists().
- llvm-19/clang19.patch: Fix new instance of -Wlifetime-safety-permissive.
- llvm-19/value-or.patch: Fix new instance of .value_or().
* d/rules: Set CPPFLAGS explicitly so that the env var is always populated.
* New "pre-gen" framework for generating, saving, and consuming source files
that normally require recent versions of bindgen, golang, nodejs et al. in
order to be generated by the build. This will facilitate building Chromium
for the stable releases, as those recent versions will no longer need to
be backported, and ugly compatibility hacks no longer needed. Please see
pre-gen/README.Debian for more information. New/updated files:
- d/deb_pre_gen.py: Core implementation module of the framework.
- d/patches/debianization/pre-gen.patch: Hook the core module into various
Chromium build-tooling scripts.
- d/rules: Create and clean up appropriate pre-gen/arch symlink, plus an
"init-pre-gen" target to create the .orig-pre-gen.tar.xz source tarball.
- d/scripts/init-pre-gen.sh: Maintainer script called by "init-pre-gen"
target that does most of the work of creating the tarball.
.
[ Timothy Pearson ]
* d/patches/ppc64le:
- fixes/fix-partition-alloc-compile.patch: remove
- sandbox/0001-sandbox-Enable-seccomp_bpf-for-ppc64.patch: refresh for
upstream changes
- third_party/0001-Add-PPC64-support-for-boringssl.patch: refresh for
upstream changes
- third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream
changes
- third_party/skia-vsx-instructions.patch: refresh for upstream changes
Checksums-Sha1:
1a7ba2cebd5e606ee17d17d611758f888e9466e1 4398 chromium_151.0.7922.71-1~deb13u1.dsc
dc722fb3cb5384a2239c20c6d61472f194fcfb97 15040720 chromium_151.0.7922.71.orig-pre-gen.tar.xz
d4f2ffad3afdca20e1fb90d0f0a13d7d7701165f 952065332 chromium_151.0.7922.71.orig.tar.xz
bf2e312dd9a5ff44752b144e9bae6349d728eeae 548508 chromium_151.0.7922.71-1~deb13u1.debian.tar.xz
990d590a9067855fc821f862db07fa78d85dba76 27823 chromium_151.0.7922.71-1~deb13u1_source.buildinfo
Checksums-Sha256:
85481613bb4c83aab42489be1a96fa360f5f205be70473625d9b3677b6991858 4398 chromium_151.0.7922.71-1~deb13u1.dsc
de2b1399c3b7940f78fba757a5c1c61c10237881d6a73adb13c1718f3d8beb10 15040720 chromium_151.0.7922.71.orig-pre-gen.tar.xz
f7c8bb0c45c0488cb48a22fdc20ac3da2fa02ac89c67898ff6272b6fd0e1b11c 952065332 chromium_151.0.7922.71.orig.tar.xz
53c4ecabda14fc65cd9eeb91f90dea7057e00818c7f99217674c84b7dd006687 548508 chromium_151.0.7922.71-1~deb13u1.debian.tar.xz
b01157c7d2ba219df74b378d01f75f11201111139ff1841d5186fadb0306388d 27823 chromium_151.0.7922.71-1~deb13u1_source.buildinfo
Files:
6c7f66c21cabca9e43a424a6339dc437 4398 web optional chromium_151.0.7922.71-1~deb13u1.dsc
18416d706ff835ecc758c85372b2895f 15040720 web optional chromium_151.0.7922.71.orig-pre-gen.tar.xz
bab8784de46947929b26c06edf0b1747 952065332 web optional chromium_151.0.7922.71.orig.tar.xz
2ff9b7fe0e340eb3711fba5cbd2b676b 548508 web optional chromium_151.0.7922.71-1~deb13u1.debian.tar.xz
174f63848e0734aa63d629944a169b69 27823 web optional chromium_151.0.7922.71-1~deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmpsV/UUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjeFeA/9EjQT3uH96+uTqazBpWVJrflYLWY+
cbxVELsfKuQOGeGTQ4wf4ACe134/+AYi76Jfcfm1+kzrUzgQmp5s7y+PdT9I0hzJ
qZVr/2qFPSmi1V90G/SuOZRrWABgh21G3cz5o+dC1L5navRKDnst+lPalgIh8F0y
qJEmnOinawyUv4yaE7A0UBUBa+caIhaCC7mghW9chgiBl9Qp77haByNyjvCLdLXd
Qk5N8DElq+zdKFG1DYmujUN4eZyruBwLVpzU9aY9OWgCW03JPACXcgL5fRymP+bC
2S02qn06VkMG3f8VnROLktFjIvrdfNwiobP7pLbe7rPvzRaY0/JtCVW0ebGUhwij
MSv8bbMODRZe+tsgKxDzwOZsPk2ClnQcu/hSDKbnedoUB08Qzo1evx+tLU2AZKg3
iIPwh0lBaALH7awqX0dPKF8taoY8QQ0xmjuZdNQCuqyu6kJzxWvPijSMncjoJFpt
kIxZxGl2qCDW3/UJs8OFjXvLD7O/D0rOmpiTPt0oXvyLnPB9omshEvjxFPuT0vx+
65J+MAAo8BmQbFwld6jbFn9SVMsclUtgPkNO6EmhDGVk91knw0iEsWua39vB8ym/
4nOPVx80MUqicEM9bgkJWhX5rTYjTtG3684QhE7REOJsyjrFMHwcCY4EYtizFTjr
Hx1jCWI4gBp+WV0=
=6S4k
-----END PGP SIGNATURE-----