-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Fri, 07 Aug 2026 12:19:50 -0400
Source: chromium
Architecture: source
Version: 151.0.7922.108-1
Distribution: unstable
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (151.0.7922.108-1) unstable; urgency=high
.
[ Daniel Richard G. ]
* d/deb_pre_gen.py: Minor fixes to the pre-gen framework:
- Always record target outputs in an .OUTPUTS file, even if a target has
only a single output. This incurs only a small (tarball) size penalty,
and catches cases where there is disagreement on which is the first
output file of a .ninja target.
- Update the handling logic for generate_css_js_files.js, as the first
output file of the .ninja target changed from v150.
- Add an extra check to ensure that target outputs are unique.
* d/patches/debianization/pre-gen.patch: Tweak a script so that it outputs
a constant UUID, instead of one dependent on the build path.
* d/patches/system/golang.patch: Prevent the Go compiler from writing
things into our home dir, or accessing the network.
* d/scripts/init-pre-gen.sh: Don't hard-code the package name, as we might
be doing init-pre-gen for ungoogled-chromium.
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-19137: Use after free in WebGL. Reported by anonymous.
- CVE-2026-19149: Use after free in Aura. Reported by Google.
- CVE-2026-19154: Use after free in Skia. Reported by Google.
- CVE-2026-19157: Out of bounds write in ANGLE. Reported by Google.
- CVE-2026-19170: Use after free in WebGL. Reported by Muhammad Alifa
Ramdhan, Pan ZhenPeng, Billy Jheng Bing Jhong of STAR Labs SG Pte. Ltd.
- CVE-2026-19172: Use after free in Views. Reported by Google.
- CVE-2026-19169: Insufficient validation of untrusted input in
Contextual Tasks. Reported by Sven Dysthe (@svn-dys).
- CVE-2026-19168: Inappropriate implementation in V8.
Reported by XBOW and triaged by Andrés Luksenberg.
- CVE-2026-19138: Heap buffer overflow in CrashReporting.
Reported by Google.
- CVE-2026-19139: Race in CredentialProvider. Reported by Google.
- CVE-2026-19140: Use after free in GPU. Reported by Google.
- CVE-2026-19141: Use after free in Resources. Reported by Google.
- CVE-2026-19142: Use after free in Views. Reported by Google.
- CVE-2026-19143: Insufficient validation of untrusted input in
WebAPKs. Reported by Google.
- CVE-2026-19144: Use after free in HTML. Reported by Google.
- CVE-2026-19145: Use after free in Translate. Reported by Google.
- CVE-2026-19146: Uninitialized Use in GPU. Reported by Google.
- CVE-2026-19147: Use after free in Aura. Reported by Google.
- CVE-2026-19148: Out of bounds write in GPU. Reported by Google.
- CVE-2026-19150: Inappropriate implementation in V8. Reported by Google.
- CVE-2026-19151: Use after free in V8. Reported by Google.
- CVE-2026-19152: Inappropriate implementation in Navigation.
Reported by Google.
- CVE-2026-19153: Insufficient validation of untrusted input in Workers.
Reported by Google.
- CVE-2026-19155: Use after free in Payments. Reported by Google.
- CVE-2026-19156: Heap buffer overflow in Base.
Reported by Viktoria Zlatinova.
- CVE-2026-19158: Use after free in Views. Reported by Google.
- CVE-2026-19159: Use after free in Views. Reported by Google.
- CVE-2026-19160: Uninitialized Use in Skia. Reported by Google.
- CVE-2026-19161: Uninitialized Use in Skia. Reported by Google.
- CVE-2026-19162: Out of bounds write in V8.
Reported by OpenAI Codex Security (amyb).
- CVE-2026-19163: Use after free in Media. Reported by Google.
- CVE-2026-19164: Insufficient validation of untrusted input in Codecs.
Reported by Google.
- CVE-2026-19165: Use after free in Extensions. Reported by @bean5oup.
- CVE-2026-19166: Use after free in Web Authentication.
Reported by heesun.
- CVE-2026-19167: Integer overflow in GPU. Reported by Google.
- CVE-2026-19171: Use after free in Media. Reported by Google.
- CVE-2026-19173: Out of bounds write in Skia.
Reported by Vu Van Tien (@n0_Be3r).
- CVE-2026-19174: Integer overflow in V8.
Reported by Seunghyun Lee (@0x10n) of QED Audit (qedaudit.io).
- CVE-2026-19175: Use after free in Payments. Reported by Google.
- CVE-2026-19176: Use after free in Skia.
Reported by WinD39 - Huynh Dinh Vu.
- CVE-2026-19177: Insufficient validation of untrusted input in UI.
Reported by Fabian Wahle (Hap Security).
Checksums-Sha1:
9d1f4d05354b63d90b44370c5f7c729ab0859a99 4388 chromium_151.0.7922.108-1.dsc
5db7fe8f89a8fa3ff494e0286ff5f91358ab6ad5 15073392 chromium_151.0.7922.108.orig-pre-gen.tar.xz
9f6610225455ca29c87964dc04ad23e16873b605 949043204 chromium_151.0.7922.108.orig.tar.xz
af8e958c557ba45e5b116d51817f887b8016a9a6 549256 chromium_151.0.7922.108-1.debian.tar.xz
d75f338c1854b13896d0586b7f9369f7593afca6 28276 chromium_151.0.7922.108-1_source.buildinfo
Checksums-Sha256:
49e5099a0b874f14234f52f271c551780b91760061dac5ab75868ebf57c9af20 4388 chromium_151.0.7922.108-1.dsc
ec5cdca5594aadeeb7076fa27712278037b0ba6f00d5a8ae86602ed573bacba2 15073392 chromium_151.0.7922.108.orig-pre-gen.tar.xz
90e46be09cf71d1d426e6c8266657d85bf75faf958c2ac6d8d31786430ee3762 949043204 chromium_151.0.7922.108.orig.tar.xz
3cffbec2d0279cf597d766c6b5a217ece0d8b9161e97c9e30f8bd9eff8fd0981 549256 chromium_151.0.7922.108-1.debian.tar.xz
591564c0a45dccf1e2ced0b4c1327bdbb73e948280d092e89d431bd78033955a 28276 chromium_151.0.7922.108-1_source.buildinfo
Files:
7fa39ee391407bd52b6d00e5efcc9f6b 4388 web optional chromium_151.0.7922.108-1.dsc
8f3589d01d63ade127070eb61257aea5 15073392 web optional chromium_151.0.7922.108.orig-pre-gen.tar.xz
dd30a91d4d7d2e2a7dcd4d3b86e44ec4 949043204 web optional chromium_151.0.7922.108.orig.tar.xz
481bfb1f0a9f04039847549dcb7a632f 549256 web optional chromium_151.0.7922.108-1.debian.tar.xz
86c3d05f8ded8882dea4cd2a6a63dc3c 28276 web optional chromium_151.0.7922.108-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmp2ncoUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjdFXg/9GmPFb5U5n5K5piDBd1jHO0/wzX5o
ZYmGmDSCT6cVaSbjRmO6zjuQ3aMOTO4cGi3IDaOrCGFFHUiKKoBtWXuB4tVk3b3K
zqPnh6KMSkAbgs7L/04dm+Bow2AWIVjMoAoA5LS6HlveQwewc6uKRpmMyIkbCkvM
C0nX2/LgUL2Fwoq9nUcZhCSnjdjBf9U/e0pRnD8udYGI8w0kzTQd8LSuxjhYd75F
b465J7KTlSq+NXfg6Teh+Sg3gahaFDrWFnxTOcr6HBkAuBF428hNIe1321nac144
GVRIqtWn0fL6dSyslwHLaraUmiBaVtdWhL6vbLSPMm4lRxPteVxYx5YN8SpKDSDl
CaisyLCiWKkv3ivdJeqT4JEV1Vmrqyo4xrfFjFSjqxXunSft4srA6lfADpvWuWyp
e07/nyRD7VsQHRuvWcSNmygFFlpSAJr9I1TjDwo1CHbDaH8p7VmjgfaNxNXCVJWD
mBS0wILJSeWIUqrjBInd68ZR9K/O6njTuIbfIbdVCrrPZYskbKJT/d0wXMDHL/ny
6MKsJOsxY6TBZESPc7Npb5dIqj6ldD25HqUmCSdVBTjZuZeGhw3rS4n/mdcc6WdO
AX9rqGQQjFM9PKJSPEG6lBchZCLmECd2/I9yZAb0BZ6BwMG8Mfh0QgXCZ7k0B/73
zNYFcUttppRvun8=
=2VlT
-----END PGP SIGNATURE-----