-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Fri, 07 Aug 2026 12:19:50 -0400
Source: chromium
Architecture: source
Version: 151.0.7922.108-1~deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (151.0.7922.108-1~deb12u1) bookworm-security; urgency=high
.
[ Daniel Richard G. ]
* d/deb_pre_gen.py: Minor fixes to the pre-gen framework:
- Always record target outputs in an .OUTPUTS file, even if a target has
only a single output. This incurs only a small (tarball) size penalty,
and catches cases where there is disagreement on which is the first
output file of a .ninja target.
- Update the handling logic for generate_css_js_files.js, as the first
output file of the .ninja target changed from v150.
- Add an extra check to ensure that target outputs are unique.
* d/patches/debianization/pre-gen.patch: Tweak a script so that it outputs
a constant UUID, instead of one dependent on the build path.
* d/patches/system/golang.patch: Prevent the Go compiler from writing
things into our home dir, or accessing the network.
* d/scripts/init-pre-gen.sh: Don't hard-code the package name, as we might
be doing init-pre-gen for ungoogled-chromium.
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-19137: Use after free in WebGL. Reported by anonymous.
- CVE-2026-19149: Use after free in Aura. Reported by Google.
- CVE-2026-19154: Use after free in Skia. Reported by Google.
- CVE-2026-19157: Out of bounds write in ANGLE. Reported by Google.
- CVE-2026-19170: Use after free in WebGL. Reported by Muhammad Alifa
Ramdhan, Pan ZhenPeng, Billy Jheng Bing Jhong of STAR Labs SG Pte. Ltd.
- CVE-2026-19172: Use after free in Views. Reported by Google.
- CVE-2026-19169: Insufficient validation of untrusted input in
Contextual Tasks. Reported by Sven Dysthe (@svn-dys).
- CVE-2026-19168: Inappropriate implementation in V8.
Reported by XBOW and triaged by Andrés Luksenberg.
- CVE-2026-19138: Heap buffer overflow in CrashReporting.
Reported by Google.
- CVE-2026-19139: Race in CredentialProvider. Reported by Google.
- CVE-2026-19140: Use after free in GPU. Reported by Google.
- CVE-2026-19141: Use after free in Resources. Reported by Google.
- CVE-2026-19142: Use after free in Views. Reported by Google.
- CVE-2026-19143: Insufficient validation of untrusted input in
WebAPKs. Reported by Google.
- CVE-2026-19144: Use after free in HTML. Reported by Google.
- CVE-2026-19145: Use after free in Translate. Reported by Google.
- CVE-2026-19146: Uninitialized Use in GPU. Reported by Google.
- CVE-2026-19147: Use after free in Aura. Reported by Google.
- CVE-2026-19148: Out of bounds write in GPU. Reported by Google.
- CVE-2026-19150: Inappropriate implementation in V8. Reported by Google.
- CVE-2026-19151: Use after free in V8. Reported by Google.
- CVE-2026-19152: Inappropriate implementation in Navigation.
Reported by Google.
- CVE-2026-19153: Insufficient validation of untrusted input in Workers.
Reported by Google.
- CVE-2026-19155: Use after free in Payments. Reported by Google.
- CVE-2026-19156: Heap buffer overflow in Base.
Reported by Viktoria Zlatinova.
- CVE-2026-19158: Use after free in Views. Reported by Google.
- CVE-2026-19159: Use after free in Views. Reported by Google.
- CVE-2026-19160: Uninitialized Use in Skia. Reported by Google.
- CVE-2026-19161: Uninitialized Use in Skia. Reported by Google.
- CVE-2026-19162: Out of bounds write in V8.
Reported by OpenAI Codex Security (amyb).
- CVE-2026-19163: Use after free in Media. Reported by Google.
- CVE-2026-19164: Insufficient validation of untrusted input in Codecs.
Reported by Google.
- CVE-2026-19165: Use after free in Extensions. Reported by @bean5oup.
- CVE-2026-19166: Use after free in Web Authentication.
Reported by heesun.
- CVE-2026-19167: Integer overflow in GPU. Reported by Google.
- CVE-2026-19171: Use after free in Media. Reported by Google.
- CVE-2026-19173: Out of bounds write in Skia.
Reported by Vu Van Tien (@n0_Be3r).
- CVE-2026-19174: Integer overflow in V8.
Reported by Seunghyun Lee (@0x10n) of QED Audit (qedaudit.io).
- CVE-2026-19175: Use after free in Payments. Reported by Google.
- CVE-2026-19176: Use after free in Skia.
Reported by WinD39 - Huynh Dinh Vu.
- CVE-2026-19177: Insufficient validation of untrusted input in UI.
Reported by Fabian Wahle (Hap Security).
Checksums-Sha1:
2233c9f05674b343d60c2ce44134a21e32dd8596 4374 chromium_151.0.7922.108-1~deb12u1.dsc
5db7fe8f89a8fa3ff494e0286ff5f91358ab6ad5 15073392 chromium_151.0.7922.108.orig-pre-gen.tar.xz
9f6610225455ca29c87964dc04ad23e16873b605 949043204 chromium_151.0.7922.108.orig.tar.xz
502aa4b5c55e2b51d4afd7db9766c90f7decbb3e 557200 chromium_151.0.7922.108-1~deb12u1.debian.tar.xz
3f61843e261333e23dc4a27594ed0fbf3a17cf9e 27247 chromium_151.0.7922.108-1~deb12u1_source.buildinfo
Checksums-Sha256:
1dc5262000aeec9ab0e694d30644db5d043a7b842affda960edd94137e2c9ca3 4374 chromium_151.0.7922.108-1~deb12u1.dsc
ec5cdca5594aadeeb7076fa27712278037b0ba6f00d5a8ae86602ed573bacba2 15073392 chromium_151.0.7922.108.orig-pre-gen.tar.xz
90e46be09cf71d1d426e6c8266657d85bf75faf958c2ac6d8d31786430ee3762 949043204 chromium_151.0.7922.108.orig.tar.xz
a5c0687646181f29ff03bb744ad267ba221c944022e907247ffe08e9d87dfe18 557200 chromium_151.0.7922.108-1~deb12u1.debian.tar.xz
ea345e18bc2fe7a3b5ae24bda5b71e1713ca9934c2e5e8d14ea8f439a70f7940 27247 chromium_151.0.7922.108-1~deb12u1_source.buildinfo
Files:
f9d9def209432ae40b5c524be141b8be 4374 web optional chromium_151.0.7922.108-1~deb12u1.dsc
8f3589d01d63ade127070eb61257aea5 15073392 web optional chromium_151.0.7922.108.orig-pre-gen.tar.xz
dd30a91d4d7d2e2a7dcd4d3b86e44ec4 949043204 web optional chromium_151.0.7922.108.orig.tar.xz
acc9c7d8b3f82ace1ecdc6320ed59bb1 557200 web optional chromium_151.0.7922.108-1~deb12u1.debian.tar.xz
5be1e57767219dc5b6fd0d2a6984c31e 27247 web optional chromium_151.0.7922.108-1~deb12u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmp2w+IUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjfKPw//dGxiMtrU3wtGqINYPaSAnNwGt0UL
KtZiFrP6dhgoPhc81bAtbr3McOg7tHhPlcNFbunaJ45ZsFLh0DVinVT9anyMqsFS
ULVXjirkqxvLLLNyW5J77FzDM9GavrOqAyh0aNQxzwgi7w5wCkhh1X1v8jr/5e7e
QXYU++4GWg0tU0xlBtHwssAnHivajguPodVW9l/B09nYpCFkSe8IcgsnWT0rR1AY
ivVwponLtF7nmZqRr5R31C3g78K7nVDByr+Fk3N1eD6OMO8DWdF4IWMEipW822Fk
/XZhn266jqTmr+985tefkiz6oMI7ne0GdfS2+0WcO386gYeo0Xlh2HC5RMFokQG/
r1jWYWJkDnbnITQwEOqrdecRSs/eD7C3JiLHKKwAQXThv6it2xwhNKijIZ6/8gh8
ehAs6t+pyNXrfMsLninX4/8qVfhCbhwGwPhalLcXeFYSdt4UwQNbtrM8Qt2dtvER
MgYcUHkh/wimXdnrCqK/jQspWsJx+gxu9Vb65mCe0Rv8kB8ZTJr/XOOOWL+hLrE6
+1/D3BOB6NBd1zbo58p1M3hk0e3EZAgPV/A7S41OLV543lNcfHSyT1OabLwBzyGn
NLOLkCbbCmh/2d5sclrZHJIugwGYP46oOnlKLr47CFhotslnI7aKu4x2zSLICXAu
MzhGigcVP0lws3o=
=0y5t
-----END PGP SIGNATURE-----