-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Fri, 07 Aug 2026 12:19:50 -0400
Source: chromium
Architecture: source
Version: 151.0.7922.108-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (151.0.7922.108-1~deb13u1) trixie-security; urgency=high
.
[ Daniel Richard G. ]
* d/deb_pre_gen.py: Minor fixes to the pre-gen framework:
- Always record target outputs in an .OUTPUTS file, even if a target has
only a single output. This incurs only a small (tarball) size penalty,
and catches cases where there is disagreement on which is the first
output file of a .ninja target.
- Update the handling logic for generate_css_js_files.js, as the first
output file of the .ninja target changed from v150.
- Add an extra check to ensure that target outputs are unique.
* d/patches/debianization/pre-gen.patch: Tweak a script so that it outputs
a constant UUID, instead of one dependent on the build path.
* d/patches/system/golang.patch: Prevent the Go compiler from writing
things into our home dir, or accessing the network.
* d/scripts/init-pre-gen.sh: Don't hard-code the package name, as we might
be doing init-pre-gen for ungoogled-chromium.
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-19137: Use after free in WebGL. Reported by anonymous.
- CVE-2026-19149: Use after free in Aura. Reported by Google.
- CVE-2026-19154: Use after free in Skia. Reported by Google.
- CVE-2026-19157: Out of bounds write in ANGLE. Reported by Google.
- CVE-2026-19170: Use after free in WebGL. Reported by Muhammad Alifa
Ramdhan, Pan ZhenPeng, Billy Jheng Bing Jhong of STAR Labs SG Pte. Ltd.
- CVE-2026-19172: Use after free in Views. Reported by Google.
- CVE-2026-19169: Insufficient validation of untrusted input in
Contextual Tasks. Reported by Sven Dysthe (@svn-dys).
- CVE-2026-19168: Inappropriate implementation in V8.
Reported by XBOW and triaged by Andrés Luksenberg.
- CVE-2026-19138: Heap buffer overflow in CrashReporting.
Reported by Google.
- CVE-2026-19139: Race in CredentialProvider. Reported by Google.
- CVE-2026-19140: Use after free in GPU. Reported by Google.
- CVE-2026-19141: Use after free in Resources. Reported by Google.
- CVE-2026-19142: Use after free in Views. Reported by Google.
- CVE-2026-19143: Insufficient validation of untrusted input in
WebAPKs. Reported by Google.
- CVE-2026-19144: Use after free in HTML. Reported by Google.
- CVE-2026-19145: Use after free in Translate. Reported by Google.
- CVE-2026-19146: Uninitialized Use in GPU. Reported by Google.
- CVE-2026-19147: Use after free in Aura. Reported by Google.
- CVE-2026-19148: Out of bounds write in GPU. Reported by Google.
- CVE-2026-19150: Inappropriate implementation in V8. Reported by Google.
- CVE-2026-19151: Use after free in V8. Reported by Google.
- CVE-2026-19152: Inappropriate implementation in Navigation.
Reported by Google.
- CVE-2026-19153: Insufficient validation of untrusted input in Workers.
Reported by Google.
- CVE-2026-19155: Use after free in Payments. Reported by Google.
- CVE-2026-19156: Heap buffer overflow in Base.
Reported by Viktoria Zlatinova.
- CVE-2026-19158: Use after free in Views. Reported by Google.
- CVE-2026-19159: Use after free in Views. Reported by Google.
- CVE-2026-19160: Uninitialized Use in Skia. Reported by Google.
- CVE-2026-19161: Uninitialized Use in Skia. Reported by Google.
- CVE-2026-19162: Out of bounds write in V8.
Reported by OpenAI Codex Security (amyb).
- CVE-2026-19163: Use after free in Media. Reported by Google.
- CVE-2026-19164: Insufficient validation of untrusted input in Codecs.
Reported by Google.
- CVE-2026-19165: Use after free in Extensions. Reported by @bean5oup.
- CVE-2026-19166: Use after free in Web Authentication.
Reported by heesun.
- CVE-2026-19167: Integer overflow in GPU. Reported by Google.
- CVE-2026-19171: Use after free in Media. Reported by Google.
- CVE-2026-19173: Out of bounds write in Skia.
Reported by Vu Van Tien (@n0_Be3r).
- CVE-2026-19174: Integer overflow in V8.
Reported by Seunghyun Lee (@0x10n) of QED Audit (qedaudit.io).
- CVE-2026-19175: Use after free in Payments. Reported by Google.
- CVE-2026-19176: Use after free in Skia.
Reported by WinD39 - Huynh Dinh Vu.
- CVE-2026-19177: Insufficient validation of untrusted input in UI.
Reported by Fabian Wahle (Hap Security).
Checksums-Sha1:
aaa18e1fc7807c6a98f69b64179a102bd6b993cd 4408 chromium_151.0.7922.108-1~deb13u1.dsc
5db7fe8f89a8fa3ff494e0286ff5f91358ab6ad5 15073392 chromium_151.0.7922.108.orig-pre-gen.tar.xz
9f6610225455ca29c87964dc04ad23e16873b605 949043204 chromium_151.0.7922.108.orig.tar.xz
033f17f1095dad419b39140da51e6f8384148f5f 549364 chromium_151.0.7922.108-1~deb13u1.debian.tar.xz
3129b3a6b7061d48917b5d48c089e339091f5243 27844 chromium_151.0.7922.108-1~deb13u1_source.buildinfo
Checksums-Sha256:
226d69fa1aed9c4b2e8c1d0ab5278802e78d5ce4b10d4f4fbca5e6c925f85ff9 4408 chromium_151.0.7922.108-1~deb13u1.dsc
ec5cdca5594aadeeb7076fa27712278037b0ba6f00d5a8ae86602ed573bacba2 15073392 chromium_151.0.7922.108.orig-pre-gen.tar.xz
90e46be09cf71d1d426e6c8266657d85bf75faf958c2ac6d8d31786430ee3762 949043204 chromium_151.0.7922.108.orig.tar.xz
3296e191796d2b1f579b0722408186f4b8f048a4f19cf7220864bca82537685a 549364 chromium_151.0.7922.108-1~deb13u1.debian.tar.xz
ac0d98c1199a789b2a9f51f036cfdcb3fe4bcf63504c5c4fba3c862824a3076b 27844 chromium_151.0.7922.108-1~deb13u1_source.buildinfo
Files:
414a9d50346f8c3b717409c02f0e1245 4408 web optional chromium_151.0.7922.108-1~deb13u1.dsc
8f3589d01d63ade127070eb61257aea5 15073392 web optional chromium_151.0.7922.108.orig-pre-gen.tar.xz
dd30a91d4d7d2e2a7dcd4d3b86e44ec4 949043204 web optional chromium_151.0.7922.108.orig.tar.xz
d954f6a01bfb3d45c6cae20b76c0e801 549364 web optional chromium_151.0.7922.108-1~deb13u1.debian.tar.xz
c64b4630ae21a7c7d41889d3edbfc356 27844 web optional chromium_151.0.7922.108-1~deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmp21q4UHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjfyKw/+K/HblXohmwk/ZLR1R8b7VHc0RFLC
Dj5BxuWk9GyDwYOfn71gLBY8SUYcKfFgI0Kx6slUTIWhqPcTwYgl67k9hZZ4fa8C
1nl54v5x79YiSlpB+yylBOyLndax3l54U/NY9NcQ6txaE3JW++B+egrWjRk5k7xL
kooTIabTUsmNKKuLJwnrBZ+K/LxUjNeMGnI8YwI0cWqI3njHNEAbnkzHBvyJ3bKA
GzAURoEID8+CTljymQwNfRrR4TCRLO92WZhXc1Or0Rc6ELC+N45tUvev3J0OApbW
DU9TqQN/D02wP2FOd15/P9YapL9hNs+h4a/EDL/y62B8ImQxj2P2hQBW0kP2xD1t
7P+aOBJAdKYu3J2E3TlmQxvYzDUTGAqrfYmE8qpDubyKVMSWMZyA05crb5pZWrwI
TvpUazqAUxgGtsDH3S0Wmne4xDVrEfninNJYmGjR8/KZAAtyDxeFDfCMIbo4vx0z
Vb6rRxaxOrG7JANpwZB7SGGJ//RFeR1JhE+2uqEeyBTWeXeULXItBDuUJ4ISe0EZ
s5ixfkgR4sPbJ8N1JFUJt8Lr1YvNF84R4Mirt0CIltfHoytRbQiBMGADrY6A0mMl
l4eItJJ0qoyBjAZo/eJgJk8TOLewr2WlowKzNG2FauamWAv2CzBnDAu0sAu8F5AO
EEAx2b3UC/sohck=
=aLg9
-----END PGP SIGNATURE-----