-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Wed, 02 Sep 2026 14:22:49 -0400
Source: chromium
Architecture: source
Version: 152.0.7977.75-1
Distribution: unstable
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (152.0.7977.75-1) unstable; urgency=high
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-84353: Use after free in Shared Tab Groups. Reported by Google.
- CVE-2026-84352: Use after free in WebGL. Reported by Google.
- CVE-2026-84354: Incorrect authorization in FileSystem.
Reported by Google.
- CVE-2026-84359: Information leak in Skia. Reported by Google.
- CVE-2026-84357: Improper input validation in Omnibox.
Reported by Google.
- CVE-2026-84324: Use after free in Proxy. Reported by Google.
- CVE-2026-84349: Use after free in Browser. Reported by Google.
- CVE-2026-84326: Uninitialized resource in V8. Reported by Jihyeon Jeong
(Compsec Lab, Seoul National University / Research Intern).
- CVE-2026-84333: Use after free in Dawn. Reported by Google.
- CVE-2026-84351: Buffer overflow in GPU. Reported by Cassio Lima.
- CVE-2026-84325: Improper input validation in DataTransfer.
Reported by Google.
- CVE-2026-84328: Missing authorization in FileSystem. Reported by Google.
- CVE-2026-84347: Use after free in WebRTC. Reported by Google.
- CVE-2026-84323: Missing authorization in FileSystem. Reported by Google.
- CVE-2026-84355: Incorrect authorization in Navigation.
Reported by Google.
- CVE-2026-84358: Improper privilege management in Downloads.
Reported by Google.
- CVE-2026-84332: Incorrect authorization in SiteSettings.
Reported by Google.
- CVE-2026-84330: UI misrepresentation in FullScreen. Reported by Google.
- CVE-2026-84334: Incorrect authorization in Chromoting.
Reported by Google.
- CVE-2026-84348: Information leak in MediaCapture. Reported by Google.
- CVE-2026-84335: Incorrect authorization in TabStrip. Reported by Google.
- CVE-2026-84327: Incorrect authorization in Autofill. Reported by Google.
- CVE-2026-84329: Confused deputy in CredentialProvider.
Reported by Google.
- CVE-2026-84356: UI misrepresentation in FullScreen.
Reported by Francesco Topol (k4tedu).
- CVE-2026-84350: Use after free in TabStrip. Reported by Google.
- CVE-2026-84331: Incorrect authorization in Actor. Reported by Google.
* d/patches:
- trixie/rust-no-alloc-shim.patch: drop, no longer needed with newer rust.
- trixie/rust-sanitize.patch: drop, no longer needed with newer rust.
- debianization/rust-disable-debugsym.patch: add --no-mmap-output-file
to link flags (another attempt to reduce armhf memory usage).
.
[ Daniel Richard G. ]
* d/deb_pre_gen.py: Exclude a couple of targets from the pre-gen process as
making them causes files to be written to the source tree.
.
[ Timothy Pearson ]
* d/patches/ppc64le:
- third_party/0003-third_party-ffmpeg-Add-ppc64-generated-config.patch:
Fix FTBFS on ppc64le systems due to FFmpeg patch update.
Checksums-Sha1:
24708db999d7ed3c36e51a39bf4bf67f373ebb94 4378 chromium_152.0.7977.75-1.dsc
6d45fa80d18b0e4122444bacb33e2d243023c0b1 15494756 chromium_152.0.7977.75.orig-pre-gen.tar.xz
69d14549882256db44ddd7e12e46bdb6eafcc95a 959301568 chromium_152.0.7977.75.orig.tar.xz
c06df198a000f9d24e50eceed4b1cdda08e1d395 555900 chromium_152.0.7977.75-1.debian.tar.xz
93f97fbba8aaaffd9f8e53032aa72d8741339872 27044 chromium_152.0.7977.75-1_source.buildinfo
Checksums-Sha256:
02d4c008ee9cd38aa38dff5b281b7ed663f582c137caabaff4955356bf64b2dc 4378 chromium_152.0.7977.75-1.dsc
44ca79343649fbd31955bc3c9aa0a3b53a065468135da1fc9fcd7871d147cb28 15494756 chromium_152.0.7977.75.orig-pre-gen.tar.xz
971e45816002d400a559cca507d311aa9b01a3f59cf1e679b5882e873694c40a 959301568 chromium_152.0.7977.75.orig.tar.xz
c0eac8d23dc8a0249b9786a5f8830dee1d9b5a2a562c5d67a3ca16fc4d2c53f2 555900 chromium_152.0.7977.75-1.debian.tar.xz
ee1521faf1a76c8f0087a3427789c5302458f2cdc24bf716998abf2365931f30 27044 chromium_152.0.7977.75-1_source.buildinfo
Files:
d026fe4dc4c6b2addfe25300ff59edeb 4378 web optional chromium_152.0.7977.75-1.dsc
2f1a71325e2a69acc43cf4b08bc8cf56 15494756 web optional chromium_152.0.7977.75.orig-pre-gen.tar.xz
2583798ec5b1e0333eecfaec169aec49 959301568 web optional chromium_152.0.7977.75.orig.tar.xz
9d0164763aa218f9e6f9eb172ca2c450 555900 web optional chromium_152.0.7977.75-1.debian.tar.xz
305f7d248d740fffc3806f6a68cc8239 27044 web optional chromium_152.0.7977.75-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmqYa7sUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8Nudjef2w/7B5m+FHRHwRBeWHpXNm1cqms8KA16
iBX/9eY8myOwX7FuwzUGNtawq/FUJyiep9c1+Tj8+GK+qXgAZsILp8puP6HXGeHF
7FosAOaBuUz8RbDFTuqC57CrKLHXX3BGiQSoNZB8Z2SzvApZrkxF0mkGKvffI+vU
5cNrRHI9HFl2RGODb08VnXix3cMfT9xuLbTijj5wwOwdY73g55FshI/fR0VxnS2t
MSgG7p7YaMbVSb6um89v9RneT3TAG1wWmghI0hiNcNMOeOlxlkWdl4bkiMBRVX7C
13CZUIMm2uFVtdntOj36kFQQ3q6eqEVZ5TA21x3sXCObDDsoECBYkdu3Bq1bAmSM
/EcEKVW3jjIGgFtiHjmv7KCsTL79eexDMLXjABBlUFFbv0KehLfFwtHneIOW5Bf9
MQwy08F/z5R73mJmN/UE8Lf5wwN2simcIjkXTWsWyrMZbiUiXBAPTqd7okWG+dUS
LDCAv63rld04RR5ZAi7NFEmUtG0PzE9c+tZP0swFoaBDU0gOUFWlOEnc/j4QnG0v
c1D2e7cG98sdXU7kswF2LhtX2totaPjeBmD184pk8OnE4JeeXrPP2hbwLFnocpRO
duTtKRQJZaVv/qmqsSQznLITx/DsNKHUSqAtkYj9C0v2bZZdwPWYvmM2e2ixnTAt
l8kNKEoWyqw7soA=
=IU9G
-----END PGP SIGNATURE-----