-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Wed, 02 Sep 2026 14:22:49 -0400
Source: chromium
Architecture: source
Version: 152.0.7977.75-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (152.0.7977.75-1~deb13u1) trixie-security; urgency=high
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-84353: Use after free in Shared Tab Groups. Reported by Google.
- CVE-2026-84352: Use after free in WebGL. Reported by Google.
- CVE-2026-84354: Incorrect authorization in FileSystem.
Reported by Google.
- CVE-2026-84359: Information leak in Skia. Reported by Google.
- CVE-2026-84357: Improper input validation in Omnibox.
Reported by Google.
- CVE-2026-84324: Use after free in Proxy. Reported by Google.
- CVE-2026-84349: Use after free in Browser. Reported by Google.
- CVE-2026-84326: Uninitialized resource in V8. Reported by Jihyeon Jeong
(Compsec Lab, Seoul National University / Research Intern).
- CVE-2026-84333: Use after free in Dawn. Reported by Google.
- CVE-2026-84351: Buffer overflow in GPU. Reported by Cassio Lima.
- CVE-2026-84325: Improper input validation in DataTransfer.
Reported by Google.
- CVE-2026-84328: Missing authorization in FileSystem. Reported by Google.
- CVE-2026-84347: Use after free in WebRTC. Reported by Google.
- CVE-2026-84323: Missing authorization in FileSystem. Reported by Google.
- CVE-2026-84355: Incorrect authorization in Navigation.
Reported by Google.
- CVE-2026-84358: Improper privilege management in Downloads.
Reported by Google.
- CVE-2026-84332: Incorrect authorization in SiteSettings.
Reported by Google.
- CVE-2026-84330: UI misrepresentation in FullScreen. Reported by Google.
- CVE-2026-84334: Incorrect authorization in Chromoting.
Reported by Google.
- CVE-2026-84348: Information leak in MediaCapture. Reported by Google.
- CVE-2026-84335: Incorrect authorization in TabStrip. Reported by Google.
- CVE-2026-84327: Incorrect authorization in Autofill. Reported by Google.
- CVE-2026-84329: Confused deputy in CredentialProvider.
Reported by Google.
- CVE-2026-84356: UI misrepresentation in FullScreen.
Reported by Francesco Topol (k4tedu).
- CVE-2026-84350: Use after free in TabStrip. Reported by Google.
- CVE-2026-84331: Incorrect authorization in Actor. Reported by Google.
* d/control: bump rustc-web build-dep versioning up to 1.96, now that we
have that in bookworm-proposed-updates.
* d/patches:
- trixie/rust-no-alloc-shim.patch: drop, no longer needed with newer rust.
- trixie/rust-sanitize.patch: drop, no longer needed with newer rust.
- debianization/rust-disable-debugsym.patch: add --no-mmap-output-file
to link flags (another attempt to reduce armhf memory usage).
- rust-1.85/jxl-simd-avx512.patch: drop, no longer needed with newer rust
- rust-1.85/jxl-features.patch: drop, no longer needed with newer rust.
- rust-1.85/parsing.patch: drop, no longer needed with newer rust.
- rust-1.85/image.patch: drop, no longer needed with newer rust.
- rust-1.85/rust-is-multiple-of.patch: drop, no longer needed with newer
rust.
- rust-1.85/file_as_c_str.patch: drop, no longer needed with newer rust.
- rust-1.85/mojo-features.patch: drop, no longer needed with newer rust.
- rust-1.85/zip8.patch: drop, no longer needed with newer rust.
- rust-1.85/std-from-utf8.patch: drop, no longer needed with newer rust.
- rust-1.85/let-chains.patch: drop, no longer needed with newer rust.
- trixie/adler1.patch: drop, now that we have a newer rustc-web in
bookworm.
.
[ Daniel Richard G. ]
* d/deb_pre_gen.py: Exclude a couple of targets from the pre-gen process as
making them causes files to be written to the source tree.
.
[ Timothy Pearson ]
* d/patches/ppc64le:
- third_party/0003-third_party-ffmpeg-Add-ppc64-generated-config.patch:
Fix FTBFS on ppc64le systems due to FFmpeg patch update.
Checksums-Sha1:
11c6e865b7e31cfc61eb2c93a1eb42e6e2af2928 4406 chromium_152.0.7977.75-1~deb13u1.dsc
6d45fa80d18b0e4122444bacb33e2d243023c0b1 15494756 chromium_152.0.7977.75.orig-pre-gen.tar.xz
69d14549882256db44ddd7e12e46bdb6eafcc95a 959301568 chromium_152.0.7977.75.orig.tar.xz
8ce67f11ec389ecc42745634dcd41574b30e13d9 556344 chromium_152.0.7977.75-1~deb13u1.debian.tar.xz
d14ba4938ac43af3b0fad3cab83b8970e1a711e6 27920 chromium_152.0.7977.75-1~deb13u1_source.buildinfo
Checksums-Sha256:
b4e7e1c7c8ca63ef18ab5f245883cedabd1ddfff91ae14bd0780c9a516dbda3d 4406 chromium_152.0.7977.75-1~deb13u1.dsc
44ca79343649fbd31955bc3c9aa0a3b53a065468135da1fc9fcd7871d147cb28 15494756 chromium_152.0.7977.75.orig-pre-gen.tar.xz
971e45816002d400a559cca507d311aa9b01a3f59cf1e679b5882e873694c40a 959301568 chromium_152.0.7977.75.orig.tar.xz
81fd4849a2304750eafdfa3bdcc91f266728a3a92e9d92e2d0a14c76824c96f4 556344 chromium_152.0.7977.75-1~deb13u1.debian.tar.xz
62eb160922fb2c2d5792f36a0e0ab859efa811de320ae239e4ba332b58bff6af 27920 chromium_152.0.7977.75-1~deb13u1_source.buildinfo
Files:
18fcfb79d19e819f647362e741235229 4406 web optional chromium_152.0.7977.75-1~deb13u1.dsc
2f1a71325e2a69acc43cf4b08bc8cf56 15494756 web optional chromium_152.0.7977.75.orig-pre-gen.tar.xz
2583798ec5b1e0333eecfaec169aec49 959301568 web optional chromium_152.0.7977.75.orig.tar.xz
3cfdc4bd4d8989087e4cadbc0ea8b6cd 556344 web optional chromium_152.0.7977.75-1~deb13u1.debian.tar.xz
0bb19e17fc33b3eba9a98bbe1d685abd 27920 web optional chromium_152.0.7977.75-1~deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmqYh4kUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjeFsA//W8onG6FIU8iajNQ5q83dhnLdtyf+
rev2EClZTRNbblT2ZteJ+dsXc5usmnhrmxo+V2KtNdeVmWAgpEuhsfTymJAMnRr/
SqfHxjOEp4VP9mBq2BYuiFxiyTDqXSvzYin4RG5KQXq8YLQeqvpU0ozK9AD/ldM+
HKuo5P5XryGNanfyJOFM2pFFM6Yi9n4+ZcY0JSzIQFa3vCsye0RtOzGrsVBwyLp0
OgkUCBDnq/tMhU4EVcnUuy1xNLiJJLNBlg7GUOcUc591NDo4I6pBPUhI0qMni1FB
y4j6ThMzBZ5inP9HO71QH23MQC/KDcvQtfr90oAziBK+OKFagg9gfAy59hUbKcT+
5y5+UEagwkIQKu0obLB6+zl/fUEh1sF0+dxu5NuLD89FZ/XT3vVjsPlvEmvEbZ+I
pPyag5vLDHMRPv9vpbUmxsQlmd5q/Kn0fqGpSWSc1Znri7iQac8GHSYdUFBawtJT
fw434EyLhzfLWdscRFFuedAiCvSSCkGCi4+aQcTYLUm+KY5FAHTv2PlopQ3dtdkK
RrN0+GF0JXoA7yaZvTQ/EUugCDMYRky1ts82ekdFqyWJ1V+DnBBvccASdmFrWxYW
XgNPyrhgsmj+eKABLgUZiA+8WjMZVdXXAJXUOMLwqSycDU+66fuJtW7TI3V3hnUX
7n+pIO1gHLh1AUA=
=UCVS
-----END PGP SIGNATURE-----