-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 24 Sep 2026 17:31:48 -0400 Source: chromium Architecture: source Version: 154.0.8037.57-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: Debian Chromium Team <chromium@packages.debian.org> Changed-By: Andres Salomon <dilinger@debian.org> Closes: 1135653 1146746 Changes: chromium (154.0.8037.57-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-95350: Buffer overflow in ANGLE. Reported by Billy Jheng Bing Jhong, Muhammad Alifa Ramdhan, Pan Zhenpeng of STAR. - CVE-2026-95357: Out of bounds write in GPU. Reported by Anymous. - CVE-2026-95339: Use after free in ServiceWorker. Reported by Andrew Boni. - CVE-2026-95281: Buffer overflow in ANGLE. Reported by Muhammad Alifa Ramdhan of STAR Labs SG Pte. Ltd. - CVE-2026-95313: Use after free in Fullscreen. Reported by WinD39 - Huynh Dinh Vu. - CVE-2026-95349: Buffer overflow in WebGL. Reported by Google. - CVE-2026-95284: Buffer overflow in ANGLE. Reported by Muhammad Alifa Ramdhan (STARLABS SG). - CVE-2026-95322: Out of bounds write in GPU. Reported by David Sievers (@loknop). - CVE-2026-95329: Out of bounds write in WebGL. Reported by Google. - CVE-2026-95356: Use after free in WindowDialog. Reported by Xinyang Ge. - CVE-2026-95310: Use after free in AdFilter. Reported by Xinyang Ge. - CVE-2026-95301: Missing authorization in Extensions. Reported by OGINOME Tomohito. - CVE-2026-95291: UI misrepresentation in SecurityIndicators. Reported by NH DEV. - CVE-2026-95355: Incorrect authorization in Navigation. Reported by Google. - CVE-2026-95315: Use after free in Aura. Reported by Google. - CVE-2026-95298: Use after free in Browser. Reported by Google. - CVE-2026-95372: Use after free in Chromecast. Reported by Google. - CVE-2026-95324: Uninitialized resource in GPU. Reported by Google. - CVE-2026-95283: Buffer overflow in Tint. Reported by Google. - CVE-2026-95293: Uninitialized resource in GPU. Reported by TienPA - NGS Holdings. - CVE-2026-95274: Improper output encoding in DevTools. Reported by Google. - CVE-2026-95282: Use after free in Platform. Reported by Google. - CVE-2026-95373: Use after free in DevTools. Reported by Google. - CVE-2026-95277: Use after free in Views. Reported by Google. - CVE-2026-95348: Use after free in Bluetooth. Reported by Google. - CVE-2026-95335: Use after free in HID. Reported by WinD39 - Huynh Dinh Vu. - CVE-2026-95338: Use after free in PDFium. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722). - CVE-2026-95318: Buffer overflow in Video. Reported by alex.laboirie. - CVE-2026-95286: Type confusion in Bindings. Reported by @bean5oup. - CVE-2026-95365: Type confusion in IndexedDB. Reported by HoneyBee. - CVE-2026-95343: Use after free in WebAudio. Reported by HoneyBee. - CVE-2026-95280: Race condition in V8. Reported by Google. - CVE-2026-95304: Out of bounds write in V8. Reported by OpenAI Codex Security (amyb). - CVE-2026-95306: Type confusion in V8. Reported by OpenAI Codex Security (amyb). - CVE-2026-95299: Use after free in GPU. Reported by Google. - CVE-2026-95351: Use after free in Views. Reported by Xinyang Ge. - CVE-2026-95287: Missing authorization in Navigation. Reported by Google - CVE-2026-95366: Use of released resource in Core. Reported by Google. - CVE-2026-95382: Improper input validation in Auth. Reported by Google. - CVE-2026-95381: Improper input validation in Printing. Reported by Google. - CVE-2026-95331: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-95297: Missing authorization in Contextual Tasks. Reported by Google. - CVE-2026-95375: Incorrect authorization in BrowserTag. Reported by Google. - CVE-2026-95302: Incorrect authorization in WebAPKs. Reported by Google. - CVE-2026-95362: Cross-site request forgery in DevTools. Reported by Google. - CVE-2026-95369: Inappropriate implementation in XML. Reported by Google - CVE-2026-95376: Externally controlled reference in DevTools. Reported by Google. - CVE-2026-95359: Uninitialized resource in GPU. Reported by Google. - CVE-2026-95294: UI misrepresentation in Browser. Reported by Google. - CVE-2026-95337: UI misrepresentation in Messages. Reported by Google. - CVE-2026-95346: UI misrepresentation in Chromoting. Reported by Google. - CVE-2026-95320: Missing authorization in Navigation. Reported by Google - CVE-2026-95317: Incorrect authorization in MediaCapture. Reported by Google. - CVE-2026-95345: Use after free in Actor. Reported by Google. - CVE-2026-95330: Improper state validation in Downloads. Reported by Google. - CVE-2026-95370: Inappropriate implementation in NFC. Reported by Google - CVE-2026-95303: Incomplete cleanup in SmartCard. Reported by Google. - CVE-2026-95360: Race condition in Editing. Reported by Google. - CVE-2026-95295: Information leak in Mobile. Reported by Google. - CVE-2026-95276: Improper input validation in Themes. Reported by Google - CVE-2026-95314: Incorrect authorization in HID. Reported by Google. - CVE-2026-95371: Missing authorization in Views. Reported by Google. - CVE-2026-95353: Use after free in Bindings. Reported by Google. - CVE-2026-95363: UI misrepresentation in FileSystem. Reported by Google. - CVE-2026-95341: Improper input validation in Desktop. Reported by Google. - CVE-2026-95354: Use after free in Verifier. Reported by Google. - CVE-2026-95384: Race condition in Transactions Platform. Reported by Google. - CVE-2026-95336: Information leak in Transactions Platform. Reported by Google. - CVE-2026-95290: Missing authorization in NFC. Reported by Google. - CVE-2026-95325: Use after free in ANGLE. Reported by Google. - CVE-2026-95275: Incorrect reference resolution in MediaStream. Reported by Zabith Mohammed (@nmzabith). - CVE-2026-95374: Incorrect authorization in Network. Reported by NH DEV. - CVE-2026-95300: Missing authorization in DevTools. Reported by Google. - CVE-2026-95321: UI misrepresentation in Payments. Reported by jodyritonga. - CVE-2026-95323: UI misrepresentation in Chromium. Reported by Wihdatu Nuuro Ahmadi. - CVE-2026-95332: Use of uninitialized variable in Tint. Reported by Google. - CVE-2026-95312: Information leak in Passwords. Reported by Google. - CVE-2026-95344: Race condition in DevTools. Reported by @bean5oup. - CVE-2026-95289: Incorrect authorization in Scroll. Reported by Vu Van Tien (@n0_Be3r). - CVE-2026-95347: Use after free in Updater. Reported by a45hif. - CVE-2026-95311: Free of non-heap memory in Fonts. Reported by Google. - CVE-2026-95358: Incorrect authorization in Mobile. Reported by Google. - CVE-2026-95333: Use after free in Metrics. Reported by sean geofrey. - CVE-2026-95307: UI misrepresentation in ExtensionsMenu. Reported by Hafiizh. - CVE-2026-95285: Missing authorization in WebView. Reported by Google. - CVE-2026-95278: Missing authorization in WakeLock. Reported by Google. - CVE-2026-95327: Information leak in Networking. Reported by Google. - CVE-2026-95334: Incorrect reference resolution in WebProtect. Reported by Google. - CVE-2026-95308: Integer overflow in Metrics. Reported by Google. - CVE-2026-95292: Incorrect authorization in Safebrowsing. Reported by Google. - CVE-2026-95352: Incorrect authorization in DevTools. Reported by Google - CVE-2026-95279: UI misrepresentation in Omnibox. Reported by Google. - CVE-2026-95367: Information leak in DataTransfer. Reported by Google. - CVE-2026-95385: Inappropriate implementation in PlatformIntegration. Reported by Google. - CVE-2026-95368: Incorrect authorization in DevTools. Reported by Google - CVE-2026-95319: Use after free in Printing. Reported by Google. - CVE-2026-95326: Incomplete cleanup in Bluetooth. Reported by Google. - CVE-2026-95309: UI misrepresentation in Mobile. Reported by Google. - CVE-2026-95361: Confused deputy in DevTools. Reported by Google. - CVE-2026-95288: UI misrepresentation in Mobile. Reported by Google. - CVE-2026-95380: Type confusion in V8. Reported by Google. - CVE-2026-95342: Missing authorization in V8. Reported by Hongwei Li, Zhun Wang, Ziyue Pan, Junmin Zhu, Saastha Vasan, and Wenbo Guo. - CVE-2026-95296: Missing authorization in Core. Reported by Quyền Sơn (@zer0qs1337). - CVE-2026-95316: Unchecked return value in Performance. Reported by Google. - CVE-2026-95328: Confused deputy in Mobile. Reported by Google. - CVE-2026-95340: Incorrect authorization in PictureInPicture. Reported by Google. - CVE-2026-95364: Improper input validation in Passwords. Reported by Google. - CVE-2026-95305: UI misrepresentation in Chromoting. Reported by Google. * d/control: - remove generate-ninja build-dep. - stop recommending chromium-sandbox (closes: #1135653). * d/copyright: stop deleting tools/gn/. * d/rules: restore old code that builds the bundled version of generate-ninja as part of the chromium build. Upstream keeps using brand new gn features (sometimes not even available in sid yet) and we're carrying too many patches to work around that. * d/patches: - debianization/pre-gen.patch: rework clang argument filtering due to upstream changes. - disable/tests.patch: refresh. - disable/catapult.patch: refresh. - llvm-22/clang22.patch: refresh. - ungoogled/disable-ai.patch: sync from u-c - ungoogled/disable-mei-preload.patch: sync from u-c - ungoogled/disable-privacy-sandbox.patch: sync from u-c - fixes/crubit.patch: drop - system/rust-cbor.patch: drop - ungoogled/crubit.patch: add a patch pulled from u-c, which includes stuff from fixes/crubit.patch and system/rust-cbor.patch.. plus more. - ungoogled/verification-tokens.patch: add a patch pulled from u-c to fix a build failure related to private verification tokens. Two week release cycle is awesomesauce. - fixes/tsc-split-comp.patch: add a build fix for debian's typescript. - ungoogled/disable-ai-search-shortcuts.patch: add patch to disable the new AI button and the @gemini/@aimode shortcuts (closes: #1146746). - trixie/gn-string-hash.patch: drop, no longer needed with bundled gn. - trixie/gn-len.patch: drop, no longer needed with bundled gn [trixie, bookworm]. - trixie/gn-module-name.patch: drop, no longer needed with bundled gn [trixie, bookworm]. - trixie/gn-unused-vars.patch: drop, no longer needed with bundled gn [trixie, bookworm]. - trixie/gn-funcs.patch: drop, no longer needed with bundled gn [trixie, bookworm]. - bookworm/gn-revert-path-exists.patch: drop, no longer needed with bundled gn. - bookworm/foreach.patch: drop, no longer needed with newer clang [sid, trixie]. . [ Timothy Pearson ] * d/patches/ppc64le: - fixes/fix-rust-linking.patch: refresh for upstream changes - third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream changes - third_party/0003-third_party-ffmpeg-Add-ppc64-generated-config.patch: refresh for upstream changes . [ Daniel Richard G. ] * d/deb_pre_gen.py: Handle new arg signature of generate_css_js_files.js, and the new run_with_restat.py script; also streamline regexes a bit. * d/patches: - debianization/pre-gen.patch: Handle run_with_restat.py script, and neuter run_with_stamp.py. - trixie/gn-unused-vars.patch: Refresh. * d/rules: Set njobs for the init-pre-gen target for a faster GN build. . [ Jianfeng Liu ] * d/patches: loongarch64/0020-user_agent-add-loongarch-architecture-support.patch: refresh for upstream changes Checksums-Sha1: 6bad2eb2caa155803294b69887e5fbbbccfa23af 4415 chromium_154.0.8037.57-1~deb13u1.dsc 434a8c1905a2afc05536786b84988ae3eebfbf6a 16687904 chromium_154.0.8037.57.orig-pre-gen.tar.xz 0400bfcdcf576ce0df8de5d98ac88da42c5379d8 994972848 chromium_154.0.8037.57.orig.tar.xz 64009d939940c7036620ed66f15ceadd114596ad 574952 chromium_154.0.8037.57-1~deb13u1.debian.tar.xz 75b755d8838db2d916ecf7064bed4f152ee18bca 27964 chromium_154.0.8037.57-1~deb13u1_source.buildinfo Checksums-Sha256: 33b7c7643951385340a37d346c49284d86b1293786ae678ffb17b3679b55a27b 4415 chromium_154.0.8037.57-1~deb13u1.dsc 3f42d7e0516007a88ac97e2e596ffd4f2602f0164a6ff0571a0dfafe1881d454 16687904 chromium_154.0.8037.57.orig-pre-gen.tar.xz d251fba87c477bc04a08dd0a7426f6373327487d878d13664477c41faed50fee 994972848 chromium_154.0.8037.57.orig.tar.xz 5ff103139cc220d9b1e54e7249d8723c8071795239ede5c5b28fde3f7a2b2d03 574952 chromium_154.0.8037.57-1~deb13u1.debian.tar.xz cc82e4a7fc4580b9d719922f3cf0144144c4fe22cf6c7c9d95765adbe04c27b4 27964 chromium_154.0.8037.57-1~deb13u1_source.buildinfo Files: dcb073c458bf65f703355120d55d1cbb 4415 web optional chromium_154.0.8037.57-1~deb13u1.dsc e06cc97eb104fe55cc12053c9d97c39b 16687904 web optional chromium_154.0.8037.57.orig-pre-gen.tar.xz 4b738be21f773aa587179d01ddb4100e 994972848 web optional chromium_154.0.8037.57.orig.tar.xz 4481ee00ac9a8d45ff6761c257ccca05 574952 web optional chromium_154.0.8037.57-1~deb13u1.debian.tar.xz de8fa6a79e092b380fbfeb567bef1007 27964 web optional chromium_154.0.8037.57-1~deb13u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmq1vnAUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8Nudjc4fg//YlLQWvT3E1orUR775IUTUdzYWwCC nASlk11yVKqypmZR4JKbIl1SkZ8Ux36yHNosXpYy5I0bMHS0oVAAwVo2YspHTW/j HL+Vy0o3LJKsRT/RYnbsu6e0Uex8FPBs9Ge3Nso17E+6L9J6+neBfxvyS4ZRwByR hlW1Hguha9Kdlwjj9HI1XYq72lV3xFx1KDfIZHIMT/67GPoakVz7bqUIZlMlwyKU Hu4LEVtVBW8tlROGAKFAf6OEE0HbzAYQu4Cs85ZcZdDauIOs5gyP2Ll8kLr4U1gH cc2a6CrQhLLfX13BGW4BDqVFjkzefmtu/+egTtEbi+weq5iV+swVxzpyZB854DRb zdD8SzUCsLQ032B2zYBl/5UZmPBQlvUvVXZzODbiLBRsaD8pvjdTzh/AJPdlbzFi ucCAdO2SfOhVrSl4QXMMWbsvU5H2bh3rkA8axWW3fXiyafoQgTBYOycu4xvVIkRY ueqU+z17dAwOn2s7GJgzRs3XwafQxQq3ew+0HFDq5zG5YNW8neqOId/EyIu75Uxl HYQSQy7cDPFM2VlIsyYNtgRBxerPKzozIjcAM0sVpeF0b5ZhufEIHnfAvOhjUNep P6Mq44t+crY7I1prEYaFnmXvdHeayx3+73YruiVCTTIP683oYFTLJBSGtIy71SE4 HGwWM0oLxDlFcu8= =Npyo -----END PGP SIGNATURE-----