-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Wed, 30 Sep 2026 03:47:05 -0400
Source: chromium
Architecture: source
Version: 154.0.8037.92-1
Distribution: unstable
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (154.0.8037.92-1) unstable; urgency=high
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-102331: Buffer overflow in ANGLE. Reported by @mfx.
- CVE-2026-102317: Improper privilege management in Mojo.
Reported by Google.
- CVE-2026-102312: UI misrepresentation in Omnibox.
Reported by jodyritonga.
- CVE-2026-102313: Uninitialized resource in ANGLE. Reported by Google.
- CVE-2026-102299: Type confusion in V8. Reported by Andrew Boni.
- CVE-2026-102306: Use after free in Bluetooth. Reported by Google.
- CVE-2026-102307: Uninitialized resource in Dawn. Reported by Google.
- CVE-2026-102323: Type confusion in V8.
Reported by OpenAI Codex Security (amyb).
- CVE-2026-102303: Uninitialized resource in GPU. Reported by Google.
- CVE-2026-102311: Uninitialized resource in GPU. Reported by Google.
- CVE-2026-102300: Uninitialized resource in WebGPU.
Reported by Arni Hardarson (Neonix Security).
- CVE-2026-102326: Type confusion in V8.
Reported by OpenAI Codex Security (amyb).
- CVE-2026-102316: Use after free in Views. Reported by Xinyang Ge.
- CVE-2026-102304: Use after free in Passwords. Reported by Xinyang Ge.
- CVE-2026-102328: Type confusion in V8.
Reported by OpenAI Codex Security (amyb).
- CVE-2026-102309: Use after free in FullScreen. Reported by sean geofrey.
- CVE-2026-102325: Uninitialized resource in Skia. Reported by Google.
- CVE-2026-102308: Use after free in Views. Reported by Google.
- CVE-2026-102301: Out of bounds write in GPU. Reported by Google.
- CVE-2026-102319: Uninitialized resource in GPU. Reported by Google.
- CVE-2026-102324: Use after free in PictureInPicture.
Reported by Blockian Creator of Kritt and Open-Kritt.
- CVE-2026-102318: Out of bounds read in WebGL. Reported by Google.
- CVE-2026-102329: Cross-site scripting in WebUI. Reported by chipsec.
- CVE-2026-102315: Uninitialized resource in Media. Reported by Google.
- CVE-2026-102302: Buffer overflow in V8. Reported by Google.
- CVE-2026-102321: Type confusion in V8.
Reported by Taisic Yun (@taisic_) of Theori, with Xint.
- CVE-2026-102320: Missing authorization in CORS. Reported by Anonymous.
- CVE-2026-102310: Missing authorization in Payments.
Reported by Autodidact.
- CVE-2026-102327: Incorrect authorization in WebView. Reported by Google.
- CVE-2026-102330: Incorrect authorization in SiteIsolation.
Reported by Google.
- CVE-2026-102314: UI misrepresentation in TabStrip. Reported by Google.
- CVE-2026-102305: UI misrepresentation in SignIn. Reported by Google.
* d/patches:
- disable/omnibox-ai-mode.patch: add patch that *actually* removes the
AI Mode button from the new tab page's omnibox.
Checksums-Sha1:
6ae16b240bded4a5b517a2a2d4e19c1b249f143a 4394 chromium_154.0.8037.92-1.dsc
971bd0c616f73b93c555e45aaafea6a7b4bf33d3 16689032 chromium_154.0.8037.92.orig-pre-gen.tar.xz
eab6649cbb68eeb184a5a899fda828988ac0b608 995122080 chromium_154.0.8037.92.orig.tar.xz
4969f4376cb9dab1051d10a5267968a845cd0232 574984 chromium_154.0.8037.92-1.debian.tar.xz
531287917a9ea125bd6aca78561e167b5befcc4e 27104 chromium_154.0.8037.92-1_source.buildinfo
Checksums-Sha256:
9b3de8d4e57510b7034e23264e322f7788188f509db8ad6f772602431ed3d882 4394 chromium_154.0.8037.92-1.dsc
d8316f2d3cbe1ab942629b9b1044166f33ca9575478feac814a31463c81e8cbe 16689032 chromium_154.0.8037.92.orig-pre-gen.tar.xz
d5a37fdb95f8c2d24f505f36824540158367d20101f47623e93670cbda006e7e 995122080 chromium_154.0.8037.92.orig.tar.xz
28cdf6c932e78b3ea46c79d5f7fc61f2bbf7fafe8398b2f225623dc31915ef59 574984 chromium_154.0.8037.92-1.debian.tar.xz
0b25ab0f2bed20ea1f6fb3b788766477a62079c9574b43765411688519ac7428 27104 chromium_154.0.8037.92-1_source.buildinfo
Files:
6966e7e273f8bb0d9747f72d642c8aa8 4394 web optional chromium_154.0.8037.92-1.dsc
e2bbef87a3ae1828a7d523507e0fbe11 16689032 web optional chromium_154.0.8037.92.orig-pre-gen.tar.xz
49e6d74714cbed79ccb64da86f35c830 995122080 web optional chromium_154.0.8037.92.orig.tar.xz
4653e5487ae0165d7b7cf1c60ec8784c 574984 web optional chromium_154.0.8037.92-1.debian.tar.xz
01d3d64b828715ecf50b025d52399285 27104 web optional chromium_154.0.8037.92-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmq9SN0UHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjcOjBAAsDvq33WN+3zx0p2sUdY20wvIJYHI
EQf06ZUdrKQWjk/gXf3Y4QW9eA4hQQXj6+CRCVvDGOSiY/IcYC0KNZh74zJT1v4P
tSlF3jHfvb9oZ+0EaXp4svY4wCayGyngnbgLsJ1lYpHEfTQBnCsCdsbTha1xX4/G
5UP1T6RHcX3lYTBw0uUxOwhua1p/mOohFZWRp++/hNC0YyeiWkKIgFqtQh6gdXSI
OkMek/1qaTnivZ7Vih8fiO/MjOkg0UFlo0UpXbKbsBIZ1zL1ybK0Jj09WjQ6TazH
L92RrtGgJaCwxNFPhxLlkoyiuf6srq493uHXubbDq7uW1II5geYZgO8mGVUExmpu
BG9qecJbjRzD8KSm82O6oiLBuOs45VCdEXh3/cOOkQVkB11Y3m72Ylm+b1fbKjk4
oZlyoo7fiyPtdaqis7HiUE+JjMcqFbQhExyIvo+xdV4bzS4MARfuZcdHmaczrmLc
KHoAd0SsadKdnQIhzu3KILrFz24uWAhc/fOc6fOKoRzxseHhNsitsLKMBDgJmLgm
rWT1DH9aWZXyKKdxKgXRb8FBncxhEtEX1RLkKk/Vanh6K1XXwmFn2nRE2n+qzfO2
sAiEkwuGMXuOrYWcr4VYRgIDhf0eKymN2OWH4UT6ZtIvonkOAAfTVMs/TGMPHknh
5hC/MgX2knDLmGs=
=IDdl
-----END PGP SIGNATURE-----