-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Wed, 30 Sep 2026 03:47:05 -0400
Source: chromium
Architecture: source
Version: 154.0.8037.92-1~deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (154.0.8037.92-1~deb12u1) bookworm-security; urgency=high
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-102331: Buffer overflow in ANGLE. Reported by @mfx.
- CVE-2026-102317: Improper privilege management in Mojo.
Reported by Google.
- CVE-2026-102312: UI misrepresentation in Omnibox.
Reported by jodyritonga.
- CVE-2026-102313: Uninitialized resource in ANGLE. Reported by Google.
- CVE-2026-102299: Type confusion in V8. Reported by Andrew Boni.
- CVE-2026-102306: Use after free in Bluetooth. Reported by Google.
- CVE-2026-102307: Uninitialized resource in Dawn. Reported by Google.
- CVE-2026-102323: Type confusion in V8.
Reported by OpenAI Codex Security (amyb).
- CVE-2026-102303: Uninitialized resource in GPU. Reported by Google.
- CVE-2026-102311: Uninitialized resource in GPU. Reported by Google.
- CVE-2026-102300: Uninitialized resource in WebGPU.
Reported by Arni Hardarson (Neonix Security).
- CVE-2026-102326: Type confusion in V8.
Reported by OpenAI Codex Security (amyb).
- CVE-2026-102316: Use after free in Views. Reported by Xinyang Ge.
- CVE-2026-102304: Use after free in Passwords. Reported by Xinyang Ge.
- CVE-2026-102328: Type confusion in V8.
Reported by OpenAI Codex Security (amyb).
- CVE-2026-102309: Use after free in FullScreen. Reported by sean geofrey.
- CVE-2026-102325: Uninitialized resource in Skia. Reported by Google.
- CVE-2026-102308: Use after free in Views. Reported by Google.
- CVE-2026-102301: Out of bounds write in GPU. Reported by Google.
- CVE-2026-102319: Uninitialized resource in GPU. Reported by Google.
- CVE-2026-102324: Use after free in PictureInPicture.
Reported by Blockian Creator of Kritt and Open-Kritt.
- CVE-2026-102318: Out of bounds read in WebGL. Reported by Google.
- CVE-2026-102329: Cross-site scripting in WebUI. Reported by chipsec.
- CVE-2026-102315: Uninitialized resource in Media. Reported by Google.
- CVE-2026-102302: Buffer overflow in V8. Reported by Google.
- CVE-2026-102321: Type confusion in V8.
Reported by Taisic Yun (@taisic_) of Theori, with Xint.
- CVE-2026-102320: Missing authorization in CORS. Reported by Anonymous.
- CVE-2026-102310: Missing authorization in Payments.
Reported by Autodidact.
- CVE-2026-102327: Incorrect authorization in WebView. Reported by Google.
- CVE-2026-102330: Incorrect authorization in SiteIsolation.
Reported by Google.
- CVE-2026-102314: UI misrepresentation in TabStrip. Reported by Google.
- CVE-2026-102305: UI misrepresentation in SignIn. Reported by Google.
* d/patches:
- disable/omnibox-ai-mode.patch: add patch that *actually* removes the
AI Mode button from the new tab page's omnibox.
Checksums-Sha1:
60108826d6af5ebd70c895b42ca0ef3e1e67f722 4377 chromium_154.0.8037.92-1~deb12u1.dsc
971bd0c616f73b93c555e45aaafea6a7b4bf33d3 16689032 chromium_154.0.8037.92.orig-pre-gen.tar.xz
eab6649cbb68eeb184a5a899fda828988ac0b608 995122080 chromium_154.0.8037.92.orig.tar.xz
e84739f88cbb7b82adf67c107a161ea3fbb72bbc 583224 chromium_154.0.8037.92-1~deb12u1.debian.tar.xz
5426c99740a3a30ffd775121bbc140dca68e163a 27233 chromium_154.0.8037.92-1~deb12u1_source.buildinfo
Checksums-Sha256:
bf708279ff444e45eea56416cff239ca602d313cf560f1a6e4f7ba75d6bb8f23 4377 chromium_154.0.8037.92-1~deb12u1.dsc
d8316f2d3cbe1ab942629b9b1044166f33ca9575478feac814a31463c81e8cbe 16689032 chromium_154.0.8037.92.orig-pre-gen.tar.xz
d5a37fdb95f8c2d24f505f36824540158367d20101f47623e93670cbda006e7e 995122080 chromium_154.0.8037.92.orig.tar.xz
0813ba4e26b60856d0a039b2b5da12d1dac911b4d7f912c7f4b701ceb1f3553f 583224 chromium_154.0.8037.92-1~deb12u1.debian.tar.xz
6f65d5440a5bd5d17328335903294e6ae9632c4f999e625ec4b867d2a46ac5b7 27233 chromium_154.0.8037.92-1~deb12u1_source.buildinfo
Files:
be2b01389f9f5fedf5ab5762c867d688 4377 web optional chromium_154.0.8037.92-1~deb12u1.dsc
e2bbef87a3ae1828a7d523507e0fbe11 16689032 web optional chromium_154.0.8037.92.orig-pre-gen.tar.xz
49e6d74714cbed79ccb64da86f35c830 995122080 web optional chromium_154.0.8037.92.orig.tar.xz
ffc54ca22c1ce9a7d0c28682d22613e3 583224 web optional chromium_154.0.8037.92-1~deb12u1.debian.tar.xz
2127f992398ef5b4e682f8c832f3ba96 27233 web optional chromium_154.0.8037.92-1~deb12u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmq9ULYUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjfIyBAAmUEi4UMuhB5s7AhJV9n7+FZyZKUs
bUEvacn8rmviw8Myz8Ak38N1sX3yZg0w2t658E4J1IDftpEvfhhZysqbvYSy5ld3
Ft4XOYURBx8y/Dei1oe2K7eb8b10ZWDqQhobNisYWqN01z2ZSTfpoZzjivaO3il8
AVhYTKasZVYOZeOnRO/OwHTOfJ8jD2luzIs5iGJXv4JuN3wcWtWDVusJP6uO2T6J
AQRGuTrLMveRq/Z1eY/bWnQzPgAQB+7eA9RU4MBqHYRgFozOJyxfIsvpwXVP3wuK
j2Td940Su8gU/e6KOcA9TQHGTN12YsgZ48qhh38xiP/2b7MXwZ8+gJasT2N9K7Wh
vtGTKkLw4K1tbwXBPgv16t46kAjNJwCenWNWkUBpP0wdJ4luOHlA4pLtJyhu2ItK
HbPZk4zE7DzHG56gAp6i5eBx+axbqZ9sgfxWhn3OhULT1G++PuzU6DI5vRzAzLl4
cGgnvlERkQ6O4/kIYDkQaZUonfWO29JXgtPx+mmDktQNZ1MmfymAdQ62tCTUTkPe
n1V7cbwc7jTl3yiyUzhxFeeNKtmR+YydItLxlgQv/V8xANGusBSQqHHsfbl3JIk6
NaEmqsQmJ2nszJtPmGciD60x9DMTXYiH3IYhFeo29vmUf62CkBzPEovCQujSvedm
H4xpeq0JxqFWEhI=
=k3HM
-----END PGP SIGNATURE-----