[qt/qt/qtwebengine-chromium]: Summary of bulk changes made

KDE Git Services - Bulk Change <[email protected]>
Newsgroups gmane.comp.kde.cvs
Message-ID <[email protected]>
Git repository change summary for qt/qt/qtwebengine-chromium
Pushed by mirror-service into branch '140-based'.
Changed from 1e2ffa9caf5466dda4228c0d30d943251614524b to 2b58222ca1e73e710a9278986a40c1b6890bd09d
Acknowledgement was received that this change introduces only existing code that has been pushed to another public open source repository.

This change contains the following new commits:

Git commit e471cdc84f01050b0b384bb79c1d2d0bea13a595 by Michael Brüning on 28/07/2026 at 11:52..
[roll][libvpx] CVE-2026-13906: Out of bounds read in Codecs

Update libvpx to the version used in Chromium 150.0.7871.115 to include
the fix for CVE listed above and various other fixes.

Roll src/third_party/libvpx/source/libvpx/ d5f35ac8d..5f0041366 (116 commits)

https://chromium.googlesource.com/webm/libvpx.git/+log/d5f35ac8d..5f00413667d1

git log d5f35ac8d..5f0041366 --date=short --no-merges --format='%ad %ae %s'
2026-05-27 [email protected] Revert "Fix the use of uninitialized value in qsort"
2026-05-27 [email protected] vp9_encoder.c,qsort_comp: fix pointer cast
2026-05-25 [email protected] Disable usage of prev_mi_grid_visible under resize
2026-05-22 [email protected] vpx_dsp.mk: exclude highbd_sse_neon.c w/encoders disabled
2026-05-22 [email protected] include select vpx_sad functions in postproc build
2026-05-22 [email protected] vp9: Fix to perceptual_aq mode under resize.
2026-05-22 [email protected] Fix to arf/lastgolden usage buffers for realtime lag
2026-05-21 [email protected] vp9_postproc: disable VP9D_DEMACROBLOCK w/uv_width < 8
2026-05-20 [email protected] vp9_postproc: disable VP9D_DEBLOCK w/uv_width < 8
2026-05-20 [email protected] vp9_post_proc_frame: disable VP9D_ADDNOISE w/high-bitdepth
2026-05-19 [email protected] vp8-multi-res-encoding: Fix to out-of-bounds write
2026-05-19 [email protected] validate_img: add error msg for validate_hbd_input failure
2026-05-18 [email protected] vp9_cx_iface,validate_img: check plane ptr before reading
2026-04-29 [email protected] rtc-rc: Checks limts on inputs to external rc
2026-05-15 [email protected] vpx postproc: Fix to buffer overflow in vpx_setup_noise
2026-05-14 [email protected] vp9: Fix to mfqe for resize
2026-05-15 [email protected] Guard alpha plane access with condition
2026-05-13 [email protected] vp9-svc: Avoid write_superframe for empty superframe
2026-05-13 [email protected] vp9_cx_iface.c: fix signed/unsigned warning
2026-05-12 [email protected] Fix buffer overflow in set_mb_ssim_rdmult_scaling
2026-05-08 [email protected] configure: add arm64/win32 VS18 targets
2026-05-08 [email protected] Use g_bit_depth during input validation
2026-03-26 [email protected] Revert "Remove spinning before calling pthread_mutex_lock"
2026-05-07 [email protected] Replace NULL with nullptr in .cc files
2026-05-06 [email protected] Fix clang-tidy warnings in libvpx
2026-05-06 [email protected] vp9_int_pro_motion_estimation: fix stride w/scaled ref
2026-04-28 [email protected] vp9: fix to buffer overflow under resolution change
2026-04-30 [email protected] vpxenc: add --validate-hbd-input option
2026-04-30 [email protected] add test coverage for VP9E_SET_VALIDATE_HBD_INPUT
2026-05-01 [email protected] vp9-svc: Set consistent value for temporal_layering_mode
2026-04-30 [email protected] rename VP9E_SET_VALIDATE_INPUT_HBD -> VALIDATE_HBD_INPUT
2026-04-30 [email protected] vp9: wrap size check in #if INT64_MAX > SIZE_MAX
2026-04-30 [email protected] Cast tokens to size_t when allocating
2026-04-30 [email protected] vp9: replace heavy token alloc test with unit test
2026-04-28 [email protected] Fix VP9 float-to-int overflow in validate_config
2026-04-28 [email protected] Fix VP8 decoder crash on flush with no fragments
2026-04-27 [email protected] Fix overflow in get_token_alloc leading to OOM
2026-04-27 [email protected] Fix VP9 highbitdepth encoder format mismatch
2026-04-28 [email protected] Fix VP8 signed overflow in vp8_encode_frame
2026-04-27 [email protected] vp9: fix to negative quantizer with force_frame_boost
2026-04-28 [email protected] Fix VP9 float-to-int overflow with zero bitrate
2026-04-24 [email protected] vp9: Add unittest for svc issue: 505665613
2026-04-27 [email protected] vp8: Clamp vp8_set_static_threshold
2026-04-24 [email protected] vp9-svc: fix integer overflow in get layer resolution
2026-04-24 [email protected] vp9-svc: follow-up to disallow svc for 2pass
2026-04-23 [email protected] Add null checks to _set/get_reference for vp8/vp9.
2026-04-23 [email protected] vp9-svc: fix issue with svc.duration overflow
2026-04-23 [email protected] vp9-svc: Constrain per-layer speed to be >=5 for realtime build
2026-04-23 [email protected] vp9-svc: condition scale_references on use_nonrd_pick_mode
2026-04-23 [email protected] Check on baseline_gf_interval for gf_cbr_boost_pct
2026-04-22 [email protected] vp9-svc: Disallow svc for 2 pass encoding.
2026-04-22 [email protected] vp9-svc: range checks to the layer max/min_quantizers
2026-04-14 [email protected] vp9: fix to cyclic_refresh_setup with svc dynamic layers
2026-04-01 [email protected] LoongArch: Defer filter pointer retrieval to fix out-of-bounds
2026-04-14 [email protected] vpx_temporal_svc_encoder: remove unused global
2026-04-08 [email protected] decode_api_test.cc: fix visual studio warnings
2026-04-08 [email protected] vp8_de_alloc_frame_buffers: more cleanup
2026-04-08 [email protected] vp8_de_alloc_frame_buffers: clear mi/postproc_state
2026-04-07 [email protected] Change asm volatile to __asm__ __volatile__
2026-04-06 [email protected] vp9_decodeframe.c: move ref frame index check earlier
2026-04-03 [email protected] Enable the ISO C11 standard
2026-04-02 [email protected] {vp9_cx_iface,vp9_decoder}.c: add some missing includes
2026-04-01 [email protected] vp9_decodeframe: promote row-mt calcs to size_t
2026-04-01 [email protected] test/android/Android.mk: build tests w/-std=c++17
2026-03-30 [email protected] vp9: fix for out-of-bounds write in decode coeffs
2026-03-31 [email protected] gen_msvs_vcxproj: set C++ language standard to C++17
2026-03-28 [email protected] Update to GoogleTest 1.17.0
2026-03-30 [email protected] vp9; move source input check to validate_img
2026-03-29 [email protected] Allow patch files to have trailing spaces
2026-03-27 [email protected] encoder_encode: Omit two res == VPX_CODEC_OK tests
2026-03-28 [email protected] Remove bit_depth member of struct TestSSEFuncs
2026-03-27 [email protected] README: update bug tracker link
2026-03-23 [email protected] vp9: Add check to validate source input
2026-03-23 [email protected] encode_api_test: replace kHeight w/kWidth for stride
2026-03-16 [email protected] vpx_image,img_alloc_helper: verify vpx_img_fmt_t
2026-03-14 [email protected] vp[89] encoders: reject unequal UV strides
2026-03-14 [email protected] vp9,encoder_encode: fix validate_img() check
2026-03-11 [email protected] encode_api_test: add repro for b/488585490
2026-03-08 [email protected] y4minput: fix integer overflow in buffer size calculations
2026-03-11 [email protected] y4minput.c: Set alpha plane to NULL, stride to 0
2026-03-10 [email protected] vp9-svc: validate spatial_layer_id
2026-03-02 [email protected] vp9_scale_references: fail if no free buffer is available
2026-03-02 [email protected] vp9_pick_inter_mode: fix buf offsets w/scaled refs
2026-02-26 [email protected] yuv_video_source: fix stride/width check w/16bpp
2026-02-24 [email protected] yuv_video_source: fix reading files w/odd widths
2026-02-24 [email protected] add support for msvc v145 / VS 2026
2026-02-23 [email protected] encode_api_test: disable OssFuzz471723682
2026-02-18 [email protected] vpx_enc_fuzzer: condition max frames on deadline
2026-02-19 [email protected] Make direct calls to Neon variance paths in Neon subpel variance
2026-02-19 [email protected] Add Armv8.4 Neon DotProd subpel variance paths
2026-02-19 [email protected] Remove Armv8.4 Neon DotProd 4x4 variance kernel
2026-02-18 [email protected] vp8,calc_pframe_target_size: fix integer overflow
2026-02-18 [email protected] examples/*.c: fix incorrect die_codec() usage
2026-02-17 [email protected] **README.libvpx: add missing fields / sync w/libaom
2026-02-12 [email protected] vp8_decode_frame: improve header / partition 0 check
2026-02-13 [email protected] rtcd.pl: use a fixed year for *rtcd.h Copyright
2026-02-12 [email protected] vp8_decode_frame: validate partition 0 size
2026-02-10 [email protected] vpx_enc_fuzzer: limit number of encoded frames
2026-02-09 [email protected] Revert "Increase alignment for wider SIMD optimization"
2026-02-09 [email protected] Revert "vpxdsp: [x86] AVX2 and AVX512 for tm intra predictor"
2026-02-02 [email protected] vpxdsp: [x86] small tweak to vpx_highbd_tm_predictor_4x4_sse2
2026-01-22 [email protected] vpxdsp: [x86] AVX2 and AVX512 for tm intra predictor
2026-01-23 [email protected] Increase alignment for wider SIMD optimization
2026-02-04 [email protected] vpx_enc_fuzzer: add missing break statements
2026-02-03 [email protected] Test for ioc: use more general rounding
2026-01-28 [email protected] builtin_assume range of token values
2026-02-02 [email protected] Test that tokens are within range
2026-02-02 [email protected] Also builtin_assume value of ctx_cur
2026-02-02 [email protected] cleanup: remove unnecessary copy of ctx
2026-01-22 [email protected] Avoid ioc in intermediate step
2026-01-28 [email protected] builtin_assume energy values are within bounds
2026-01-28 [email protected] Add test for maximum value of vp9_pt_energy_class
2026-01-22 [email protected] __builtin_assume that scan values are in range
2026-01-08 [email protected] configure: add --disable-x86-asm
2026-01-17 [email protected] vpxdsp [x86]: AVX2 for 16x16 high bd d207 and d63 intra pred
2026-01-23 [email protected] vp8: fix use_dc_pred condition in mb_activity_measure
2026-01-22 [email protected] Add test that all scan values are <= MAX_SCAN_VALUE

Change-Id: I8a8a4a355b50d491f1d173560976aed94716b879
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/753884
Reviewed-by: Michal Klocek <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/e471cdc84f01050b0b384bb79c1d2d0bea13a595

Git commit 792aed16529eacb8664e9161e2486bc2fe419cc3 by Michal Klocek on 28/07/2026 at 11:55..
[roll][harfbuz] CVE-2026-13938: Integer overflow in Fonts

Roll harfbuzz to version 14.2.0-69 (d639197e) from Chromium
150.0.7871.150.

Changes to build itsef are done in follw up commit.

Task-number: QTBUG-147901
Change-Id: I20b39bd063b851734a5db00b398a0661853ed5ad
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754704
Reviewed-by: Allan Sandfeld Jensen <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/792aed16529eacb8664e9161e2486bc2fe419cc3

Git commit deca52af2f803b40a45072147f7b64405a59b017 by Michal Klocek on 28/07/2026 at 11:56..
[rust][harfbuzz][qt3rdparty] Build harfbuzz without rust

This is just 140-based fix, as later harfbuzz-ng becomes harfbuzz
and those files need fixup.

Disable build with rust as harfrust dependencies are not in
current source tree.

Change-Id: I7ce3b9f74356e1af25515eeca70abf1fe94d53d4
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754705
Reviewed-by: Allan Sandfeld Jensen <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/deca52af2f803b40a45072147f7b64405a59b017

Git commit 1edd2430c007b4adaabc9d291f09277ae25697ab by Michal Klocek (on behalf of Eugene Zemtsov) on 28/07/2026 at 11:56..
[backport] CVE-2026-13958: Uninitialized Use in Codecs

media: Fix buffer leak in MFAudioEncoder

MFAudioEncoder appended new buffers to the output sample without
removing old ones when the required output size increased. This
caused unbounded memory growth.

Fixed by calling `RemoveAllBuffers()` before adding a new buffer.

Bug: 513567306
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7851728
Task-number: QTBUG-147902
Change-Id: I3df6c4665111c210a3930bb69155c723074078fb
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754889
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/1edd2430c007b4adaabc9d291f09277ae25697ab

Git commit 3adedb764b842f4d9a9b40f2f0b1207b5d0f352d by Michal Klocek (on behalf of David Baron) on 28/07/2026 at 11:56..
[backport] CVE-2026-13959: Insufficient validation of untrusted input in Blink

Limit TouchEvent/WheelEvent messages about preventDefault to trusted events.

Fixed: 513609249
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7853179
Task-number: QTBUG-147902
Change-Id: I2c7e37260de6943b41ea5f56c16f5207e21dded0
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754890
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/3adedb764b842f4d9a9b40f2f0b1207b5d0f352d

Git commit 2847fd1588d896d3b530ff4d7471df70ff997afa by Michal Klocek (on behalf of Wolfgang Beyer) on 28/07/2026 at 11:56..
[backport] CVE-2026-13961: Insufficient validation of untrusted input in DevTools

Verify workspace path is local and does not reference parent

Fixed: 513719481
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7876392
Task-number: QTBUG-147902
Change-Id: I20aa1e2cb38ffdcc087f6ad95fb79ed8583edd65
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754891
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/2847fd1588d896d3b530ff4d7471df70ff997afa

Git commit 485825e2207f08b3c772b7d60814e6f66379b511 by Michal Klocek (on behalf of Michael Lippautz) on 28/07/2026 at 11:56..
[backport] CVE-2026-13965: Use after free in Oilpan

heap: Make range-based write barrier more robust

Fix bailouts on the barrier for possible nullptr cases.

CONV=47326a54-47d2-449d-b308-f51eb6b5b3b8
TAG=AGY

Fixed: 513737952
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7852268
Task-number: QTBUG-147902
Change-Id: Iaa8598bc06a1782f77af7a3ea02359d918673688
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754892
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/485825e2207f08b3c772b7d60814e6f66379b511

Git commit af38fb93d93746f466981ab1b2831bfed975b966 by Michal Klocek (on behalf of Marc Treib) on 28/07/2026 at 11:56..
[backport] CVE-2026-13966: Inappropriate implementation in History

History: Don't consider IP literals for "typed" promotion

The history component automatically promotes intranet hosts (like
"http://myhost") to a "TYPED" transition type, so that the omnibox will
recognize the known host in the future.

Before this CL, IP literals were also detected as "intranet hosts" and
so the same promotion logic would (accidentally) apply to them.

This CL fixes this by excluding IP literals from
IsUntypedIntranetHost().

Fixed: 513741393
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7864242
Task-number: QTBUG-147902
Change-Id: Ia52da2625c3da177fc35e119e3e5b54c6a6a6964
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754893
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/af38fb93d93746f466981ab1b2831bfed975b966

Git commit 0fd818b5beef15e29fa29952870a94f45007f427 by Michal Klocek (on behalf of Alina Varkki) on 28/07/2026 at 11:56..
[backport] CVE-2026-13969: Uninitialized Use in UI

Fix prototype pollution in trace FramesHandler using Map

Migrate mapFrames to a built-in Map class to prevent attacker-controlled trace frame keys from interacting with or mutating Object.prototype.

Bug: 513762145
Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/7864400
Task-number: QTBUG-147902
Change-Id: I35f1091349a956d2bcad99a2292c2b695302854f
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754894
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/0fd818b5beef15e29fa29952870a94f45007f427

Git commit bab060fe568a9502d54314f9bb8a8efb206cc2cd by Michal Klocek (on behalf of Thomas Guilbert) on 28/07/2026 at 11:56..
[backport] CVE-2026-13970: Uninitialized Use in Media

Fix IncreaseCapacity when FIFO is full

This CL fixes an edge case in `IncreaseCapacity()` which is only reached
when the FIFO is full. At full capacity, the read and write indices are
identical. After rotating the new blocks, the write index is correctly
pointing to the newly inserted blocks, and should not be updated.

Bug: 513779283
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7866205
Task-number: QTBUG-147902
Change-Id: I96199d193e7e8c704f64168a1567bcb3caca14c7
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754895
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/bab060fe568a9502d54314f9bb8a8efb206cc2cd

Git commit 2dca730dde0afecfecac4266bfeabb9ebc34688c by Michal Klocek (on behalf of Kaylee Lubick) on 28/07/2026 at 11:56..
[backport] CVE-2026-13971: Uninitialized Use in Skia

Address potential MSAN issue in SkScalerContext

If malformed data was passed to SkStrikeClient, an unexpected
mask would pass through asserts in a release build and lead
to a mask being allocated that was 4x bigger than what
was written to.

To defend against this problem, we 1) reject masks that
aren't of the three formats SkScalerContext::GenerateImageFromPath
expects; 2) zero out the whole mask, regardless of how big
it is instead of relying on how big an A8 mask would be.

Additionally, I noticed that in the intermediateDst case
(e.g. for LCD text when we draw into an A8 and then later unpack
it to be LCD16) we weren't zeroing that intermediate buffer
which could be a problem if the glyph itself was small (but
the bounds were corrupted to be big). Thus, we zero that
intermediate A8 buffer too.

Bug: 513780208
Fixed: 513780208
Reviewed-on: https://skia-review.googlesource.com/c/skia/+/1248536
Task-number: QTBUG-147902
Change-Id: Ib7080fc45eb77ea19b3e733570da33cd339a51f8
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754896
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/2dca730dde0afecfecac4266bfeabb9ebc34688c

Git commit 56a9164d4318c5056b735fe0e3c828ed3d66de23 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 11:57..
[backport] CVE-2026-13972: Inappropriate implementation in Paint

Fix occlusion by not overwriting z_offset for overflow controls

https://crrev.com/1489781 introduced an intersection observer v2
regression due to overwriting z_offset when calculating overflow
control hit testing. This patch fixes this by using
`IsHitCandidateForDepthOrder` instead of an unconditional write.

Fixed: 513792140
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7854801
Task-number: QTBUG-147902
Change-Id: Ie970f24104dfa8e14e6d4bd6c67880048c9a0209
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754897
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/56a9164d4318c5056b735fe0e3c828ed3d66de23

Git commit 632f89bd763923e3569a961a9829040d88498c8d by Michal Klocek (on behalf of Le Hoang Quyen) on 28/07/2026 at 11:57..
[backport] CVE-2026-13975: Out of bounds read in ANGLE

Metal: Fix baseVertex type in RenderCommandEncoder

Change baseVertex type from uint32_t to int32_t in
drawIndexedInstancedBaseVertexBaseInstance to correctly support
negative values. Also fix the stream fetch to use int32_t.

Added a regression test NegativeBaseVertex.

Even before this change, the sign mismatch bug didn't seem to affect
the test results, possibly because the Metal driver performs the
computation in 32 bits.

Bug: chromium:513857658
Reviewed-on: https://chromium-review.googlesource.com/c/angle/angle/+/7859153
Task-number: QTBUG-147902
Change-Id: I351ba1f3a5f84545ab6944686a091dad24b636ba
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754898
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/632f89bd763923e3569a961a9829040d88498c8d

Git commit b394f282083ce3f27007ab2d83c73d461c62a01b by Michal Klocek (on behalf of David Baron) on 28/07/2026 at 12:00..
[backport] CVE-2026-13977: Inappropriate implementation in HTMLParser

Fix fragment parsing inside <mathml:annotation-xml> elements.

Fixed: 513859894
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7863551
Task-number: QTBUG-147903
Change-Id: I413d5b1fdb61f60e38ca77d25a8b463c630f003e
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755197
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/b394f282083ce3f27007ab2d83c73d461c62a01b

Git commit 657f69de7de5ef14549d634c3e8b069b53a4d2c8 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:00..
[backport] CVE-2026-13979: Inappropriate implementation in Paint (1/5)

Avoid no-op filter invalidations with multiple filters

crrev.com/1588040 updated reference filter equality to check for
filter_ changes. If there are multiple filters though,
`SVGElementResourceClient::UpdateFilterData` will always re-create
the filter, causing an unnecessary invalidation. This patch avoids
filter_ changes if the reference filters are unchanged.

Bug: 513988889
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7872260
Task-number: QTBUG-147903
Change-Id: I16d7eff9bc3a9431cf2e28fbae4d49e189f95fd9
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755198
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/657f69de7de5ef14549d634c3e8b069b53a4d2c8

Git commit a1990e18097f5c1868f72052a560d5dc350ac710 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:00..
[backport] CVE-2026-13979: Inappropriate implementation in Paint (2/5)

Fix reference filter rect mapping with a single filter

UpdateFilterData now sets the built Filter on ReferenceFilterOperation
in the "is_single_reference_filter" codepath, matching what is already
done in the non-single-reference codepath. This enables
FilterOperations::MapRect to properly map reference filter rects.

Bug: 513988889
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7871868
Task-number: QTBUG-147903
Change-Id: Icddcf21bd4607ddbcd1364325886bf2bc5ed7dc5
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755199
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/a1990e18097f5c1868f72052a560d5dc350ac710

Git commit 5f8eb8912d678af9b13fb6016b35b5a2417bd7aa by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:00..
[backport] CVE-2026-13979: Inappropriate implementation in Paint (3/5)

Include filters in SVG occlusion tests

When performing hit tests for occlusion (i.e., intersection observer
v2), we need to include filter effects. This patch updates the SVG hit
testing code to inflate the visual overflow with filters, and use this
for occlusion hit tests.

Fixed: 513988889
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7858119
Task-number: QTBUG-147903
Change-Id: Ib2cad21105fd829d0cd744a698907fe6dd999a3c
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755200
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/5f8eb8912d678af9b13fb6016b35b5a2417bd7aa

Git commit 7e8099eb30be5b414b0662d15fc7402be6011a93 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:00..
[backport] CVE-2026-13979: Inappropriate implementation in Paint (4/5)

Unify ApplyFiltersToRect in SVGLayoutSupport and LayoutBoxModelObject

This patch updates `LayoutBoxModelObject::ApplyFiltersToRect` to call
`SVGLayoutSupport::ApplyFiltersToRect`. The call to IsZero has been
removed as there are no cases in practice where a reference box would
be zero sized and at a different location from the input rect, since
the reference box and input rect are derived from the object's size.

`MapToSVGRootIncludingFilter` is missing the reference box expansion
and would also benefit from `SVGLayoutSupport::ApplyFiltersToRect`, so
a TODO has been added to do that.

Bug: 513988889
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7876061
Task-number: QTBUG-147903
Change-Id: I7eadaf135744c023ca61d74a0776cf50f642185e
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755201
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/7e8099eb30be5b414b0662d15fc7402be6011a93

Git commit de3e6fe90d665aa743662499a3b43031adc2f434 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:00..
[backport] CVE-2026-13979: Inappropriate implementation in Paint (5/5)

Use SVGLayoutSupport::ApplyFiltersToRect in MapToSVGRootIncludingFilter

This patch updates `MapToSVGRootIncludingFilter` to use
`SVGLayoutSupport::ApplyFiltersToRect` which contains some additional
code to inflate by the reference box, fixing a bug.

Bug: 513988889
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7875520
Task-number: QTBUG-147903
Change-Id: Ia1d32911bd4f18584930baf4250a4bd356c171d6
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755202
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/de3e6fe90d665aa743662499a3b43031adc2f434

Git commit 025760ed953a1584be443f8c1efe652c428a5775 by Michal Klocek (on behalf of Ian Kilpatrick) on 28/07/2026 at 12:00..
[backport] Dependency for CVE-2026-13988

Remove {LayoutBlock,LayoutBlockFlow}::HitTestChildren

LayoutBlock overrides NodeAtPoint - without callings its super-class
method LayoutBox::NodeAtPoint.

HitTestChildren is only used within LayoutBox::NodeAtPoint, and
therefore the LayoutBlock::HitTestChildren, and
LayoutBlockFlow::HitTestChildren logic was unreachable.

Remove these override, and additionally shift LayoutBox::NodeAtPoint
down to LayoutReplaced::NodeAtPoint as this is where it is actually
used.

There should be no behaviour change.

Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7426176
Task-number: QTBUG-147903
Change-Id: I01d075bea96f651489b9c3809a10973a75a1825b
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755241
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/025760ed953a1584be443f8c1efe652c428a5775

Git commit efe2791ac58209b2abcd331e752ccc4ebb8d5db5 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:01..
[backport] CVE-2026-13988: Inappropriate implementation in Paint

Fix border-radius hit testing for visual overflow

When hit testing visual overflow, we cannot stop hit testing once a hit
is outside the border because effects like box-shadow can still be
present.

Fixed: 514040614
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7858611
Taks-number: QTBUG-147903
Change-Id: I4c0daacbb659966a4088277a1ef9f8ab5e75f5fb
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755242
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/efe2791ac58209b2abcd331e752ccc4ebb8d5db5

Git commit 25fdf60d0cb195f234e6af81309f84b9a63a3a4e by Michal Klocek (on behalf of Bryan Oltman) on 28/07/2026 at 12:01..
[backport] CVE-2026-13992: Inappropriate implementation in UI

Drop redispatched events if window is no longer key

When an unhandled renderer event is returned for system processing,
the CommandDispatcher redispatches it. If the window has lost its
"key" status (e.g., due to a focus change while the event was
in-flight), redispatching it can cause the event to be incorrectly
handled by the newly focused window.

This CL ensures that we only redispatch events if the target window
is still the key window.

Fixed: 514063409
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7864509
Task-number: QTBUG-147903
Change-Id: I022d7f45d5c35d26a96b4efc55c0621eb73b3a80
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755593
Reviewed-by: Michael Brüning <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/25fdf60d0cb195f234e6af81309f84b9a63a3a4e

Git commit 6c7949fb4e966c402211ba6b53cdec6a6da79429 by Michael Brüning (on behalf of Alexander Cooper) on 28/07/2026 at 12:09..
[Backport] CVE-2026-13910: Insufficient policy enforcement in WebXR

Cherry-pick of patch originally reviewed on
https://chromium-review.googlesource.com/c/chromium/src/+/7837042:
Improve input suppression for cross-origin DOM Overlay

Modify the DOM Overlay hit testing logic to correctly identify and
suppress input events when they intersect cross-origin frames.

Specifically, we now use the frame element's content frame directly
instead of checking for the content document. This allows properly
recognizing and handling Out-of-Process Iframes (RemoteFrames) which do
not have a local content document.

Additionally, we compare the hit frame's security origin against the
origin of the WebXR session's execution context, rather than comparing
against the outermost main frame. This correctly handles cases where the
XR session itself is running in an embedded subframe.

Fixed: 507231605
Change-Id: Ie4d5291c36f86c16d5cd8f78fc0a08a1ce783096
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7837042
Reviewed-by: Daniel Cheng <[email protected]>
Auto-Submit: Alexander Cooper <[email protected]>
Commit-Queue: Alexander Cooper <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1628794}
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755518
Reviewed-by: Allan Sandfeld Jensen <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/6c7949fb4e966c402211ba6b53cdec6a6da79429

Git commit e48489ddd8c15be7b00b1cf05421053f59611a54 by Michael Brüning (on behalf of Eden Wang) on 28/07/2026 at 12:10..
[Backport] Dependency for CVE-2026-15107

Manual cherry-pick of patch originally reviewed on
https://chromium-review.googlesource.com/c/chromium/src/+/6965169:
Fix lifetime issue in InspectorIndexedDBAgent during navigation

This change improves the lifetime management of objects involved in
asynchronous IndexedDB DevTools operations.

Previously, objects handling async callbacks could outlive the DevTools
session they depended on, particularly during a page navigation. This
could lead to instability.

The fix introduces weak pointers to safely manage the relationship
between the callback handlers and the agent. This ensures that callbacks
can detect when the session has been destroyed and abort gracefully
instead of accessing invalid state.

Bug: 446423320
Change-Id: Iec5355c44d27d496eb7274da69ddaf32be9cdfb6
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6965169
Reviewed-by: Philip Pfaffe <[email protected]>
Auto-Submit: Wang Neden <[email protected]>
Commit-Queue: Philip Pfaffe <[email protected]>
Reviewed-by: Alex Rudenko <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1518646}
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755589
Reviewed-by: Allan Sandfeld Jensen <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/e48489ddd8c15be7b00b1cf05421053f59611a54

Git commit e10fb4922bb701ac82b9642a584b8226bda3a399 by Michael Brüning (on behalf of Steve Becker) on 28/07/2026 at 12:10..
[Backport] CVE-2026-15107: Use after free in IndexedDB

Manual cherry-pick of patch originally reviewed on
https://chromium-review.googlesource.com/c/chromium/src/+/8007837:
InspectorIndexedDBAgent must not use v8_session_ after disposal

`v8_session_` is a `raw_ptr` member of `InspectorIndexedDBAgent`. To
prevent use after frees, this fix updates
`InspectorIndexedDBAgent::Dispose()` to set `v8_session_` to `nullptr`.
The change then adds null checks before each use of `v8_session_`.
`nullptr`.

This fix follows the same pattern as `InspectorDOMAgent`:

https://source.chromium.org/chromium/chromium/src/+/main:third_party/blink/renderer/core/inspector/inspector_dom_agent.cc;drc=284b36ac2742525000db2ca28f448f6cc8584f40;l=3416

The change adds a test that repros 100% on ASAN builds.

Bug: 503553615
Change-Id: Ifa540fb83556710d197ed4b3c942ab61c37de35b
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8007837
Reviewed-by: Philip Pfaffe <[email protected]>
Commit-Queue: Steve Becker <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1653288}
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755590
Reviewed-by: Allan Sandfeld Jensen <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/e10fb4922bb701ac82b9642a584b8226bda3a399

Git commit 0800b99019b11be8b57bd46691927fda283c92e0 by Michael Brüning (on behalf of Hirokazu Honda) on 28/07/2026 at 12:10..
[Backport] CVE-2026-16807: Out of bounds write in Codecs

Cherry-pick of patch originally reviewed on
https://chromium-review.googlesource.com/c/chromium/src/+/7939189:
media/gpu/v4l2: Verify chroma and detect bit depth changes

This CL updates the V4L2 stateless video decoder to reject streams
with chroma subsampling other than 4:2:0, which are unsupported.

It also introduces bit depth tracking. Previously, changes in bit
depth that did not accompany a resolution change were ignored. Now,
a change in bit depth correctly triggers the resolution change
workflow so that buffers can be reallocated with the appropriate
format.

Bug: 518237034
Test: video.ChromeStackDecoder.*
Change-Id: I3c55372ec3a454b208215626b3962b14f71230d6
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7939189
Commit-Queue: Hirokazu Honda <[email protected]>
Reviewed-by: Nathan Hebert <[email protected]>
Auto-Submit: Hirokazu Honda <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1647107}
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755598
Reviewed-by: Allan Sandfeld Jensen <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/0800b99019b11be8b57bd46691927fda283c92e0

Git commit 12ab59be7fba04c2d9dc8e46e11c6123d07def74 by Michael Brüning (on behalf of Koji Ishii) on 28/07/2026 at 12:10..
[Backport] CVE-2026-16805: Use after free in Blink

Manual cherry-pick of patch originally reviewed on
https://chromium-review.googlesource.com/c/chromium/src/+/8106916:
Add validity checks after `CompositionRange()`

Following up crrev.com/c/7840643, this patch adds validity
checks after calls to `CompositionRange()`, which invokes
`Document::UpdateStyleAndLayout()`.

Also change `FrameSelection::RootEditableElementOrDocumentElement()`
to return `nullptr` when the selection is no longer available
after the layout it forces, instead of dereferencing a cleared
`document_`.

Bug: 523292588
Change-Id: I4a82a3b57fb00137dd45be946fd8e045ed46be2f
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8106916
Reviewed-by: Dave Tapuska <[email protected]>
Auto-Submit: Koji Ishii <[email protected]>
Commit-Queue: Dave Tapuska <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1663857}
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755599
Reviewed-by: Allan Sandfeld Jensen <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/12ab59be7fba04c2d9dc8e46e11c6123d07def74

Git commit 322c8c14b26c9a469e1c13bf3f23ac81a25f41ee by Michael Brüning (on behalf of Aman Verma) on 28/07/2026 at 12:10..
[Backport] Security bug 459347936 / Dependency for CVE-2026-16804

Cherry-pick of patch originally reviewed on
https://chromium-review.googlesource.com/c/chromium/src/+/7156432:
Fix UAF in OverscrollController::CompleteAction

This patch fixes a use-after-free vulnerability in OverscrollController.
The `delegate_->OnOverscrollComplete()` call can potentially lead to the
destruction of the `OverscrollController` instance, for example, when
the delegate initiates a navigation. If this happens, the subsequent
call to `Reset()` on the now-deleted `this` pointer causes a crash.

To prevent this, this change introduces a `base::WeakPtrFactory` and
checks the validity of the weak pointer after the delegate call. If the
instance has been destroyed, the function now returns early, avoiding
the UAF.

This patch also adds a unit test to overscroll_controller_unittest.cc
(OverscrollControllerTest.DelegateDeletesControllerOnComplete) that
specifically reproduces the conditions under which the UAF occurs. The
test configures the delegate to destroy the OverscrollController within
the OnOverscrollComplete callback. This test fails without the WeakPtr
fix when run under ASan and passes with the fix.

Bug: 459347936
Change-Id: Ieab001ffc628b3b2e5ab00d51800e186e5620605
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7156432
Commit-Queue: Aman Verma <[email protected]>
Reviewed-by: Jonathan Ross <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1546305}
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755600
Reviewed-by: Allan Sandfeld Jensen <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/322c8c14b26c9a469e1c13bf3f23ac81a25f41ee

Git commit 2b58222ca1e73e710a9278986a40c1b6890bd09d by Michael Brüning (on behalf of Bo Liu) on 28/07/2026 at 12:10..
[Backport] CVE-2026-16804: Use after free in Input

Manual cherry-pick of patch originally reviewed on
https://chromium-review.googlesource.com/c/chromium/src/+/8102902:
content: Post OnOverscrollComplete

To avoid reentrancy issues.

Fixed: 524721670
Change-Id: Ibb60766beba22d1cc64d29505cbeb1860b00dc5d
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8102902
Commit-Queue: Bo Liu <[email protected]>
Reviewed-by: Kartar Singh <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1664626}
Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755601
Reviewed-by: Allan Sandfeld Jensen <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/2b58222ca1e73e710a9278986a40c1b6890bd09d
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.