[qt/qt/qtwebengine-chromium]: Summary of bulk changes made
KDE Git Services - Bulk Change <[email protected]>
| Newsgroups | gmane.comp.kde.cvs |
|---|---|
| Message-ID | <[email protected]> |
Git repository change summary for qt/qt/qtwebengine-chromium Pushed by mirror-service into branch '140-based'. Changed from 1e2ffa9caf5466dda4228c0d30d943251614524b to 2b58222ca1e73e710a9278986a40c1b6890bd09d Acknowledgement was received that this change introduces only existing code that has been pushed to another public open source repository. This change contains the following new commits: Git commit e471cdc84f01050b0b384bb79c1d2d0bea13a595 by Michael Brüning on 28/07/2026 at 11:52.. [roll][libvpx] CVE-2026-13906: Out of bounds read in Codecs Update libvpx to the version used in Chromium 150.0.7871.115 to include the fix for CVE listed above and various other fixes. Roll src/third_party/libvpx/source/libvpx/ d5f35ac8d..5f0041366 (116 commits) https://chromium.googlesource.com/webm/libvpx.git/+log/d5f35ac8d..5f00413667d1 git log d5f35ac8d..5f0041366 --date=short --no-merges --format='%ad %ae %s' 2026-05-27 [email protected] Revert "Fix the use of uninitialized value in qsort" 2026-05-27 [email protected] vp9_encoder.c,qsort_comp: fix pointer cast 2026-05-25 [email protected] Disable usage of prev_mi_grid_visible under resize 2026-05-22 [email protected] vpx_dsp.mk: exclude highbd_sse_neon.c w/encoders disabled 2026-05-22 [email protected] include select vpx_sad functions in postproc build 2026-05-22 [email protected] vp9: Fix to perceptual_aq mode under resize. 2026-05-22 [email protected] Fix to arf/lastgolden usage buffers for realtime lag 2026-05-21 [email protected] vp9_postproc: disable VP9D_DEMACROBLOCK w/uv_width < 8 2026-05-20 [email protected] vp9_postproc: disable VP9D_DEBLOCK w/uv_width < 8 2026-05-20 [email protected] vp9_post_proc_frame: disable VP9D_ADDNOISE w/high-bitdepth 2026-05-19 [email protected] vp8-multi-res-encoding: Fix to out-of-bounds write 2026-05-19 [email protected] validate_img: add error msg for validate_hbd_input failure 2026-05-18 [email protected] vp9_cx_iface,validate_img: check plane ptr before reading 2026-04-29 [email protected] rtc-rc: Checks limts on inputs to external rc 2026-05-15 [email protected] vpx postproc: Fix to buffer overflow in vpx_setup_noise 2026-05-14 [email protected] vp9: Fix to mfqe for resize 2026-05-15 [email protected] Guard alpha plane access with condition 2026-05-13 [email protected] vp9-svc: Avoid write_superframe for empty superframe 2026-05-13 [email protected] vp9_cx_iface.c: fix signed/unsigned warning 2026-05-12 [email protected] Fix buffer overflow in set_mb_ssim_rdmult_scaling 2026-05-08 [email protected] configure: add arm64/win32 VS18 targets 2026-05-08 [email protected] Use g_bit_depth during input validation 2026-03-26 [email protected] Revert "Remove spinning before calling pthread_mutex_lock" 2026-05-07 [email protected] Replace NULL with nullptr in .cc files 2026-05-06 [email protected] Fix clang-tidy warnings in libvpx 2026-05-06 [email protected] vp9_int_pro_motion_estimation: fix stride w/scaled ref 2026-04-28 [email protected] vp9: fix to buffer overflow under resolution change 2026-04-30 [email protected] vpxenc: add --validate-hbd-input option 2026-04-30 [email protected] add test coverage for VP9E_SET_VALIDATE_HBD_INPUT 2026-05-01 [email protected] vp9-svc: Set consistent value for temporal_layering_mode 2026-04-30 [email protected] rename VP9E_SET_VALIDATE_INPUT_HBD -> VALIDATE_HBD_INPUT 2026-04-30 [email protected] vp9: wrap size check in #if INT64_MAX > SIZE_MAX 2026-04-30 [email protected] Cast tokens to size_t when allocating 2026-04-30 [email protected] vp9: replace heavy token alloc test with unit test 2026-04-28 [email protected] Fix VP9 float-to-int overflow in validate_config 2026-04-28 [email protected] Fix VP8 decoder crash on flush with no fragments 2026-04-27 [email protected] Fix overflow in get_token_alloc leading to OOM 2026-04-27 [email protected] Fix VP9 highbitdepth encoder format mismatch 2026-04-28 [email protected] Fix VP8 signed overflow in vp8_encode_frame 2026-04-27 [email protected] vp9: fix to negative quantizer with force_frame_boost 2026-04-28 [email protected] Fix VP9 float-to-int overflow with zero bitrate 2026-04-24 [email protected] vp9: Add unittest for svc issue: 505665613 2026-04-27 [email protected] vp8: Clamp vp8_set_static_threshold 2026-04-24 [email protected] vp9-svc: fix integer overflow in get layer resolution 2026-04-24 [email protected] vp9-svc: follow-up to disallow svc for 2pass 2026-04-23 [email protected] Add null checks to _set/get_reference for vp8/vp9. 2026-04-23 [email protected] vp9-svc: fix issue with svc.duration overflow 2026-04-23 [email protected] vp9-svc: Constrain per-layer speed to be >=5 for realtime build 2026-04-23 [email protected] vp9-svc: condition scale_references on use_nonrd_pick_mode 2026-04-23 [email protected] Check on baseline_gf_interval for gf_cbr_boost_pct 2026-04-22 [email protected] vp9-svc: Disallow svc for 2 pass encoding. 2026-04-22 [email protected] vp9-svc: range checks to the layer max/min_quantizers 2026-04-14 [email protected] vp9: fix to cyclic_refresh_setup with svc dynamic layers 2026-04-01 [email protected] LoongArch: Defer filter pointer retrieval to fix out-of-bounds 2026-04-14 [email protected] vpx_temporal_svc_encoder: remove unused global 2026-04-08 [email protected] decode_api_test.cc: fix visual studio warnings 2026-04-08 [email protected] vp8_de_alloc_frame_buffers: more cleanup 2026-04-08 [email protected] vp8_de_alloc_frame_buffers: clear mi/postproc_state 2026-04-07 [email protected] Change asm volatile to __asm__ __volatile__ 2026-04-06 [email protected] vp9_decodeframe.c: move ref frame index check earlier 2026-04-03 [email protected] Enable the ISO C11 standard 2026-04-02 [email protected] {vp9_cx_iface,vp9_decoder}.c: add some missing includes 2026-04-01 [email protected] vp9_decodeframe: promote row-mt calcs to size_t 2026-04-01 [email protected] test/android/Android.mk: build tests w/-std=c++17 2026-03-30 [email protected] vp9: fix for out-of-bounds write in decode coeffs 2026-03-31 [email protected] gen_msvs_vcxproj: set C++ language standard to C++17 2026-03-28 [email protected] Update to GoogleTest 1.17.0 2026-03-30 [email protected] vp9; move source input check to validate_img 2026-03-29 [email protected] Allow patch files to have trailing spaces 2026-03-27 [email protected] encoder_encode: Omit two res == VPX_CODEC_OK tests 2026-03-28 [email protected] Remove bit_depth member of struct TestSSEFuncs 2026-03-27 [email protected] README: update bug tracker link 2026-03-23 [email protected] vp9: Add check to validate source input 2026-03-23 [email protected] encode_api_test: replace kHeight w/kWidth for stride 2026-03-16 [email protected] vpx_image,img_alloc_helper: verify vpx_img_fmt_t 2026-03-14 [email protected] vp[89] encoders: reject unequal UV strides 2026-03-14 [email protected] vp9,encoder_encode: fix validate_img() check 2026-03-11 [email protected] encode_api_test: add repro for b/488585490 2026-03-08 [email protected] y4minput: fix integer overflow in buffer size calculations 2026-03-11 [email protected] y4minput.c: Set alpha plane to NULL, stride to 0 2026-03-10 [email protected] vp9-svc: validate spatial_layer_id 2026-03-02 [email protected] vp9_scale_references: fail if no free buffer is available 2026-03-02 [email protected] vp9_pick_inter_mode: fix buf offsets w/scaled refs 2026-02-26 [email protected] yuv_video_source: fix stride/width check w/16bpp 2026-02-24 [email protected] yuv_video_source: fix reading files w/odd widths 2026-02-24 [email protected] add support for msvc v145 / VS 2026 2026-02-23 [email protected] encode_api_test: disable OssFuzz471723682 2026-02-18 [email protected] vpx_enc_fuzzer: condition max frames on deadline 2026-02-19 [email protected] Make direct calls to Neon variance paths in Neon subpel variance 2026-02-19 [email protected] Add Armv8.4 Neon DotProd subpel variance paths 2026-02-19 [email protected] Remove Armv8.4 Neon DotProd 4x4 variance kernel 2026-02-18 [email protected] vp8,calc_pframe_target_size: fix integer overflow 2026-02-18 [email protected] examples/*.c: fix incorrect die_codec() usage 2026-02-17 [email protected] **README.libvpx: add missing fields / sync w/libaom 2026-02-12 [email protected] vp8_decode_frame: improve header / partition 0 check 2026-02-13 [email protected] rtcd.pl: use a fixed year for *rtcd.h Copyright 2026-02-12 [email protected] vp8_decode_frame: validate partition 0 size 2026-02-10 [email protected] vpx_enc_fuzzer: limit number of encoded frames 2026-02-09 [email protected] Revert "Increase alignment for wider SIMD optimization" 2026-02-09 [email protected] Revert "vpxdsp: [x86] AVX2 and AVX512 for tm intra predictor" 2026-02-02 [email protected] vpxdsp: [x86] small tweak to vpx_highbd_tm_predictor_4x4_sse2 2026-01-22 [email protected] vpxdsp: [x86] AVX2 and AVX512 for tm intra predictor 2026-01-23 [email protected] Increase alignment for wider SIMD optimization 2026-02-04 [email protected] vpx_enc_fuzzer: add missing break statements 2026-02-03 [email protected] Test for ioc: use more general rounding 2026-01-28 [email protected] builtin_assume range of token values 2026-02-02 [email protected] Test that tokens are within range 2026-02-02 [email protected] Also builtin_assume value of ctx_cur 2026-02-02 [email protected] cleanup: remove unnecessary copy of ctx 2026-01-22 [email protected] Avoid ioc in intermediate step 2026-01-28 [email protected] builtin_assume energy values are within bounds 2026-01-28 [email protected] Add test for maximum value of vp9_pt_energy_class 2026-01-22 [email protected] __builtin_assume that scan values are in range 2026-01-08 [email protected] configure: add --disable-x86-asm 2026-01-17 [email protected] vpxdsp [x86]: AVX2 for 16x16 high bd d207 and d63 intra pred 2026-01-23 [email protected] vp8: fix use_dc_pred condition in mb_activity_measure 2026-01-22 [email protected] Add test that all scan values are <= MAX_SCAN_VALUE Change-Id: I8a8a4a355b50d491f1d173560976aed94716b879 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/753884 Reviewed-by: Michal Klocek <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/e471cdc84f01050b0b384bb79c1d2d0bea13a595 Git commit 792aed16529eacb8664e9161e2486bc2fe419cc3 by Michal Klocek on 28/07/2026 at 11:55.. [roll][harfbuz] CVE-2026-13938: Integer overflow in Fonts Roll harfbuzz to version 14.2.0-69 (d639197e) from Chromium 150.0.7871.150. Changes to build itsef are done in follw up commit. Task-number: QTBUG-147901 Change-Id: I20b39bd063b851734a5db00b398a0661853ed5ad Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754704 Reviewed-by: Allan Sandfeld Jensen <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/792aed16529eacb8664e9161e2486bc2fe419cc3 Git commit deca52af2f803b40a45072147f7b64405a59b017 by Michal Klocek on 28/07/2026 at 11:56.. [rust][harfbuzz][qt3rdparty] Build harfbuzz without rust This is just 140-based fix, as later harfbuzz-ng becomes harfbuzz and those files need fixup. Disable build with rust as harfrust dependencies are not in current source tree. Change-Id: I7ce3b9f74356e1af25515eeca70abf1fe94d53d4 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754705 Reviewed-by: Allan Sandfeld Jensen <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/deca52af2f803b40a45072147f7b64405a59b017 Git commit 1edd2430c007b4adaabc9d291f09277ae25697ab by Michal Klocek (on behalf of Eugene Zemtsov) on 28/07/2026 at 11:56.. [backport] CVE-2026-13958: Uninitialized Use in Codecs media: Fix buffer leak in MFAudioEncoder MFAudioEncoder appended new buffers to the output sample without removing old ones when the required output size increased. This caused unbounded memory growth. Fixed by calling `RemoveAllBuffers()` before adding a new buffer. Bug: 513567306 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7851728 Task-number: QTBUG-147902 Change-Id: I3df6c4665111c210a3930bb69155c723074078fb Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754889 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/1edd2430c007b4adaabc9d291f09277ae25697ab Git commit 3adedb764b842f4d9a9b40f2f0b1207b5d0f352d by Michal Klocek (on behalf of David Baron) on 28/07/2026 at 11:56.. [backport] CVE-2026-13959: Insufficient validation of untrusted input in Blink Limit TouchEvent/WheelEvent messages about preventDefault to trusted events. Fixed: 513609249 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7853179 Task-number: QTBUG-147902 Change-Id: I2c7e37260de6943b41ea5f56c16f5207e21dded0 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754890 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/3adedb764b842f4d9a9b40f2f0b1207b5d0f352d Git commit 2847fd1588d896d3b530ff4d7471df70ff997afa by Michal Klocek (on behalf of Wolfgang Beyer) on 28/07/2026 at 11:56.. [backport] CVE-2026-13961: Insufficient validation of untrusted input in DevTools Verify workspace path is local and does not reference parent Fixed: 513719481 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7876392 Task-number: QTBUG-147902 Change-Id: I20aa1e2cb38ffdcc087f6ad95fb79ed8583edd65 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754891 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/2847fd1588d896d3b530ff4d7471df70ff997afa Git commit 485825e2207f08b3c772b7d60814e6f66379b511 by Michal Klocek (on behalf of Michael Lippautz) on 28/07/2026 at 11:56.. [backport] CVE-2026-13965: Use after free in Oilpan heap: Make range-based write barrier more robust Fix bailouts on the barrier for possible nullptr cases. CONV=47326a54-47d2-449d-b308-f51eb6b5b3b8 TAG=AGY Fixed: 513737952 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7852268 Task-number: QTBUG-147902 Change-Id: Iaa8598bc06a1782f77af7a3ea02359d918673688 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754892 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/485825e2207f08b3c772b7d60814e6f66379b511 Git commit af38fb93d93746f466981ab1b2831bfed975b966 by Michal Klocek (on behalf of Marc Treib) on 28/07/2026 at 11:56.. [backport] CVE-2026-13966: Inappropriate implementation in History History: Don't consider IP literals for "typed" promotion The history component automatically promotes intranet hosts (like "http://myhost") to a "TYPED" transition type, so that the omnibox will recognize the known host in the future. Before this CL, IP literals were also detected as "intranet hosts" and so the same promotion logic would (accidentally) apply to them. This CL fixes this by excluding IP literals from IsUntypedIntranetHost(). Fixed: 513741393 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7864242 Task-number: QTBUG-147902 Change-Id: Ia52da2625c3da177fc35e119e3e5b54c6a6a6964 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754893 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/af38fb93d93746f466981ab1b2831bfed975b966 Git commit 0fd818b5beef15e29fa29952870a94f45007f427 by Michal Klocek (on behalf of Alina Varkki) on 28/07/2026 at 11:56.. [backport] CVE-2026-13969: Uninitialized Use in UI Fix prototype pollution in trace FramesHandler using Map Migrate mapFrames to a built-in Map class to prevent attacker-controlled trace frame keys from interacting with or mutating Object.prototype. Bug: 513762145 Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/7864400 Task-number: QTBUG-147902 Change-Id: I35f1091349a956d2bcad99a2292c2b695302854f Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754894 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/0fd818b5beef15e29fa29952870a94f45007f427 Git commit bab060fe568a9502d54314f9bb8a8efb206cc2cd by Michal Klocek (on behalf of Thomas Guilbert) on 28/07/2026 at 11:56.. [backport] CVE-2026-13970: Uninitialized Use in Media Fix IncreaseCapacity when FIFO is full This CL fixes an edge case in `IncreaseCapacity()` which is only reached when the FIFO is full. At full capacity, the read and write indices are identical. After rotating the new blocks, the write index is correctly pointing to the newly inserted blocks, and should not be updated. Bug: 513779283 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7866205 Task-number: QTBUG-147902 Change-Id: I96199d193e7e8c704f64168a1567bcb3caca14c7 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754895 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/bab060fe568a9502d54314f9bb8a8efb206cc2cd Git commit 2dca730dde0afecfecac4266bfeabb9ebc34688c by Michal Klocek (on behalf of Kaylee Lubick) on 28/07/2026 at 11:56.. [backport] CVE-2026-13971: Uninitialized Use in Skia Address potential MSAN issue in SkScalerContext If malformed data was passed to SkStrikeClient, an unexpected mask would pass through asserts in a release build and lead to a mask being allocated that was 4x bigger than what was written to. To defend against this problem, we 1) reject masks that aren't of the three formats SkScalerContext::GenerateImageFromPath expects; 2) zero out the whole mask, regardless of how big it is instead of relying on how big an A8 mask would be. Additionally, I noticed that in the intermediateDst case (e.g. for LCD text when we draw into an A8 and then later unpack it to be LCD16) we weren't zeroing that intermediate buffer which could be a problem if the glyph itself was small (but the bounds were corrupted to be big). Thus, we zero that intermediate A8 buffer too. Bug: 513780208 Fixed: 513780208 Reviewed-on: https://skia-review.googlesource.com/c/skia/+/1248536 Task-number: QTBUG-147902 Change-Id: Ib7080fc45eb77ea19b3e733570da33cd339a51f8 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754896 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/2dca730dde0afecfecac4266bfeabb9ebc34688c Git commit 56a9164d4318c5056b735fe0e3c828ed3d66de23 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 11:57.. [backport] CVE-2026-13972: Inappropriate implementation in Paint Fix occlusion by not overwriting z_offset for overflow controls https://crrev.com/1489781 introduced an intersection observer v2 regression due to overwriting z_offset when calculating overflow control hit testing. This patch fixes this by using `IsHitCandidateForDepthOrder` instead of an unconditional write. Fixed: 513792140 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7854801 Task-number: QTBUG-147902 Change-Id: Ie970f24104dfa8e14e6d4bd6c67880048c9a0209 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754897 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/56a9164d4318c5056b735fe0e3c828ed3d66de23 Git commit 632f89bd763923e3569a961a9829040d88498c8d by Michal Klocek (on behalf of Le Hoang Quyen) on 28/07/2026 at 11:57.. [backport] CVE-2026-13975: Out of bounds read in ANGLE Metal: Fix baseVertex type in RenderCommandEncoder Change baseVertex type from uint32_t to int32_t in drawIndexedInstancedBaseVertexBaseInstance to correctly support negative values. Also fix the stream fetch to use int32_t. Added a regression test NegativeBaseVertex. Even before this change, the sign mismatch bug didn't seem to affect the test results, possibly because the Metal driver performs the computation in 32 bits. Bug: chromium:513857658 Reviewed-on: https://chromium-review.googlesource.com/c/angle/angle/+/7859153 Task-number: QTBUG-147902 Change-Id: I351ba1f3a5f84545ab6944686a091dad24b636ba Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/754898 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/632f89bd763923e3569a961a9829040d88498c8d Git commit b394f282083ce3f27007ab2d83c73d461c62a01b by Michal Klocek (on behalf of David Baron) on 28/07/2026 at 12:00.. [backport] CVE-2026-13977: Inappropriate implementation in HTMLParser Fix fragment parsing inside <mathml:annotation-xml> elements. Fixed: 513859894 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7863551 Task-number: QTBUG-147903 Change-Id: I413d5b1fdb61f60e38ca77d25a8b463c630f003e Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755197 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/b394f282083ce3f27007ab2d83c73d461c62a01b Git commit 657f69de7de5ef14549d634c3e8b069b53a4d2c8 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:00.. [backport] CVE-2026-13979: Inappropriate implementation in Paint (1/5) Avoid no-op filter invalidations with multiple filters crrev.com/1588040 updated reference filter equality to check for filter_ changes. If there are multiple filters though, `SVGElementResourceClient::UpdateFilterData` will always re-create the filter, causing an unnecessary invalidation. This patch avoids filter_ changes if the reference filters are unchanged. Bug: 513988889 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7872260 Task-number: QTBUG-147903 Change-Id: I16d7eff9bc3a9431cf2e28fbae4d49e189f95fd9 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755198 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/657f69de7de5ef14549d634c3e8b069b53a4d2c8 Git commit a1990e18097f5c1868f72052a560d5dc350ac710 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:00.. [backport] CVE-2026-13979: Inappropriate implementation in Paint (2/5) Fix reference filter rect mapping with a single filter UpdateFilterData now sets the built Filter on ReferenceFilterOperation in the "is_single_reference_filter" codepath, matching what is already done in the non-single-reference codepath. This enables FilterOperations::MapRect to properly map reference filter rects. Bug: 513988889 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7871868 Task-number: QTBUG-147903 Change-Id: Icddcf21bd4607ddbcd1364325886bf2bc5ed7dc5 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755199 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/a1990e18097f5c1868f72052a560d5dc350ac710 Git commit 5f8eb8912d678af9b13fb6016b35b5a2417bd7aa by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:00.. [backport] CVE-2026-13979: Inappropriate implementation in Paint (3/5) Include filters in SVG occlusion tests When performing hit tests for occlusion (i.e., intersection observer v2), we need to include filter effects. This patch updates the SVG hit testing code to inflate the visual overflow with filters, and use this for occlusion hit tests. Fixed: 513988889 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7858119 Task-number: QTBUG-147903 Change-Id: Ib2cad21105fd829d0cd744a698907fe6dd999a3c Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755200 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/5f8eb8912d678af9b13fb6016b35b5a2417bd7aa Git commit 7e8099eb30be5b414b0662d15fc7402be6011a93 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:00.. [backport] CVE-2026-13979: Inappropriate implementation in Paint (4/5) Unify ApplyFiltersToRect in SVGLayoutSupport and LayoutBoxModelObject This patch updates `LayoutBoxModelObject::ApplyFiltersToRect` to call `SVGLayoutSupport::ApplyFiltersToRect`. The call to IsZero has been removed as there are no cases in practice where a reference box would be zero sized and at a different location from the input rect, since the reference box and input rect are derived from the object's size. `MapToSVGRootIncludingFilter` is missing the reference box expansion and would also benefit from `SVGLayoutSupport::ApplyFiltersToRect`, so a TODO has been added to do that. Bug: 513988889 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7876061 Task-number: QTBUG-147903 Change-Id: I7eadaf135744c023ca61d74a0776cf50f642185e Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755201 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/7e8099eb30be5b414b0662d15fc7402be6011a93 Git commit de3e6fe90d665aa743662499a3b43031adc2f434 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:00.. [backport] CVE-2026-13979: Inappropriate implementation in Paint (5/5) Use SVGLayoutSupport::ApplyFiltersToRect in MapToSVGRootIncludingFilter This patch updates `MapToSVGRootIncludingFilter` to use `SVGLayoutSupport::ApplyFiltersToRect` which contains some additional code to inflate by the reference box, fixing a bug. Bug: 513988889 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7875520 Task-number: QTBUG-147903 Change-Id: Ia1d32911bd4f18584930baf4250a4bd356c171d6 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755202 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/de3e6fe90d665aa743662499a3b43031adc2f434 Git commit 025760ed953a1584be443f8c1efe652c428a5775 by Michal Klocek (on behalf of Ian Kilpatrick) on 28/07/2026 at 12:00.. [backport] Dependency for CVE-2026-13988 Remove {LayoutBlock,LayoutBlockFlow}::HitTestChildren LayoutBlock overrides NodeAtPoint - without callings its super-class method LayoutBox::NodeAtPoint. HitTestChildren is only used within LayoutBox::NodeAtPoint, and therefore the LayoutBlock::HitTestChildren, and LayoutBlockFlow::HitTestChildren logic was unreachable. Remove these override, and additionally shift LayoutBox::NodeAtPoint down to LayoutReplaced::NodeAtPoint as this is where it is actually used. There should be no behaviour change. Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7426176 Task-number: QTBUG-147903 Change-Id: I01d075bea96f651489b9c3809a10973a75a1825b Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755241 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/025760ed953a1584be443f8c1efe652c428a5775 Git commit efe2791ac58209b2abcd331e752ccc4ebb8d5db5 by Michal Klocek (on behalf of Philip Rogers) on 28/07/2026 at 12:01.. [backport] CVE-2026-13988: Inappropriate implementation in Paint Fix border-radius hit testing for visual overflow When hit testing visual overflow, we cannot stop hit testing once a hit is outside the border because effects like box-shadow can still be present. Fixed: 514040614 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7858611 Taks-number: QTBUG-147903 Change-Id: I4c0daacbb659966a4088277a1ef9f8ab5e75f5fb Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755242 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/efe2791ac58209b2abcd331e752ccc4ebb8d5db5 Git commit 25fdf60d0cb195f234e6af81309f84b9a63a3a4e by Michal Klocek (on behalf of Bryan Oltman) on 28/07/2026 at 12:01.. [backport] CVE-2026-13992: Inappropriate implementation in UI Drop redispatched events if window is no longer key When an unhandled renderer event is returned for system processing, the CommandDispatcher redispatches it. If the window has lost its "key" status (e.g., due to a focus change while the event was in-flight), redispatching it can cause the event to be incorrectly handled by the newly focused window. This CL ensures that we only redispatch events if the target window is still the key window. Fixed: 514063409 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7864509 Task-number: QTBUG-147903 Change-Id: I022d7f45d5c35d26a96b4efc55c0621eb73b3a80 Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755593 Reviewed-by: Michael Brüning <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/25fdf60d0cb195f234e6af81309f84b9a63a3a4e Git commit 6c7949fb4e966c402211ba6b53cdec6a6da79429 by Michael Brüning (on behalf of Alexander Cooper) on 28/07/2026 at 12:09.. [Backport] CVE-2026-13910: Insufficient policy enforcement in WebXR Cherry-pick of patch originally reviewed on https://chromium-review.googlesource.com/c/chromium/src/+/7837042: Improve input suppression for cross-origin DOM Overlay Modify the DOM Overlay hit testing logic to correctly identify and suppress input events when they intersect cross-origin frames. Specifically, we now use the frame element's content frame directly instead of checking for the content document. This allows properly recognizing and handling Out-of-Process Iframes (RemoteFrames) which do not have a local content document. Additionally, we compare the hit frame's security origin against the origin of the WebXR session's execution context, rather than comparing against the outermost main frame. This correctly handles cases where the XR session itself is running in an embedded subframe. Fixed: 507231605 Change-Id: Ie4d5291c36f86c16d5cd8f78fc0a08a1ce783096 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7837042 Reviewed-by: Daniel Cheng <[email protected]> Auto-Submit: Alexander Cooper <[email protected]> Commit-Queue: Alexander Cooper <[email protected]> Cr-Commit-Position: refs/heads/main@{#1628794} Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755518 Reviewed-by: Allan Sandfeld Jensen <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/6c7949fb4e966c402211ba6b53cdec6a6da79429 Git commit e48489ddd8c15be7b00b1cf05421053f59611a54 by Michael Brüning (on behalf of Eden Wang) on 28/07/2026 at 12:10.. [Backport] Dependency for CVE-2026-15107 Manual cherry-pick of patch originally reviewed on https://chromium-review.googlesource.com/c/chromium/src/+/6965169: Fix lifetime issue in InspectorIndexedDBAgent during navigation This change improves the lifetime management of objects involved in asynchronous IndexedDB DevTools operations. Previously, objects handling async callbacks could outlive the DevTools session they depended on, particularly during a page navigation. This could lead to instability. The fix introduces weak pointers to safely manage the relationship between the callback handlers and the agent. This ensures that callbacks can detect when the session has been destroyed and abort gracefully instead of accessing invalid state. Bug: 446423320 Change-Id: Iec5355c44d27d496eb7274da69ddaf32be9cdfb6 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6965169 Reviewed-by: Philip Pfaffe <[email protected]> Auto-Submit: Wang Neden <[email protected]> Commit-Queue: Philip Pfaffe <[email protected]> Reviewed-by: Alex Rudenko <[email protected]> Cr-Commit-Position: refs/heads/main@{#1518646} Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755589 Reviewed-by: Allan Sandfeld Jensen <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/e48489ddd8c15be7b00b1cf05421053f59611a54 Git commit e10fb4922bb701ac82b9642a584b8226bda3a399 by Michael Brüning (on behalf of Steve Becker) on 28/07/2026 at 12:10.. [Backport] CVE-2026-15107: Use after free in IndexedDB Manual cherry-pick of patch originally reviewed on https://chromium-review.googlesource.com/c/chromium/src/+/8007837: InspectorIndexedDBAgent must not use v8_session_ after disposal `v8_session_` is a `raw_ptr` member of `InspectorIndexedDBAgent`. To prevent use after frees, this fix updates `InspectorIndexedDBAgent::Dispose()` to set `v8_session_` to `nullptr`. The change then adds null checks before each use of `v8_session_`. `nullptr`. This fix follows the same pattern as `InspectorDOMAgent`: https://source.chromium.org/chromium/chromium/src/+/main:third_party/blink/renderer/core/inspector/inspector_dom_agent.cc;drc=284b36ac2742525000db2ca28f448f6cc8584f40;l=3416 The change adds a test that repros 100% on ASAN builds. Bug: 503553615 Change-Id: Ifa540fb83556710d197ed4b3c942ab61c37de35b Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8007837 Reviewed-by: Philip Pfaffe <[email protected]> Commit-Queue: Steve Becker <[email protected]> Cr-Commit-Position: refs/heads/main@{#1653288} Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755590 Reviewed-by: Allan Sandfeld Jensen <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/e10fb4922bb701ac82b9642a584b8226bda3a399 Git commit 0800b99019b11be8b57bd46691927fda283c92e0 by Michael Brüning (on behalf of Hirokazu Honda) on 28/07/2026 at 12:10.. [Backport] CVE-2026-16807: Out of bounds write in Codecs Cherry-pick of patch originally reviewed on https://chromium-review.googlesource.com/c/chromium/src/+/7939189: media/gpu/v4l2: Verify chroma and detect bit depth changes This CL updates the V4L2 stateless video decoder to reject streams with chroma subsampling other than 4:2:0, which are unsupported. It also introduces bit depth tracking. Previously, changes in bit depth that did not accompany a resolution change were ignored. Now, a change in bit depth correctly triggers the resolution change workflow so that buffers can be reallocated with the appropriate format. Bug: 518237034 Test: video.ChromeStackDecoder.* Change-Id: I3c55372ec3a454b208215626b3962b14f71230d6 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7939189 Commit-Queue: Hirokazu Honda <[email protected]> Reviewed-by: Nathan Hebert <[email protected]> Auto-Submit: Hirokazu Honda <[email protected]> Cr-Commit-Position: refs/heads/main@{#1647107} Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755598 Reviewed-by: Allan Sandfeld Jensen <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/0800b99019b11be8b57bd46691927fda283c92e0 Git commit 12ab59be7fba04c2d9dc8e46e11c6123d07def74 by Michael Brüning (on behalf of Koji Ishii) on 28/07/2026 at 12:10.. [Backport] CVE-2026-16805: Use after free in Blink Manual cherry-pick of patch originally reviewed on https://chromium-review.googlesource.com/c/chromium/src/+/8106916: Add validity checks after `CompositionRange()` Following up crrev.com/c/7840643, this patch adds validity checks after calls to `CompositionRange()`, which invokes `Document::UpdateStyleAndLayout()`. Also change `FrameSelection::RootEditableElementOrDocumentElement()` to return `nullptr` when the selection is no longer available after the layout it forces, instead of dereferencing a cleared `document_`. Bug: 523292588 Change-Id: I4a82a3b57fb00137dd45be946fd8e045ed46be2f Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8106916 Reviewed-by: Dave Tapuska <[email protected]> Auto-Submit: Koji Ishii <[email protected]> Commit-Queue: Dave Tapuska <[email protected]> Cr-Commit-Position: refs/heads/main@{#1663857} Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755599 Reviewed-by: Allan Sandfeld Jensen <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/12ab59be7fba04c2d9dc8e46e11c6123d07def74 Git commit 322c8c14b26c9a469e1c13bf3f23ac81a25f41ee by Michael Brüning (on behalf of Aman Verma) on 28/07/2026 at 12:10.. [Backport] Security bug 459347936 / Dependency for CVE-2026-16804 Cherry-pick of patch originally reviewed on https://chromium-review.googlesource.com/c/chromium/src/+/7156432: Fix UAF in OverscrollController::CompleteAction This patch fixes a use-after-free vulnerability in OverscrollController. The `delegate_->OnOverscrollComplete()` call can potentially lead to the destruction of the `OverscrollController` instance, for example, when the delegate initiates a navigation. If this happens, the subsequent call to `Reset()` on the now-deleted `this` pointer causes a crash. To prevent this, this change introduces a `base::WeakPtrFactory` and checks the validity of the weak pointer after the delegate call. If the instance has been destroyed, the function now returns early, avoiding the UAF. This patch also adds a unit test to overscroll_controller_unittest.cc (OverscrollControllerTest.DelegateDeletesControllerOnComplete) that specifically reproduces the conditions under which the UAF occurs. The test configures the delegate to destroy the OverscrollController within the OnOverscrollComplete callback. This test fails without the WeakPtr fix when run under ASan and passes with the fix. Bug: 459347936 Change-Id: Ieab001ffc628b3b2e5ab00d51800e186e5620605 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7156432 Commit-Queue: Aman Verma <[email protected]> Reviewed-by: Jonathan Ross <[email protected]> Cr-Commit-Position: refs/heads/main@{#1546305} Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755600 Reviewed-by: Allan Sandfeld Jensen <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/322c8c14b26c9a469e1c13bf3f23ac81a25f41ee Git commit 2b58222ca1e73e710a9278986a40c1b6890bd09d by Michael Brüning (on behalf of Bo Liu) on 28/07/2026 at 12:10.. [Backport] CVE-2026-16804: Use after free in Input Manual cherry-pick of patch originally reviewed on https://chromium-review.googlesource.com/c/chromium/src/+/8102902: content: Post OnOverscrollComplete To avoid reentrancy issues. Fixed: 524721670 Change-Id: Ibb60766beba22d1cc64d29505cbeb1860b00dc5d Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8102902 Commit-Queue: Bo Liu <[email protected]> Reviewed-by: Kartar Singh <[email protected]> Cr-Commit-Position: refs/heads/main@{#1664626} Reviewed-on: https://codereview.qt-project.org/c/qt/qtwebengine-chromium/+/755601 Reviewed-by: Allan Sandfeld Jensen <[email protected]> https://invent.kde.org/qt/qt/qtwebengine-chromium/-/commit/2b58222ca1e73e710a9278986a40c1b6890bd09d