[qt/qt/qtwebengine]: Summary of bulk changes made

KDE Git Services - Bulk Change <[email protected]>
Newsgroups gmane.comp.kde.cvs
Message-ID <[email protected]>
Git repository change summary for qt/qt/qtwebengine
Pushed by mirror-service into branch '6.11'.
Changed from c6156aca57513577b06ffc102d343e035305890a to 4b24c0369946b9551c091e56be72e263b76b5c4f
Acknowledgement was received that this change introduces only existing code that has been pushed to another public open source repository.

This change contains the following new commits:

Git commit 6f88d53cf386e1baffb1c07576fdbca8d5a5391e by Qt Cherry-pick Bot (on behalf of Michal Klocek) on 30/07/2026 at 18:12..
Update Chromium

Submodule src/3rdparty 1e2ffa9c..2b58222c:
* [Backport] CVE-2026-16804: Use after free in Input
* [Backport] Security bug 459347936 / Dependency for CVE-2026-16804
* [Backport] CVE-2026-16805: Use after free in Blink
* [Backport] CVE-2026-16807: Out of bounds write in Codecs
* [Backport] CVE-2026-15107: Use after free in IndexedDB
* [Backport] Dependency for CVE-2026-15107
* [Backport] CVE-2026-13910: Insufficient policy enforcement in WebXR
* [backport] CVE-2026-13992: Inappropriate implementation in UI
* [backport] CVE-2026-13988: Inappropriate implementation in Paint
* [backport] Dependency for CVE-2026-13988
* [backport] CVE-2026-13979: Inappropriate implementation in Paint (5/5)
* [backport] CVE-2026-13979: Inappropriate implementation in Paint (4/5)
* [backport] CVE-2026-13979: Inappropriate implementation in Paint (3/5)
* [backport] CVE-2026-13979: Inappropriate implementation in Paint (2/5)
* [backport] CVE-2026-13979: Inappropriate implementation in Paint (1/5)
* [backport] CVE-2026-13977: Inappropriate implementation in HTMLParser
* [backport] CVE-2026-13975: Out of bounds read in ANGLE
* [backport] CVE-2026-13972: Inappropriate implementation in Paint
* [backport] CVE-2026-13971: Uninitialized Use in Skia
* [backport] CVE-2026-13970: Uninitialized Use in Media
* [backport] CVE-2026-13969: Uninitialized Use in UI
* [backport] CVE-2026-13966: Inappropriate implementation in History
* [backport] CVE-2026-13965: Use after free in Oilpan
* [backport] CVE-2026-13961: Insufficient validation of untrusted input in DevTools
* [backport] CVE-2026-13959: Insufficient validation of untrusted input in Blink
* [backport] CVE-2026-13958: Uninitialized Use in Codecs
* [rust][harfbuzz][qt3rdparty] Build harfbuzz without rust
* [roll][harfbuz] CVE-2026-13938: Integer overflow in Fonts
* [roll][libvpx] CVE-2026-13906: Out of bounds read in Codecs

Change-Id: If855211f468238b1178c4fbc4b0c882c8a2f2b50
Reviewed-by: Moss Heim <[email protected]>
(cherry picked from commit 7f476f59cf5d00a3b47b52331b37f99d52b616b7)
Reviewed-by: Qt Cherry-pick Bot <[email protected]>
(cherry picked from commit c9b5c6a93c738a629f3ed152083bbe8c378d3944)
https://invent.kde.org/qt/qt/qtwebengine/-/commit/6f88d53cf386e1baffb1c07576fdbca8d5a5391e

Git commit 4b24c0369946b9551c091e56be72e263b76b5c4f by Qt Cherry-pick Bot (on behalf of Michal Klocek) on 30/07/2026 at 18:12..
Update Chromium

Submodule src/3rdparty 2b58222c..ba7ac37c:
* [fixup][rust][harfbuzz] Build harfbuzz without rust
* [fixup] [Backport] CVE-2026-14421: Uninitialized Use in Dawn
* [Backport] CVE-2026-14032: Use after free in Bluetooth
* [Backport] CVE-2026-14025: Use after free in Views
* [Backport] CVE-2026-16424: Use after free in GPU
* [Backport] CVE-2026-16423: Use after free in UI
* [Backport] CVE-2026-16422: Insufficient validation of untrusted input in Certificate
* [Backport] CVE-2026-16419: Out of bounds read and write in ANGLE
* [Backport] CVE-2026-16418: Stack buffer overflow in V8
* [Backport] CVE-2026-16417: Uninitialized Use in Skia
* [Backport] CVE-2026-16413: Out of bounds write in ANGLE
* [Backport] CVE-2026-16420/CVE-2026-16421: Type Confusion in WebAudio/Inappropriate Implementation in WebAudio
* Look for system installed sandbox launcher
* [Backport] CVE-2026-15133: Use after free in InterestGroups
* [Backport] CVE-2026-11673: Use after free in InterestGroups
* [Backport] CVE-2026-14421: Uninitialized Use in Dawn
* [Backport] CVE-2026-14408: Uninitialized Use in Dawn
* [Backport] CVE-2026-11266: Policy bypass in SafeBrowsing
* [fixup][3rdparty] Unbundle Linux system libraries for GN

Change-Id: Ic4f42b914a6a884ae5205f0c2728b69bf05a57b4
Reviewed-by: Moss Heim <[email protected]>
(cherry picked from commit fb532afe3c409fe08adc4359cc321e1544ed643d)
Reviewed-by: Qt Cherry-pick Bot <[email protected]>
(cherry picked from commit f07dde736c9c5c9a110e8714dbdc38696381d442)
https://invent.kde.org/qt/qt/qtwebengine/-/commit/4b24c0369946b9551c091e56be72e263b76b5c4f
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.