[qt/qt/qtwebengine]: Summary of bulk changes made

KDE Git Services - Bulk Change <[email protected]>
Newsgroups gmane.comp.kde.cvs
Message-ID <[email protected]>
Git repository change summary for qt/qt/qtwebengine
Pushed by mirror-service into branch '6.11'.
Changed from 88d557f47c15a5266a006e1ef5c7e3d59991aab1 to f573c0c1bccc3f674ae7ed95ea0d6fbbe4e5f573
Acknowledgement was received that this change introduces only existing code that has been pushed to another public open source repository.

This change contains the following new commits:

Git commit 5c68941fdeb466817dafdc28812fd6fd90e457cd by Qt Cherry-pick Bot (on behalf of Michal Klocek) on 04/08/2026 at 21:18..
Update Chromium

Submodule src/3rdparty ba7ac37c..35fc3dc4:
* [backport][parts] CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI
* [backport] CVE-2026-14022: Insufficient validation of untrusted input in Network
* [backport] CVE-2026-14020: Insufficient validation of untrusted input in WebXR
* [backport] CVE-2026-14017: Inappropriate implementation in Navigation
* [backport] CVE-2026-14015: Inappropriate implementation in WebRTC
* [backport] CVE-2026-14013: Inappropriate implementation in SVG
* [backport] CVE-2026-14012: Side-channel information leakage in CSS
* [backport] CVE-2026-14011: Out of bounds read in SurfaceCapture
* [backport] CVE-2026-14010: Uninitialized Use in Codecs
* [backport] CVE-2026-14009: Insufficient data validation in Passwords
* [backport] CVE-2026-14008: Uninitialized Use in WebXR
* [backport] CVE-2026-14006: Use after free in Navigation
* [backport] CVE-2026-14003: Insufficient policy enforcement in Extensions
* [backport] CVE-2026-14001: Inappropriate implementation in Network
* [backport] CVE-2026-13999: Inappropriate implementation in Extensions
* [backport] CVE-2026-13998: Incorrect security UI in File Input
* [Backport] CVE-2026-14040: Use after free in BrowserTag
* [Backport] Dependency for CVE-2026-14040
* [Backport] CVE-2026-14039: Insufficient policy enforcement in GetUserMedia
* [Backport] CVE-2026-14037: Insufficient policy enforcement in GPU
* [Backport] CVE-2026-14036: Insufficient policy enforcement in Bluetooth
* [Backport] CVE-2026-14035: Insufficient policy enforcement in Bluetooth
* [Backport] CVE-2026-14034: Inappropriate implementation in WebXR
* [Backport] CVE-2026-14432: Use after free in V8
* [Backport] CVE-2026-13922: Side-channel information leakage in Paint
* [fixup][msvc] Fix QtWebEngine build on Windows
* [ohos][qtpdf] Support OHOS build for QtPdf

Change-Id: I4f20ff93385d3ddf24625e7be4e85e5c113a7ac8
Reviewed-by: Kaloyan Chehlarski <[email protected]>
(cherry picked from commit d884689bb1693b1700e2cd0bd7207418933c8273)
Reviewed-by: Qt Cherry-pick Bot <[email protected]>
(cherry picked from commit 7db3fc15393ae2887eee2dc157aa9eb2350584f4)
https://invent.kde.org/qt/qt/qtwebengine/-/commit/5c68941fdeb466817dafdc28812fd6fd90e457cd

Git commit 7b983b3872bc87ab9648c9d1460950a5d0a52fb5 by Qt Cherry-pick Bot (on behalf of Michal Klocek) on 04/08/2026 at 21:18..
Update Chromium

Submodule src/3rdparty 35fc3dc4..cbf4306f:
* [Backport] Dependency for CVE-2026-17665
* [Backport] CVE-2026-13935: Side-channel information leakage in ComputePressure (3/3)
* [Backport] CVE-2026-13935: Side-channel information leakage in ComputePressure (2/3)
* [Backport] CVE-2026-13935: Side-channel information leakage in ComputePressure (1/3)
* [Backport] CVE-2026-13934: Insufficient validation of untrusted input in Dawn
* [Backport] CVE-2026-13931: Inappropriate implementation in Media
* [Backport] CVE-2026-13925: Inappropriate implementation in Downloads
* [Backport] CVE-2026-13923: Uninitialized Use in GPU
* [Backport] CVE-2026-17721: Out of bounds write in ANGLE
* [Backport] CVE-2026-17718: Use after free in ANGLE
* [Backport] CVE-2026-17713: Insufficient validation of untrusted input in Accessibility
* [Backport] CVE-2026-17710: Inappropriate implementation in MHTML
* [Backport] CVE-2026-17709: Race in Downloads
* [Backport] CVE-2026-17704: Use after free in ANGLE
* [Backport] CVE-2026-17702: Inappropriate implementation in Skia
* [Backport] CVE-2026-17701: Out of bounds read in ANGLE
* [Backport] CVE-2026-17695: Inappropriate implementation in ANGLE
* [Backport] CVE-2026-17692: Use after free in DataTransfer
* [Backport] CVE-2026-17691: Out of bounds write in ANGLE
* [Backport] CVE-2026-17689: Uninitialized Use in ANGLE
* [Backport] CVE-2026-17673: Integer overflow in QUIC
* [Backport] CVE-2026-17676: Inappropriate implementation in ANGLE
* [Backport] CVE-2026-17671: Insufficient validation of untrusted input in ANGLE
* [Backport] CVE-2026-17668: Uninitialized Use in ANGLE
* [Backport] CVE-2026-17665: Use after free in V8
* [Backport] CVE-2026-17664: Insufficient validation of untrusted input in Loader
* [Backport] CVE-2026-17650: Use after free in Compositing
* [Backport] CVE-2026-14044: Use after free in ANGLE
* [Backport] CVE-2026-14043: Use after free in GetUserMedia
* [backport] Dependency for CVE-2026-14016
* [backport] CVE-2026-14406: Out of bounds read in V8
* [backport] CVE-2026-14404: Inappropriate implementation in PDFium
* [backport] CVE-2026-14399: Uninitialized Use in Dawn
* [backport] CVE-2026-14397: Out of bounds write in ANGLE (2/2)
* [backport] CVE-2026-14397: Out of bounds write in ANGLE (1/2)
* [backport] CVE-2026-14393: Use after free in V8 (2/2)
* [backport] CVE-2026-14393: Use after free in V8 (1/2)
* [backport] Dependency for CVE-2026-14393 (2/2)
* [backport] Dependency for CVE-2026-14393 (1/2)
* [backport] CVE-2026-14391: Integer overflow in ANGLE
* [backport] CVE-2026-14389: Integer overflow in Skia
* [backport] CVE-2026-14388: Out of bounds read in ANGLE
* [backport] Dependency for CVE-2026-14388:
* [backport] CVE-2026-14384: Out of bounds read in ANGLE
* [backport] Dependency for CVE-2026-14384

Change-Id: I277fb5d8198ac2ce400031d20a17179fc8f6c74d
Reviewed-by: Michael Brüning <[email protected]>
(cherry picked from commit 0dc9388e2132e6bca9efde90aa2319c6318818bd)
Reviewed-by: Qt Cherry-pick Bot <[email protected]>
(cherry picked from commit ad0057eed904f3983611d10c5bd5faf2ba84cb0a)
https://invent.kde.org/qt/qt/qtwebengine/-/commit/7b983b3872bc87ab9648c9d1460950a5d0a52fb5

Git commit f4c31ee0763236e07d8e7c28d2bf4c5ddf52fb9a by Qt Cherry-pick Bot (on behalf of Kaloyan Chehlarski) on 04/08/2026 at 23:56..
Port away from QLibraryInfo::path()

The path() API is obsolete and in talks of getting deprecated, since
it can only return a single path; specifically, the first path
provided by a call to paths(). Recent changes to qtbase make that
first path different from what was being returned in 6.11, leading
to incorrect paths for the QtWebEngineProcess executable on
installed Qt. This change replaces calls to path() with paths(), and
makes sure all returned paths are put into the consideration list
at startup.

Fixes: QTBUG-148751
Change-Id: I79fce46ec7e600437ac219ead5c71567dace1d8d
Reviewed-by: Tor Arne Vestbø <[email protected]>
(cherry picked from commit ff2ebd6b81ac2d480a2201e8ae05f0abb62a510c)
Reviewed-by: Qt Cherry-pick Bot <[email protected]>
(cherry picked from commit 9b7a276ea6c7b54014bf1aa3230dbf0d92f63d52)
https://invent.kde.org/qt/qt/qtwebengine/-/commit/f4c31ee0763236e07d8e7c28d2bf4c5ddf52fb9a

Git commit f573c0c1bccc3f674ae7ed95ea0d6fbbe4e5f573 by Qt Submodule Update Bot on 05/08/2026 at 05:27..
Update dependencies on '6.11' in qt/qtwebengine

Change-Id: Ic91df92af4ccd676b3fe9abec04571ffe60b0bf3
Reviewed-by: Qt Submodule Update Bot <[email protected]>
https://invent.kde.org/qt/qt/qtwebengine/-/commit/f573c0c1bccc3f674ae7ed95ea0d6fbbe4e5f573
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.