Accepted chromium 148.0.7778.167-1~deb13u1 (source) into proposed-updates

Debian FTP Masters <[email protected]>
Newsgroups gmane.linux.debian.devel.changes.stable
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Thu, 14 May 2026 16:39:29 -0400
Source: chromium
Architecture: source
Version: 148.0.7778.167-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Chromium Team <[email protected]>
Changed-By: Andres Salomon <[email protected]>
Changes:
 chromium (148.0.7778.167-1~deb13u1) trixie-security; urgency=high
 .
   [ Andres Salomon ]
   * New upstream security release.
     - CVE-2026-8509: Heap buffer overflow in WebML.
       Reported by c6eed09fc8b174b0f3eebedcceb1e792.
     - CVE-2026-8510: Integer overflow in Skia. Reported by [email protected].
     - CVE-2026-8511: Use after free in UI. Reported by Google.
     - CVE-2026-8512: Use after free in FileSystem. Reported by Google.
     - CVE-2026-8513: Use after free in Input. Reported by Google.
     - CVE-2026-8514: Use after free in Aura. Reported by Google.
     - CVE-2026-8515: Use after free in HID. Reported by Google.
     - CVE-2026-8516: Insufficient validation of untrusted input in
       DataTransfer. Reported by Google.
     - CVE-2026-8517: Object lifecycle issue in WebShare. Reported by Google.
     - CVE-2026-8518: Use after free in Blink. Reported by Google.
     - CVE-2026-8519: Integer overflow in ANGLE. Reported by Google.
     - CVE-2026-8520: Race in Payments. Reported by Google.
     - CVE-2026-8521: Use after free in Tab Groups. Reported by Google.
     - CVE-2026-8522: Use after free in Downloads. Reported by Google.
     - CVE-2026-8523: Use after free in Mojo.
       Reported by Paul Seekamp / nullenc0de.
     - CVE-2026-8558: Out of bounds write in Fonts. Reported by Matej Smycka.
     - CVE-2026-8524: Out of bounds write in WebAudio.
       Reported by Brendan Dolan-Gavitt, XBOW.
     - CVE-2026-8525: Heap buffer overflow in ANGLE.
       Reported by Nathaniel Oh (@calysteon).
     - CVE-2026-8526: Out of bounds write in WebRTC.
       Reported by c6eed09fc8b174b0f3eebedcceb1e792.
     - CVE-2026-8527: Insufficient validation of untrusted input in Downloads.
       Reported by rachmat.abdul.ro.
     - CVE-2026-8528: Insufficient validation of untrusted input in
       SiteIsolation. Reported by Google.
     - CVE-2026-8529: Heap buffer overflow in Codecs. Reported by Google.
     - CVE-2026-8530: Use after free in Network. Reported by Google.
     - CVE-2026-8531: Heap buffer overflow in WebML. Reported by Syn4pse.
     - CVE-2026-8532: Integer overflow in XML. Reported by Google.
     - CVE-2026-8533: Use after free in Accessibility. Reported by Google.
     - CVE-2026-8534: Integer overflow in GPU. Reported by Google.
     - CVE-2026-8535: Out of bounds read in Media. Reported by Google.
     - CVE-2026-8536: Insufficient validation of untrusted input in
       ReadingMode. Reported by Google.
     - CVE-2026-8537: Insufficient policy enforcement in ViewTransitions.
       Reported by Google.
     - CVE-2026-8538: Insufficient validation of untrusted input in GPU.
       Reported by Google.
     - CVE-2026-8539: Script injection in SanitizerAPI.
       Reported by Jungwoo Lee (@physicube) and Wongi Lee (@_qwerty_po).
     - CVE-2026-8540: Type Confusion in V8. Reported by Google.
     - CVE-2026-8541: Out of bounds read in UI. Reported by Google.
     - CVE-2026-8542: Use after free in Core. Reported by Google.
     - CVE-2026-8543: Out of bounds read in FileSystem. Reported by Google.
     - CVE-2026-8544: Use after free in Media. Reported by Google.
     - CVE-2026-8545: Object corruption in Compositing. Reported by Google.
     - CVE-2026-8546: Out of bounds read in GPU. Reported by Google.
     - CVE-2026-8547: Insufficient policy enforcement in Passwords.
       Reported by Google.
     - CVE-2026-8548: Out of bounds write in Media. Reported by Google.
     - CVE-2026-8549: Use after free in Media. Reported by Google.
     - CVE-2026-8550: Use after free in Google Lens. Reported by Google.
     - CVE-2026-8551: Use after free in Downloads. Reported by Google.
     - CVE-2026-8552: Heap buffer overflow in GPU. Reported by Google.
     - CVE-2026-8553: Use after free in GPU. Reported by Google.
     - CVE-2026-8554: Type Confusion in ANGLE. Reported by Google.
     - CVE-2026-8555: Use after free in GTK. Reported by Google.
     - CVE-2026-8556: Inappropriate implementation in ANGLE. Reported by Google
     - CVE-2026-8557: Use after free in Accessibility. Reported by Google.
     - CVE-2026-8559: Integer overflow in Internationalization.
       Reported by Google.
     - CVE-2026-8560: Heap buffer overflow in SwiftShader.
       Reported by Cassidy Kim(@cassidy6564).
     - CVE-2026-8561: Incorrect security UI in Fullscreen. Reported by
       Wolfgang Ettlinger (aff. Certitude Consulting GmbH) Alexander Hurbean
       (aff. Certitude Consulting GmbH).
     - CVE-2026-8562: Side-channel information leakage in Navigation.
       Reported by Google.
     - CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox.
       Reported by Luan Herrera (@lbherrera_).
     - CVE-2026-8564: Incorrect security UI in Downloads.
       Reported by Alesandro Ortiz https://AlesandroOrtiz.com.
     - CVE-2026-8565: Inappropriate implementation in Downloads.
       Reported by Farras Givari.
     - CVE-2026-8566: Insufficient policy enforcement in Payments.
       Reported by Jorian Woltjer.
     - CVE-2026-8567: Integer overflow in ANGLE. Reported by cinzinga.
     - CVE-2026-8568: Insufficient policy enforcement in AI.
       Reported by Tianyi Hu.
     - CVE-2026-8569: Out of bounds write in Codecs. Reported by Google.
     - CVE-2026-8570: Type Confusion in V8. Reported by Google.
     - CVE-2026-8571: Insufficient policy enforcement in GPU.
       Reported by Mark Blaszczyk.
     - CVE-2026-8572: Insufficient policy enforcement in Network.
       Reported by Google.
     - CVE-2026-8573: Integer overflow in Codecs. Reported by Google.
     - CVE-2026-8574: Use after free in Core. Reported by Google.
     - CVE-2026-8575: Use after free in UI. Reported by Google.
     - CVE-2026-8576: Inappropriate implementation in CORS. Reported by Google
     - CVE-2026-8577: Integer overflow in Fonts. Reported by Google.
     - CVE-2026-8578: Out of bounds read in GPU. Reported by Google.
     - CVE-2026-8579: Insufficient validation of untrusted input in Skia.
       Reported by Google.
     - CVE-2026-8580: Use after free in Mojo. Reported by Google.
     - CVE-2026-8581: Use after free in GPU. Reported by Google.
     - CVE-2026-8582: Object lifecycle issue in Dawn. Reported by Google.
     - CVE-2026-8583: Insufficient policy enforcement in WebXR.
       Reported by Google.
     - CVE-2026-8584: Inappropriate implementation in Views. Reported by Google
     - CVE-2026-8585: Inappropriate implementation in Media. Reported by Google
     - CVE-2026-8586: Inappropriate implementation in Chromoting.
       Reported by Google.
     - CVE-2026-8587: Use after free in Extensions.
       Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab.
   * rust-1.85/file_as_c_str.patch: fix build on non-x86 archs, as char*
     signed-ness is apparently different there versus arm & ppc64 [trixie,
     bookworm].
Checksums-Sha1:
 cd214a36bb6ee428fd9da60c956458e49c833ed7 4099 chromium_148.0.7778.167-1~deb13u1.dsc
 1ce8e6516d62190f97ba688b4ff4d0411add81c7 900734916 chromium_148.0.7778.167.orig.tar.xz
 044cedde02bd96d093e89589a6bac55ea705ef8f 487100 chromium_148.0.7778.167-1~deb13u1.debian.tar.xz
 412201a4060d8d9a3cefb32e5e3a89204bcf3266 26933 chromium_148.0.7778.167-1~deb13u1_source.buildinfo
Checksums-Sha256:
 0b74ce1449f527b98c62d6fb579deb88ebcd1c4291d467fc60b4531ce34a6220 4099 chromium_148.0.7778.167-1~deb13u1.dsc
 82f42e6c4ef729654ed806192fd49fa750f810cfe6f18651c76110eeb50750be 900734916 chromium_148.0.7778.167.orig.tar.xz
 c203aa962e15e16b64178bb91213a038ffe94d8268e0c5d909f753f0d725eb59 487100 chromium_148.0.7778.167-1~deb13u1.debian.tar.xz
 3b64ff783ff280e645d9b5f44e77addd87ba94746bd93695d5d90815dd69957f 26933 chromium_148.0.7778.167-1~deb13u1_source.buildinfo
Files:
 f29d353161e2e8ff95b30418bd6a3f6d 4099 web optional chromium_148.0.7778.167-1~deb13u1.dsc
 b193e9b383a121afb04f22210aba1d8b 900734916 web optional chromium_148.0.7778.167.orig.tar.xz
 82fa2086ecf0c9e81deb3b41d6ecc32c 487100 web optional chromium_148.0.7778.167-1~deb13u1.debian.tar.xz
 23014cc8710fa98aa3f7207eff23b659 26933 web optional chromium_148.0.7778.167-1~deb13u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmoGNQ8UHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjeDUQ/+KM2dEVPxEk+NFEdhqIEs8ZdGXbz8
TOIocdAexm7uUC2xJWbirZFWtXunDRXTvA4e9ZIn7tXEKsVsMPqgKb+OyAhzc7ms
cFJqfHRsYyCSvF7jPO6O2myZcsKONtuu9Rai/rePYpl78q9Il7A93dGveS7T31cL
HyHKLkQkpTKns5eSFiTPyW6aoArbZEpqi0lfOwSnL6E1i/l/g0EKGgVNP4ayynpm
9nPB1UYswCYcIQgeyFe/0vb0K/qvCK/Z0iHZ2rBOHTfr6IEh8rWrUbMR2+wOG7XZ
H0hV+o7oZEqqhFbA6raycaqVGjLqJ839dUNfpDTlribKDhoHyzDUIaT/DRRQCFYe
vWotmAErpvQ4t7D6fECExEOrEYFqa/k+8aX3+DXaebSdXmFXKeyEX73XP3B1oruD
4f8m0atVz6rDAE3P8dxOPTVzrK1XulUOfe4atzKbZzk6V3vL9rBI/MnqHvfpUv1d
XgAfN2O/P2dptcRjDe+XmZg5hk2KcIsTn8vMJx/PpcsTVsbOyE2ZifSj0O0YNTY5
BWbF7U2BGI+6BF1FJc0AONRyY5hljv2o0PFTyiyL89zt0ucF2Pai48lTdw1IolKt
k5wDHuDy+zq2alGuSIKttrfqV6FGgyQDIRzr4fw27sBzuaVYP1cl4P+aiISIxIyI
GF2yQU8YR1obogQ=
=Q6ro
-----END PGP SIGNATURE-----
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCagj+fwAKCRCb9qggYcy5
IYDrAP9vX0//vd+3BmDrzIV2GzRsRtAErGfBwo2MKb7/lcIhOQD+PF5xaLTCHZ+e
Mf3qDypKzeJX7kvyfTja+rGwkdppEA8=
=PHyG
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.