Accepted chromium 148.0.7778.167-1~deb12u1 (source) into oldstable-proposed-updates

Debian FTP Masters <[email protected]>
Newsgroups gmane.linux.debian.devel.changes.stable
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Thu, 14 May 2026 16:39:29 -0400
Source: chromium
Architecture: source
Version: 148.0.7778.167-1~deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: Debian Chromium Team <[email protected]>
Changed-By: Andres Salomon <[email protected]>
Changes:
 chromium (148.0.7778.167-1~deb12u1) bookworm-security; urgency=high
 .
   [ Andres Salomon ]
   * New upstream security release.
     - CVE-2026-8509: Heap buffer overflow in WebML.
       Reported by c6eed09fc8b174b0f3eebedcceb1e792.
     - CVE-2026-8510: Integer overflow in Skia. Reported by [email protected].
     - CVE-2026-8511: Use after free in UI. Reported by Google.
     - CVE-2026-8512: Use after free in FileSystem. Reported by Google.
     - CVE-2026-8513: Use after free in Input. Reported by Google.
     - CVE-2026-8514: Use after free in Aura. Reported by Google.
     - CVE-2026-8515: Use after free in HID. Reported by Google.
     - CVE-2026-8516: Insufficient validation of untrusted input in
       DataTransfer. Reported by Google.
     - CVE-2026-8517: Object lifecycle issue in WebShare. Reported by Google.
     - CVE-2026-8518: Use after free in Blink. Reported by Google.
     - CVE-2026-8519: Integer overflow in ANGLE. Reported by Google.
     - CVE-2026-8520: Race in Payments. Reported by Google.
     - CVE-2026-8521: Use after free in Tab Groups. Reported by Google.
     - CVE-2026-8522: Use after free in Downloads. Reported by Google.
     - CVE-2026-8523: Use after free in Mojo.
       Reported by Paul Seekamp / nullenc0de.
     - CVE-2026-8558: Out of bounds write in Fonts. Reported by Matej Smycka.
     - CVE-2026-8524: Out of bounds write in WebAudio.
       Reported by Brendan Dolan-Gavitt, XBOW.
     - CVE-2026-8525: Heap buffer overflow in ANGLE.
       Reported by Nathaniel Oh (@calysteon).
     - CVE-2026-8526: Out of bounds write in WebRTC.
       Reported by c6eed09fc8b174b0f3eebedcceb1e792.
     - CVE-2026-8527: Insufficient validation of untrusted input in Downloads.
       Reported by rachmat.abdul.ro.
     - CVE-2026-8528: Insufficient validation of untrusted input in
       SiteIsolation. Reported by Google.
     - CVE-2026-8529: Heap buffer overflow in Codecs. Reported by Google.
     - CVE-2026-8530: Use after free in Network. Reported by Google.
     - CVE-2026-8531: Heap buffer overflow in WebML. Reported by Syn4pse.
     - CVE-2026-8532: Integer overflow in XML. Reported by Google.
     - CVE-2026-8533: Use after free in Accessibility. Reported by Google.
     - CVE-2026-8534: Integer overflow in GPU. Reported by Google.
     - CVE-2026-8535: Out of bounds read in Media. Reported by Google.
     - CVE-2026-8536: Insufficient validation of untrusted input in
       ReadingMode. Reported by Google.
     - CVE-2026-8537: Insufficient policy enforcement in ViewTransitions.
       Reported by Google.
     - CVE-2026-8538: Insufficient validation of untrusted input in GPU.
       Reported by Google.
     - CVE-2026-8539: Script injection in SanitizerAPI.
       Reported by Jungwoo Lee (@physicube) and Wongi Lee (@_qwerty_po).
     - CVE-2026-8540: Type Confusion in V8. Reported by Google.
     - CVE-2026-8541: Out of bounds read in UI. Reported by Google.
     - CVE-2026-8542: Use after free in Core. Reported by Google.
     - CVE-2026-8543: Out of bounds read in FileSystem. Reported by Google.
     - CVE-2026-8544: Use after free in Media. Reported by Google.
     - CVE-2026-8545: Object corruption in Compositing. Reported by Google.
     - CVE-2026-8546: Out of bounds read in GPU. Reported by Google.
     - CVE-2026-8547: Insufficient policy enforcement in Passwords.
       Reported by Google.
     - CVE-2026-8548: Out of bounds write in Media. Reported by Google.
     - CVE-2026-8549: Use after free in Media. Reported by Google.
     - CVE-2026-8550: Use after free in Google Lens. Reported by Google.
     - CVE-2026-8551: Use after free in Downloads. Reported by Google.
     - CVE-2026-8552: Heap buffer overflow in GPU. Reported by Google.
     - CVE-2026-8553: Use after free in GPU. Reported by Google.
     - CVE-2026-8554: Type Confusion in ANGLE. Reported by Google.
     - CVE-2026-8555: Use after free in GTK. Reported by Google.
     - CVE-2026-8556: Inappropriate implementation in ANGLE. Reported by Google
     - CVE-2026-8557: Use after free in Accessibility. Reported by Google.
     - CVE-2026-8559: Integer overflow in Internationalization.
       Reported by Google.
     - CVE-2026-8560: Heap buffer overflow in SwiftShader.
       Reported by Cassidy Kim(@cassidy6564).
     - CVE-2026-8561: Incorrect security UI in Fullscreen. Reported by
       Wolfgang Ettlinger (aff. Certitude Consulting GmbH) Alexander Hurbean
       (aff. Certitude Consulting GmbH).
     - CVE-2026-8562: Side-channel information leakage in Navigation.
       Reported by Google.
     - CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox.
       Reported by Luan Herrera (@lbherrera_).
     - CVE-2026-8564: Incorrect security UI in Downloads.
       Reported by Alesandro Ortiz https://AlesandroOrtiz.com.
     - CVE-2026-8565: Inappropriate implementation in Downloads.
       Reported by Farras Givari.
     - CVE-2026-8566: Insufficient policy enforcement in Payments.
       Reported by Jorian Woltjer.
     - CVE-2026-8567: Integer overflow in ANGLE. Reported by cinzinga.
     - CVE-2026-8568: Insufficient policy enforcement in AI.
       Reported by Tianyi Hu.
     - CVE-2026-8569: Out of bounds write in Codecs. Reported by Google.
     - CVE-2026-8570: Type Confusion in V8. Reported by Google.
     - CVE-2026-8571: Insufficient policy enforcement in GPU.
       Reported by Mark Blaszczyk.
     - CVE-2026-8572: Insufficient policy enforcement in Network.
       Reported by Google.
     - CVE-2026-8573: Integer overflow in Codecs. Reported by Google.
     - CVE-2026-8574: Use after free in Core. Reported by Google.
     - CVE-2026-8575: Use after free in UI. Reported by Google.
     - CVE-2026-8576: Inappropriate implementation in CORS. Reported by Google
     - CVE-2026-8577: Integer overflow in Fonts. Reported by Google.
     - CVE-2026-8578: Out of bounds read in GPU. Reported by Google.
     - CVE-2026-8579: Insufficient validation of untrusted input in Skia.
       Reported by Google.
     - CVE-2026-8580: Use after free in Mojo. Reported by Google.
     - CVE-2026-8581: Use after free in GPU. Reported by Google.
     - CVE-2026-8582: Object lifecycle issue in Dawn. Reported by Google.
     - CVE-2026-8583: Insufficient policy enforcement in WebXR.
       Reported by Google.
     - CVE-2026-8584: Inappropriate implementation in Views. Reported by Google
     - CVE-2026-8585: Inappropriate implementation in Media. Reported by Google
     - CVE-2026-8586: Inappropriate implementation in Chromoting.
       Reported by Google.
     - CVE-2026-8587: Use after free in Extensions.
       Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab.
   * rust-1.85/file_as_c_str.patch: fix build on non-x86 archs, as char*
     signed-ness is apparently different there versus arm & ppc64 [trixie,
     bookworm].
Checksums-Sha1:
 ee2927da516639828e426982760eed9828be78a3 4068 chromium_148.0.7778.167-1~deb12u1.dsc
 1ce8e6516d62190f97ba688b4ff4d0411add81c7 900734916 chromium_148.0.7778.167.orig.tar.xz
 b3f34bd076f811c0708ba6c679391b4ab36f2b4d 8573832 chromium_148.0.7778.167-1~deb12u1.debian.tar.xz
 4c47652c5098c652c1771be7b6a822713bc03d5d 26842 chromium_148.0.7778.167-1~deb12u1_source.buildinfo
Checksums-Sha256:
 c1f32f5f7af555ed99af4ee1fb22d59907359b1d1de6e544f9261ae675165a2e 4068 chromium_148.0.7778.167-1~deb12u1.dsc
 82f42e6c4ef729654ed806192fd49fa750f810cfe6f18651c76110eeb50750be 900734916 chromium_148.0.7778.167.orig.tar.xz
 9fe444930fb4705f5d12ebdc4a86bf1e3a0b7acf9bbe62fc6e4ea4dc0c224509 8573832 chromium_148.0.7778.167-1~deb12u1.debian.tar.xz
 64adf6bc8d75cdfc35943d9f7e42625aaa56b8e1e7782857e7e565d3f57a0c85 26842 chromium_148.0.7778.167-1~deb12u1_source.buildinfo
Files:
 aeeaeb1c1785b16ef8392c9b165fe712 4068 web optional chromium_148.0.7778.167-1~deb12u1.dsc
 b193e9b383a121afb04f22210aba1d8b 900734916 web optional chromium_148.0.7778.167.orig.tar.xz
 20d0da275a652bd5b60bf839d308d24b 8573832 web optional chromium_148.0.7778.167-1~deb12u1.debian.tar.xz
 e2e8c11dff5f5f1461566ecad80f568b 26842 web optional chromium_148.0.7778.167-1~deb12u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmoGO0UUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjeU3g/8DX0ZJuyb+euOh5WOYtFiLRbOv0cv
+Wrao+B097/1Wq6KLEWcYD2vl/JJPds9BShaVkRQslBkkem6cMVS/pPEJy01dP40
hcVUGwF2ZMv46fVLMtEjQodmx7puneamjRmKYPXoQduTsOX5SSdTLsINHtt9CsGI
WAjzDDU5csDLM2oNmr+C2bbClEPoJtIzZRX2qlCQDKM2yQvMZ0eTdYHz+KWng1Ez
+LPGiYkUDbSylYy2cguFCRivU1L3m2X0MOUBYSpIf8WiIGUk5GCtvovG/S0cL5t3
n+ywL6wUozqm4VKsgk/cuuS5m+0JIO4hjOhMNpM/C5WAbQROAq+29NraJIxF3dnS
5W5Tuy+CVbM8bv+HE1f7HJUiiskPnpzipNFeWCn9Q4tlP8PeRTOeZ+89nA96TdPK
m1XQHYTOLa0Y8T3dG1OmRfcZIYd3b1/5HwQsZNKjRXcWH8sjsye0c1JUoPnU7UGb
liTRB3mah2V7EkEDMK9mz9UZQw+B8xTvF1l/q88tqYo2Z6TQlNfkk0/GQdnru1do
Hty3emegwtlTUo4vJvdWK50Ct5nd2crGHfiVeb03jgBQvYVwi6DdR1/IBJIe3mMf
p7rH0rrUthiWrx+ntUaY+5amvznuA/Tw7lql9/5asIWwmc+i5F5TK0mNqG2nbnQh
8RpqcztYtZgB/rw=
=T7WF
-----END PGP SIGNATURE-----
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCagmcvwAKCRCb9qggYcy5
IR5DAP9J+WmsSeUAmHXt/+RnaKbtsPJLdF0ZQJxhQSP1mq5S3gEAzf4KMA6nKDRC
0bzy+p4PQNTtNn0KQh0fYGKGd8EmQQ4=
=a48I
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.