-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 12 Jun 2026 17:27:35 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: amd64 Version: 149.0.7827.114-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (149.0.7827.114-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12007: Use after free  Core. Reported by Google. - CVE-2026-12008: Use after free  DigitalCredentials. Reported by Google. - CVE-2026-12009: Insufficient validation of untrusted input Accessibility. Reported by Google. - CVE-2026-12010: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12011: Use after free  WebMIDI. Reported by Google. - CVE-2026-12012: Use after free  Network. Reported by Google. - CVE-2026-12013: Use after free  Media. Reported by Henock Habte, Independent Security Researcher. - CVE-2026-12014: Use after free  Cast. Reported by Google. - CVE-2026-12015: Use after free  Autofill. Reported by Google. - CVE-2026-12016: Insufficient validation of untrusted input  DevTools. Reported by Google. - CVE-2026-12017: Insufficient validation of untrusted input Extensions. Reported by Google. - CVE-2026-12018: Inappropriate implementation  Mojo. Reported by Google. - CVE-2026-12019: Out of bounds write  Codecs. Reported by Google. - CVE-2026-12020: Use after free  Autofill. Reported by Google. - CVE-2026-12022: Race  Safe Browsing. Reported by Google. - CVE-2026-12023: Use after free  GPU. Reported by Google. - CVE-2026-12024: Insufficient policy enforcement  DevTools. Reported by Google. - CVE-2026-12025: Insufficient validation of untrusted input  Network. Reported by Google. - CVE-2026-12026: Out of bounds read  Video. Reported by Google. - CVE-2026-12027: Insufficient policy enforcement  Headless. Reported by Google. - CVE-2026-12028: Use after free  GPU. Reported by Google. - CVE-2026-12029: Use after free  Video. Reported by Google. - CVE-2026-12030: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12031: Inappropriate implementation  Views. Reported by Google - CVE-2026-12032: Inappropriate implementation  Passwords. Reported by Google. - CVE-2026-12033: Out of bounds read  VideoCapture. Reported by Google. - CVE-2026-12034: Insufficient validation of untrusted input  Linux Toolkit Theming. Reported by Google. - CVE-2026-12035: Use after free  Views. Reported by Google. . [ Jianfeng Liu ] * d/patches/loongarch64/0024-fix-libyuv-lsx.patch: drop due to upstream reverting to version of libyuv that doesn't have lsx issue. Checksums-Sha1: 75fd026989ed09b8b81e8adca07da723f791f187 5211232 chromium-common-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 2dd93b5cc9dd062fc714ef0fd5b560aea3da7f2a 26258148 chromium-common_149.0.7827.114-1~deb13u1_amd64.deb 20038bbf03546244880b4c734e4845bb521fe053 33351428 chromium-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 7be1c17797d6dfaa0ffbd0a3418a0861a0e5a41c 7673148 chromium-driver_149.0.7827.114-1~deb13u1_amd64.deb 1f6d2940e6959c843f69ed1ad003850a5c0b17b0 28188944 chromium-headless-shell-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 36be79a874da878f2b43b84740c1cf3568c1391f 63461060 chromium-headless-shell_149.0.7827.114-1~deb13u1_amd64.deb 87b7900a88faf5c4aa0041421cc5da319e62021c 20212 chromium-sandbox-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb d064d5c03aff42776aab2210a27e88f1217894c7 125752 chromium-sandbox_149.0.7827.114-1~deb13u1_amd64.deb f90591d56ddcce68e59f51a217370c0b7b95b43e 29813160 chromium-shell-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 429f9852d3f438eefe064ae52b5aa20a1e132f94 63076236 chromium-shell_149.0.7827.114-1~deb13u1_amd64.deb 3ba7314ed584c034d466dbb941c77a0d3fc78123 30680 chromium_149.0.7827.114-1~deb13u1_amd64-buildd.buildinfo 42fd8ebc228229db6461917207cc2e561df75d19 85768256 chromium_149.0.7827.114-1~deb13u1_amd64.deb Checksums-Sha256: 82034fbb985d6c676687605594b4c3ff86322aea7f8678d758838b0bb2a9445f 5211232 chromium-common-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb d1f3c47ff3de7385052b0436a620a889247e9911d830abe9507cef2fe8bb5855 26258148 chromium-common_149.0.7827.114-1~deb13u1_amd64.deb 78a345a2bb42f7b460938d3187c7b2593c7ecad7f3bd98c4f52ea1bf5eee18aa 33351428 chromium-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 8f90381a8e83f8c0afb5441e2166d13fb80e05ff78a936c0b444123a61d59a32 7673148 chromium-driver_149.0.7827.114-1~deb13u1_amd64.deb d0bb22d02e10c15ef49f2784b8ef1c8bf8b2e68d30b09ecc869bdb1ddb5cd800 28188944 chromium-headless-shell-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 7a3b35d20b44c06b7eba4da15f452b3cfa43f7be092d5eea33350ef3adb6b2a8 63461060 chromium-headless-shell_149.0.7827.114-1~deb13u1_amd64.deb e55c37e0f8e5075c9d52ab945e24b2ef4bd151d4771a287698daa88794fccb4e 20212 chromium-sandbox-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 1bfab222a98127e0df15edba68a2e0924c4099df84cb0c07b3c780ed05193b61 125752 chromium-sandbox_149.0.7827.114-1~deb13u1_amd64.deb 77f36750517422b8073582845909c36cbced4de36874dc855b17ea5867b38275 29813160 chromium-shell-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb e3a6e7c8b33c883b0a69c9170a81e77ee5b0ff8a897171c5173ba4325a1112c1 63076236 chromium-shell_149.0.7827.114-1~deb13u1_amd64.deb 991817160cd7ce4c32b4cf1882085c1ed619bad51691f6941096371bfeb482e6 30680 chromium_149.0.7827.114-1~deb13u1_amd64-buildd.buildinfo 47038e1214c5fcfb1037ae5ace1e0da525d32093e7d60986ebe5807c281ef282 85768256 chromium_149.0.7827.114-1~deb13u1_amd64.deb Files: 569d8bf548275b713e29b9dfa5f5d195 5211232 debug optional chromium-common-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 9fb7b3956d96777b6cb8f66c52ce9662 26258148 web optional chromium-common_149.0.7827.114-1~deb13u1_amd64.deb 6407681bf3f7af4bfe7135586d0755c8 33351428 debug optional chromium-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 6d8933df8e800cecd4b4a5e460a97c02 7673148 web optional chromium-driver_149.0.7827.114-1~deb13u1_amd64.deb 271f5a40a36e5256cf40fd9d4d365c51 28188944 debug optional chromium-headless-shell-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 0d580570b5fbc5b1a45b13e4592d8cef 63461060 web optional chromium-headless-shell_149.0.7827.114-1~deb13u1_amd64.deb 8d3ed0606875d9706cbceca8f512efe2 20212 debug optional chromium-sandbox-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb dd9dded8810c7951c9a24811e7b5c491 125752 web optional chromium-sandbox_149.0.7827.114-1~deb13u1_amd64.deb 88c9317b45dfa676765a2c4696d2d1e3 29813160 debug optional chromium-shell-dbgsym_149.0.7827.114-1~deb13u1_amd64.deb 2f01942ba3ab535848ba83795da6ec33 63076236 web optional chromium-shell_149.0.7827.114-1~deb13u1_amd64.deb 1e6ec0882891345ced1793f1eb90cdb3 30680 web optional chromium_149.0.7827.114-1~deb13u1_amd64-buildd.buildinfo a4509609ca3ed33a2609af8a99650ebd 85768256 web optional chromium_149.0.7827.114-1~deb13u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmotbKQACgkQN8Ugyu9d QiRmPw//bLA/qV8+rY1+/WXOO8bbp0F/K09jiC9XrVSZoZdBmIp5Cpt0X9Frv97s ICw/2A1g+PiySmuJRMTKAa9pSn+nYvbYkzUxItM69DhwxMKBYqzTkNVWh/VbUqp2 AYMZtnTVOedBVHG2VkQx/8uELXrLEQw5/LixXGM81Mo2NiOG+GWgdqTTvpYIEm7A 624i9cg6C95fXBsLNFuXYalPmpBtFi5KC0NVuW6IMqwWmfPcUCwsQsftu6LpUG7g gIcjV43MuJREMznW/JVGJ5H+g9ENS9Lo5Gv1m1MWQZmmndLZ3QVUJBn2kRJnXQmQ cOR6vvA/kUv7BUKZbiN420S13rD1HBx8mUTNItppBi7fHyKkI4f5PArtzAUzK6fh 5u4vjdjDIlt+Lnk99IKgEsh3nRTTN06KgzN6xBM+EDUJTsKrXxBLUgKqW/YbXxLL dXJ75Z1M0u+QC+x5Xua9biQPhXy54mwjGJDsxj8QoyHq0ttMNw+oFy7kvStubBEw FcU8yMSkfqhYasRZVeQgdVH1EQzn4BmE3a/BcOJ5OmYwzDd8R94J+Q5FwhkmsBGB Bsc1YXXGze3kfS3j5qQVu2kdS0Xx02I9er/IIe8wlwYEsupBnOZKXxpV5kX8eWDT 268GTbELJIvP3TcPJXlUQkxKWNvYZ4ultgzbV0+vk7ILHZVHpdM= =+b0m -----END PGP SIGNATURE-----