-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 12 Jun 2026 17:27:35 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: arm64 Version: 149.0.7827.114-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm64 Build Daemon (arm-conova-04) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (149.0.7827.114-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12007: Use after free  Core. Reported by Google. - CVE-2026-12008: Use after free  DigitalCredentials. Reported by Google. - CVE-2026-12009: Insufficient validation of untrusted input Accessibility. Reported by Google. - CVE-2026-12010: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12011: Use after free  WebMIDI. Reported by Google. - CVE-2026-12012: Use after free  Network. Reported by Google. - CVE-2026-12013: Use after free  Media. Reported by Henock Habte, Independent Security Researcher. - CVE-2026-12014: Use after free  Cast. Reported by Google. - CVE-2026-12015: Use after free  Autofill. Reported by Google. - CVE-2026-12016: Insufficient validation of untrusted input  DevTools. Reported by Google. - CVE-2026-12017: Insufficient validation of untrusted input Extensions. Reported by Google. - CVE-2026-12018: Inappropriate implementation  Mojo. Reported by Google. - CVE-2026-12019: Out of bounds write  Codecs. Reported by Google. - CVE-2026-12020: Use after free  Autofill. Reported by Google. - CVE-2026-12022: Race  Safe Browsing. Reported by Google. - CVE-2026-12023: Use after free  GPU. Reported by Google. - CVE-2026-12024: Insufficient policy enforcement  DevTools. Reported by Google. - CVE-2026-12025: Insufficient validation of untrusted input  Network. Reported by Google. - CVE-2026-12026: Out of bounds read  Video. Reported by Google. - CVE-2026-12027: Insufficient policy enforcement  Headless. Reported by Google. - CVE-2026-12028: Use after free  GPU. Reported by Google. - CVE-2026-12029: Use after free  Video. Reported by Google. - CVE-2026-12030: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12031: Inappropriate implementation  Views. Reported by Google - CVE-2026-12032: Inappropriate implementation  Passwords. Reported by Google. - CVE-2026-12033: Out of bounds read  VideoCapture. Reported by Google. - CVE-2026-12034: Insufficient validation of untrusted input  Linux Toolkit Theming. Reported by Google. - CVE-2026-12035: Use after free  Views. Reported by Google. . [ Jianfeng Liu ] * d/patches/loongarch64/0024-fix-libyuv-lsx.patch: drop due to upstream reverting to version of libyuv that doesn't have lsx issue. Checksums-Sha1: 2a2396a98394f5a61adb6070f5a894d8e0075f54 6138280 chromium-common-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb 5831961a95e10666fdc58b5d9a907be21fc3b4a1 30838936 chromium-common_149.0.7827.114-1~deb13u1_arm64.deb d280b5239422e5f222485a551379bb92eb39a22f 34842328 chromium-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb f59f22ceaa237bfb7c2cdebd6847a37d4b087b9b 6806468 chromium-driver_149.0.7827.114-1~deb13u1_arm64.deb 8757928cc537477a8fb272914a9807d96a9a1a78 29029568 chromium-headless-shell-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb e8a600f154b3263d6fbe35de9bfb7d449fb03270 55473840 chromium-headless-shell_149.0.7827.114-1~deb13u1_arm64.deb 99f51264bb4b737ef33b6b8b02a2cc38be9293cc 21080 chromium-sandbox-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb 4261fabc29057b6e688ce837f021038d5cf305bd 126564 chromium-sandbox_149.0.7827.114-1~deb13u1_arm64.deb 4fd64da5c5fe9325adccab1edfa3afd52739cab8 30512036 chromium-shell-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb e3f01b20f8d116cb2e8bca95f78d5198d42d6004 55256224 chromium-shell_149.0.7827.114-1~deb13u1_arm64.deb d0eb868838e283e7f930229045f1209a5b2632ea 30646 chromium_149.0.7827.114-1~deb13u1_arm64-buildd.buildinfo 63ea76c11a0b37bc5009830bbfb6a19ba4beee1b 73975172 chromium_149.0.7827.114-1~deb13u1_arm64.deb Checksums-Sha256: f583be591f4e8e6bc319d331fb5c2592ffadd8d12d087495ba2aecaf8abc85d3 6138280 chromium-common-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb cd162ca16ac553fded1457adfcf1e6ed361ec6fc96b2239197f40bd927d10589 30838936 chromium-common_149.0.7827.114-1~deb13u1_arm64.deb b80c49793fa7c5370d7a581951632a631bdaef71a2b0caa08e75e5a46a2f13f4 34842328 chromium-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb e8acb9ad1da0c89fa438556171100cc791018348dcc7b95ef46f839c345a86ed 6806468 chromium-driver_149.0.7827.114-1~deb13u1_arm64.deb b580497d2a88d1907cb5878a4142ed18e900ab78d02c86b784d0ca827955a254 29029568 chromium-headless-shell-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb f6d7db6f0d276470ce57c4b47a2ef8df49bf7e17e5d1337b4df884a5ffbd0d87 55473840 chromium-headless-shell_149.0.7827.114-1~deb13u1_arm64.deb 6ce92f0d02a2e7a667362f61be0451d31ae322ee1b73a1611803ee12354fabe0 21080 chromium-sandbox-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb df853a24e4cb7b45badcd99f952b158066339520eaa71d0738d86dedd24cbb23 126564 chromium-sandbox_149.0.7827.114-1~deb13u1_arm64.deb c41726fa7a6851b3277225c34161693d9f71e6055e2f8ed63abc2ec7f51f13fb 30512036 chromium-shell-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb b4d93e56cf6f8cceacf980b9a5fce32239acf288279c04b86d79970d4e8698a4 55256224 chromium-shell_149.0.7827.114-1~deb13u1_arm64.deb ec2513451e1f9c5f6253ee2b942247a0c16597cf31b10c9c5111675bc427b49d 30646 chromium_149.0.7827.114-1~deb13u1_arm64-buildd.buildinfo 84cfd57adece2155256c8d198ff408df5c31a10b86eb7661439440737461ed5b 73975172 chromium_149.0.7827.114-1~deb13u1_arm64.deb Files: b32c6b46f4426b08b0d8847fa0f0725f 6138280 debug optional chromium-common-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb 856d183c2d3c712eca50a922e7a9b1f0 30838936 web optional chromium-common_149.0.7827.114-1~deb13u1_arm64.deb 77faf4ce6bf6b665904e2eb786d3cd24 34842328 debug optional chromium-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb e4d72ddaca4d0d2c65cf0a88dfb85009 6806468 web optional chromium-driver_149.0.7827.114-1~deb13u1_arm64.deb f9da26a43278e350ccb59ad11890f98c 29029568 debug optional chromium-headless-shell-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb 232e437140d76f499210e3120ac68402 55473840 web optional chromium-headless-shell_149.0.7827.114-1~deb13u1_arm64.deb 2132fd30d9c725f71961a049fa763fb9 21080 debug optional chromium-sandbox-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb 0b875cd709e11158ec6f236284ff39ee 126564 web optional chromium-sandbox_149.0.7827.114-1~deb13u1_arm64.deb 8756c98c4702311dba5ac57a6afe0ac8 30512036 debug optional chromium-shell-dbgsym_149.0.7827.114-1~deb13u1_arm64.deb f1a93360b65636676dd80b9191feeb45 55256224 web optional chromium-shell_149.0.7827.114-1~deb13u1_arm64.deb 164c100844d225af5982697659429dae 30646 web optional chromium_149.0.7827.114-1~deb13u1_arm64-buildd.buildinfo fc46089fce4d86b081b1be5ed03d9ba2 73975172 web optional chromium_149.0.7827.114-1~deb13u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYxmcRLDHP0tCCM0oScpU3dYulLgFAmoteSwACgkQScpU3dYu lLiP1xAAi3grm4haT5IvT1YsEeKM4VBy9oHU927r+XhqIUajyqarHWf6k3AdEr2+ n0MotLQkMaM0I9Qwfs+eirgezsj6kuyqKCPCrPS/4eQo08aRZeRgQ2k4LZr+uL0o SeKQyAYHBtKCU8HvIfKlRY8G2cMmS4WYefEc0SvdSg9LDix+/Ufdo/OwzxBfwCLO cCQXNJ9S4Bd+WpNtVfzDop15SwPtVI8c09vYlrenz7V9lX2yYLlBBke2uXgVip0h O1TZbeRV18fJ1+GSdgNouXu2dyvSA631ox46oYKBCNvc7mkUDoZWwE7/jj0hHBpV lZ4DEhBC38RzbzXIdqbRR+rxPf3mr+mWHqNitthd6qpVBta6xPxdDZSkpbU4RaTF PJyeE8WX5SrQoSh4AGsufr3Ub18aYxM/W3NBtqQGKNajvjfSWvq+pBd59k3/eIno ArOxXQpnsL1e9UJ6Q40kiFEeJKTw0loUStCN15qQKz27IX/v2X+dSO61nI7DjkFc wZo0fpt6zCNCPYG0JZqKLAwMrdT5qE3CTkFLvFer3BZrcxFrHCqWgi1mHJDbkOcQ wKRVFs10b+NxuqLB7UJL5q4jfWcPCmT2Qu5i+uD1z7926Zn8bUrpNxiO5gw0hGYE E15GTPi44mdJ7gLhIwemKwaHs+Gw+ZfctqtLbXhFfkerjVsW/0I= =HtOi -----END PGP SIGNATURE-----