-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 12 Jun 2026 17:27:35 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 149.0.7827.114-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (149.0.7827.114-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12007: Use after free  Core. Reported by Google. - CVE-2026-12008: Use after free  DigitalCredentials. Reported by Google. - CVE-2026-12009: Insufficient validation of untrusted input Accessibility. Reported by Google. - CVE-2026-12010: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12011: Use after free  WebMIDI. Reported by Google. - CVE-2026-12012: Use after free  Network. Reported by Google. - CVE-2026-12013: Use after free  Media. Reported by Henock Habte, Independent Security Researcher. - CVE-2026-12014: Use after free  Cast. Reported by Google. - CVE-2026-12015: Use after free  Autofill. Reported by Google. - CVE-2026-12016: Insufficient validation of untrusted input  DevTools. Reported by Google. - CVE-2026-12017: Insufficient validation of untrusted input Extensions. Reported by Google. - CVE-2026-12018: Inappropriate implementation  Mojo. Reported by Google. - CVE-2026-12019: Out of bounds write  Codecs. Reported by Google. - CVE-2026-12020: Use after free  Autofill. Reported by Google. - CVE-2026-12022: Race  Safe Browsing. Reported by Google. - CVE-2026-12023: Use after free  GPU. Reported by Google. - CVE-2026-12024: Insufficient policy enforcement  DevTools. Reported by Google. - CVE-2026-12025: Insufficient validation of untrusted input  Network. Reported by Google. - CVE-2026-12026: Out of bounds read  Video. Reported by Google. - CVE-2026-12027: Insufficient policy enforcement  Headless. Reported by Google. - CVE-2026-12028: Use after free  GPU. Reported by Google. - CVE-2026-12029: Use after free  Video. Reported by Google. - CVE-2026-12030: Heap buffer overflow  GPU. Reported by Google. - CVE-2026-12031: Inappropriate implementation  Views. Reported by Google - CVE-2026-12032: Inappropriate implementation  Passwords. Reported by Google. - CVE-2026-12033: Out of bounds read  VideoCapture. Reported by Google. - CVE-2026-12034: Insufficient validation of untrusted input  Linux Toolkit Theming. Reported by Google. - CVE-2026-12035: Use after free  Views. Reported by Google. . [ Jianfeng Liu ] * d/patches/loongarch64/0024-fix-libyuv-lsx.patch: drop due to upstream reverting to version of libyuv that doesn't have lsx issue. Checksums-Sha1: 09da540f9b5d81d2a89a359673c1b3ed5e3a0829 5319644 chromium-common-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 3ba6f5b64c9fcacceb09a43929bdc6d324490f88 26225460 chromium-common_149.0.7827.114-1~deb13u1_i386.deb 3c5e2cb3b51e4d0dbd3d82912ab738beea5c5442 36215616 chromium-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 498766ea04aad4f726d92082e446e4728787e1f9 8113656 chromium-driver_149.0.7827.114-1~deb13u1_i386.deb 85738fd94d7bce36db76bd59bd83f842576d5ead 29803080 chromium-headless-shell-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 621890a5a230eff107a613b78745cc8f2ffd60f7 59808880 chromium-headless-shell_149.0.7827.114-1~deb13u1_i386.deb bf17a7d68f1da7482a51717a677ce46b25517c98 18992 chromium-sandbox-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 34a9dc9e83f654596f9494a3cfb0b90193365ec9 125616 chromium-sandbox_149.0.7827.114-1~deb13u1_i386.deb 66bb75ee69720e29fd2bef731aee375e11bc9d22 32726152 chromium-shell-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 0d324c960fbd059a0cdff41abe312f782d922375 65562120 chromium-shell_149.0.7827.114-1~deb13u1_i386.deb cf05f08e8ae7b4903689ac71ad345050a2aa91b7 30602 chromium_149.0.7827.114-1~deb13u1_i386-buildd.buildinfo c0f7043395f365ef8acde8361dcefcf79ab58978 78080860 chromium_149.0.7827.114-1~deb13u1_i386.deb Checksums-Sha256: 122377be1fc9c36753387185cf88f1c2c9598462df4bb85554f3db449b7c3c46 5319644 chromium-common-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 3ecbd0bf0c6b49bb966157af36d47bd3ce3e2a9e7d11bb0d4e48ab568928f59f 26225460 chromium-common_149.0.7827.114-1~deb13u1_i386.deb 86013397609fd17d0f18c62f4bbcb0002e49589966c4322d982169c747b3122f 36215616 chromium-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 7e113ca5d8635ee4196ba93a52590c051647e348eccfd0b03b497fd05407f7b6 8113656 chromium-driver_149.0.7827.114-1~deb13u1_i386.deb ea41116f88e5a19fcfc601d56340a861a5ce89c2798456eeeae19f0dc3e1ae0e 29803080 chromium-headless-shell-dbgsym_149.0.7827.114-1~deb13u1_i386.deb e1da5faa89a14ea075b844d9b4cf27d8e765fd7cfb12373c51f674de7fcbd634 59808880 chromium-headless-shell_149.0.7827.114-1~deb13u1_i386.deb ead350a623e308306f5d2888f5fc046bbe0c1d4cf2a35d151e275d0c720dd5ad 18992 chromium-sandbox-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 4f77e9b8a9c7df0f5a1930573451a410eca68175a4a9f74849ced05cf711d222 125616 chromium-sandbox_149.0.7827.114-1~deb13u1_i386.deb c360f0da18ea5850800fea6cf1a1813651259e67c79b9b9f8d275cea89c2e77f 32726152 chromium-shell-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 6b4bebe44d25b539446170c903300b99e0307b0dded47067bc1b4d9111311dc1 65562120 chromium-shell_149.0.7827.114-1~deb13u1_i386.deb 8f8bd995c2fb9f468f464dfe8c39b4307303b487bf285b4c5fb64563f7fb33da 30602 chromium_149.0.7827.114-1~deb13u1_i386-buildd.buildinfo 8c0a07ff574279616e258dc901a7563db56b6318ddee3bc1ffb030439d56234d 78080860 chromium_149.0.7827.114-1~deb13u1_i386.deb Files: 452ae15540dbafe478cf718b3fa768ca 5319644 debug optional chromium-common-dbgsym_149.0.7827.114-1~deb13u1_i386.deb e1269f886ab8bb7a6ca7d42ca32f85a2 26225460 web optional chromium-common_149.0.7827.114-1~deb13u1_i386.deb a26739ae98b45d83f067bb78ce106078 36215616 debug optional chromium-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 26a3f06b9a40516996522fe8615d8a06 8113656 web optional chromium-driver_149.0.7827.114-1~deb13u1_i386.deb 3d6d154302b91837aa138aa6f0fb78e4 29803080 debug optional chromium-headless-shell-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 0af38a35241478839626c7a0e14befbc 59808880 web optional chromium-headless-shell_149.0.7827.114-1~deb13u1_i386.deb e9392f92b5313037a72af0d629c0d31c 18992 debug optional chromium-sandbox-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 516b5cc98e72447dd43184f579de4f7a 125616 web optional chromium-sandbox_149.0.7827.114-1~deb13u1_i386.deb aa1196b0803eaab09efe9a03268c54cf 32726152 debug optional chromium-shell-dbgsym_149.0.7827.114-1~deb13u1_i386.deb 4069afd402705f8de1365537565812b6 65562120 web optional chromium-shell_149.0.7827.114-1~deb13u1_i386.deb 1bb280e9281ac9224b66f5927c778744 30602 web optional chromium_149.0.7827.114-1~deb13u1_i386-buildd.buildinfo 783482e406f3d54d8da5b7e98d185fa4 78080860 web optional chromium_149.0.7827.114-1~deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEb5EwsJvHBEjqIJYIbheoBegwXLIFAmotoRoACgkQbheoBegw XLK8zRAArjobhlO9mQXIvZ4WTfH9Oxvm4MqyppCDfBqvHm3eBKj/R7LF8M0Wdy1E fm0zRXP+jLI3aA575jJ/2RLXs5R/TfaO8KV5t8zoSH9Grf9HVjXZ/YfyNun8TKrR tnwZ9nELZt2exm8OzibdBHji7rMYhLdh/XOzHTGpH2hgr9CrWCFuxSPSbYYuPomy W4IciN72xsVtzuVAu/Mh3zpQVSxSXjPrwppEjtDjXJbRASVoTzOFo3B/0zW3RMr1 UMCM7HAdF2JqpO0XF9pjPD5ELkJzV4Dnj71SqKRhZgotXNl8swtTUYLjwXpN1byM 5ulR7A3B32O7ZN2Fa2cL3tMK1NkicP6VbsTXO3IslQr/aQvzjLc8TGZ5twtjNm36 rrSp4teJera/PLZOdNwPAO6Tl88ldP1iD2AddOJzdva8PSYbbhWyC4VoHbxeTzTb v8phOUCtg6EDi8uuzcnqfZZ5O9zoPXj4FZ35EVKKuxWI6tuN0JEUVD+5PnNzdICK lzuI45L09nC3RR5yy18PEP3k5t7WULot3O6UCTx2428dmUNGXr9JqmCpnSBLuxZX IbHEUcic0HE4KMGsO8REsMHevHwxzHjQCLuztdRm8uZ17E51helm3bsq143PkrEZ ocKO+4bUSwdtx/qYHS0Pn86eA9oYiiDHiFuVo4/X2AVj0cv2qVU= =k1+l -----END PGP SIGNATURE-----