-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Jun 2026 01:14:44 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: arm64 Version: 149.0.7827.155-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm64 Build Daemon (arm-ubc-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (149.0.7827.155-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12437: Use after free in WebShare. Reported by Google. - CVE-2026-12438: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12439: Use after free in Digital Credentials. Reported by Google. - CVE-2026-12440: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12441: Use after free in File Input. Reported by Google. - CVE-2026-12442: Use after free in Passwords. Reported by Google. - CVE-2026-12443: Use after free in Web Authentication. Reported by Google - CVE-2026-12444: Out of bounds read in Chromoting. Reported by Google. - CVE-2026-12445: Use after free in Extensions. Reported by Google. - CVE-2026-12446: Insufficient data validation in Passwords. Reported by Google. - CVE-2026-12447: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12448: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12449: Use after free in Chromoting. Reported by Google. - CVE-2026-12450: Inappropriate implementation in Media. Reported by Zhixin Tu. - CVE-2026-12451: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12452: Use after free in Downloads. Reported by Google. - CVE-2026-12453: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-12454: Race in Safe Browsing. Reported by Google. - CVE-2026-12455: Use after free in Tab Strip. Reported by Google. - CVE-2026-12456: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-12457: Insufficient data validation in Extensions. Reported by Google. - CVE-2026-12458: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-12459: Inappropriate implementation in Serial. Reported by Google. - CVE-2026-12460: Insufficient policy enforcement in File System Access. Reported by Google. - CVE-2026-12461: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-12462: Use after free in Media. Reported by Google. - CVE-2026-12463: Inappropriate implementation in Views. Reported by Google. - CVE-2026-12464: Use after free in Browser. Reported by Google. - CVE-2026-12465: Insufficient validation of untrusted input in Metrics. Reported by Google. - CVE-2026-12466: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12467: Use after free in Extensions. Reported by Google. - CVE-2026-12468: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-12469: Uninitialized Use in GPU. Reported by Google. Checksums-Sha1: 6a481d85bb6e21412b40438cd5833ff39f525566 6468588 chromium-common-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb a5689390678081d7ff3bde45798b75e7c6eb5b09 30961740 chromium-common_149.0.7827.155-1~deb12u1_arm64.deb 66d68dd5aee7cd485eec110fb4b5e52b6717787f 37836560 chromium-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb 8a9446ab376c50a0655c294e49c11f65d68a4afc 6921348 chromium-driver_149.0.7827.155-1~deb12u1_arm64.deb 14fe33ffbfd5b691c71f19583938ae13d2cadf6d 30670192 chromium-headless-shell-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb 615ef697a020a5fbda65d19dbce9e4947556ab52 51561944 chromium-headless-shell_149.0.7827.155-1~deb12u1_arm64.deb f068626bfea53cbaf71b5e66275dd4f4fd2f26fd 20256 chromium-sandbox-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb f0535b94110d2742dc7f2dca65028cf189189899 128716 chromium-sandbox_149.0.7827.155-1~deb12u1_arm64.deb 992832fa00878e1511c6bd2fbd120a4f29385bb8 33138536 chromium-shell-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb d849ca304f6eb6b9adc08d434f368dc7805f61a7 56473264 chromium-shell_149.0.7827.155-1~deb12u1_arm64.deb f2f5dc58d6919cb1f5627a93a9d32e4a280341f0 30477 chromium_149.0.7827.155-1~deb12u1_arm64-buildd.buildinfo 1effb7b3307186591ccff3a03f292935a342c5b2 65747740 chromium_149.0.7827.155-1~deb12u1_arm64.deb Checksums-Sha256: 7c15b6f459118681d3e4185ac335d923cdbff32380dc65505798edc3df7fe606 6468588 chromium-common-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb 62ef26c4aa49c9371712acf8cd7a9aa3d9882d94017cd72a0336d930439cda42 30961740 chromium-common_149.0.7827.155-1~deb12u1_arm64.deb 7f00295e16adde99704ae3cdc3dec87ec8b6839084aa402b0c28560272e2c43f 37836560 chromium-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb a42f2058d6238b8d4cc5584de51fc59d3d76ffd9517095547998ea93d326f08d 6921348 chromium-driver_149.0.7827.155-1~deb12u1_arm64.deb e889b4357bb7f40d422acd81cddbdfa872b23e02075729cf9261451cf741a178 30670192 chromium-headless-shell-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb 7fc57cd0e454b63b9ca214ba2621c595ae6012c14d3bc24f50be84fdd783243c 51561944 chromium-headless-shell_149.0.7827.155-1~deb12u1_arm64.deb 076492ca7fc2fe2cfb281e163166ede4caa3d1fb1213443fb42a984a3e8df802 20256 chromium-sandbox-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb 4ef389c4b061a568b1b5dade60a26d1e36974ca9389519f603a31e81388703e8 128716 chromium-sandbox_149.0.7827.155-1~deb12u1_arm64.deb f58bbb4fcfd445b80aa07605f2528f01394ecacfc8f9112eef8a8bda5dd9d2c3 33138536 chromium-shell-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb 198cd084e567416c4192cf84760ddf7f11c3868fd0c437215fe424684baa2a61 56473264 chromium-shell_149.0.7827.155-1~deb12u1_arm64.deb 73735ce127ddea55f2cadbe5ece527b0ffcea977b7ca2858459244f53fcbe406 30477 chromium_149.0.7827.155-1~deb12u1_arm64-buildd.buildinfo dcdf330fdceee4dc37904774791873f7b3ec206eda1e6b35ea989a9f06840176 65747740 chromium_149.0.7827.155-1~deb12u1_arm64.deb Files: c7b9a37849223c49990e4c7c1ff4db36 6468588 debug optional chromium-common-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb 5580edb34397126be2f1ba0308002d4e 30961740 web optional chromium-common_149.0.7827.155-1~deb12u1_arm64.deb d9f1e59d3e2d98ddbc25f8a14f13a352 37836560 debug optional chromium-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb e2c336e989c3cf0321e265507d011a22 6921348 web optional chromium-driver_149.0.7827.155-1~deb12u1_arm64.deb e8306f405f2e22f3ff8b7a4fd03c1f3c 30670192 debug optional chromium-headless-shell-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb 781d2a192d00307c22e0b714f4a1d1fb 51561944 web optional chromium-headless-shell_149.0.7827.155-1~deb12u1_arm64.deb ce12265255bae0364420e47e50394f1d 20256 debug optional chromium-sandbox-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb c146431e39589f34745a6d3bbc00d159 128716 web optional chromium-sandbox_149.0.7827.155-1~deb12u1_arm64.deb 57e84bc1bb3a1af8a5765b52a3d68980 33138536 debug optional chromium-shell-dbgsym_149.0.7827.155-1~deb12u1_arm64.deb 3cbd6c71aa7ab15282cabe7d78349298 56473264 web optional chromium-shell_149.0.7827.155-1~deb12u1_arm64.deb b7e7014f684d9144c2e29a62c691cdda 30477 web optional chromium_149.0.7827.155-1~deb12u1_arm64-buildd.buildinfo fbe2930fd94627ba556d518ca9bcdbe0 65747740 web optional chromium_149.0.7827.155-1~deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0Ha//LlsGOpbQ/H4xqCFmsOWgoYFAmo0gikACgkQxqCFmsOW gobK1w/+KTnPtp0dUGHNSQN0XkuZtN4inRAe/a8RAABP7eRVfD271zuAJa8v6k+I nLPMyKCuyyp8yzyPPt82Rm4FnrB2z+sZPzAeM0944kjvK5MmhIOnXBrtHLtAt7Fl 3iMkfqYgRAoBFGwYwoGDOxs0qqIZS1uKWRbS7izs31dJWicULqRj81F6jmqw6d/R TaCxeIt0vXTdAZx4rRNCPBe5oYmOKu0Zqm2fA54QAVPCArApSNfu8Cux5zvJkcZD 0LziiOeg5N2lrELh5HEQxTl5le/ipiif5oDQRYjk6XfzS3J/ZsPRJ51hUcOmrl4m uYL5gBa/3Td4EO0YJs50rxSOXbymiBX65GbfACOVyS3eOWF3qQgOSiEOVwIIdQsl yyWusj/b94klBjCN4E6hhsAc5nirRCxZtLI/OlbKRRFJqcsE5r8bDzylbDGGAZAX UZudjfpwGyZpuykP4ndoag7RxiqRVmICtAMGWOqkjfgFX+w3G+My13keCK/+xYZl 8Mi/7lTjPLCsBj2JWk+sLJR2GDSs+m2SmN1W2TCk0LB5kAW1kYQprNZrbzr+RMxO AF9/zSZW4Q5m36OZYxCW/SXSszpvb3t2OXA/A9KKyR98o+q7+GFXD9fO9FH4BWOX woIJmJUPvDAxLi3fflKiweezoCOCaaYawZfPKFj2KWLL78CsK4E= =vEGi -----END PGP SIGNATURE-----