-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Jun 2026 01:14:44 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 149.0.7827.155-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (149.0.7827.155-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12437: Use after free in WebShare. Reported by Google. - CVE-2026-12438: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12439: Use after free in Digital Credentials. Reported by Google. - CVE-2026-12440: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12441: Use after free in File Input. Reported by Google. - CVE-2026-12442: Use after free in Passwords. Reported by Google. - CVE-2026-12443: Use after free in Web Authentication. Reported by Google - CVE-2026-12444: Out of bounds read in Chromoting. Reported by Google. - CVE-2026-12445: Use after free in Extensions. Reported by Google. - CVE-2026-12446: Insufficient data validation in Passwords. Reported by Google. - CVE-2026-12447: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12448: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12449: Use after free in Chromoting. Reported by Google. - CVE-2026-12450: Inappropriate implementation in Media. Reported by Zhixin Tu. - CVE-2026-12451: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12452: Use after free in Downloads. Reported by Google. - CVE-2026-12453: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-12454: Race in Safe Browsing. Reported by Google. - CVE-2026-12455: Use after free in Tab Strip. Reported by Google. - CVE-2026-12456: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-12457: Insufficient data validation in Extensions. Reported by Google. - CVE-2026-12458: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-12459: Inappropriate implementation in Serial. Reported by Google. - CVE-2026-12460: Insufficient policy enforcement in File System Access. Reported by Google. - CVE-2026-12461: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-12462: Use after free in Media. Reported by Google. - CVE-2026-12463: Inappropriate implementation in Views. Reported by Google. - CVE-2026-12464: Use after free in Browser. Reported by Google. - CVE-2026-12465: Insufficient validation of untrusted input in Metrics. Reported by Google. - CVE-2026-12466: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12467: Use after free in Extensions. Reported by Google. - CVE-2026-12468: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-12469: Uninitialized Use in GPU. Reported by Google. Checksums-Sha1: 649193ade609179534a0b4ce6149a5c65bc4d181 5318468 chromium-common-dbgsym_149.0.7827.155-1~deb13u1_i386.deb 07f53dcd266fd5380ada57c8e4cfa5346b5e8e98 26226660 chromium-common_149.0.7827.155-1~deb13u1_i386.deb afb9a94f1e7f471a46d9dbd894900f3e7f72794e 36225888 chromium-dbgsym_149.0.7827.155-1~deb13u1_i386.deb ace0e66404eadf454e78b8a4e3623dbeffc98104 8115580 chromium-driver_149.0.7827.155-1~deb13u1_i386.deb f269f81f9faa7510aefb7aa69abef9dd61ca5698 29801240 chromium-headless-shell-dbgsym_149.0.7827.155-1~deb13u1_i386.deb 4c32ee56e2073b44f13a73178ca82b832710b3cb 59809556 chromium-headless-shell_149.0.7827.155-1~deb13u1_i386.deb a05c5991849a5219b876c1bee8b52375d6db0c6c 18984 chromium-sandbox-dbgsym_149.0.7827.155-1~deb13u1_i386.deb 0e3291438724cb6bfc377ca4253b96195f09c8a0 125848 chromium-sandbox_149.0.7827.155-1~deb13u1_i386.deb edc0b4576a06ffc3ca5ec6599c82c42d0f0635dc 32726164 chromium-shell-dbgsym_149.0.7827.155-1~deb13u1_i386.deb 9ea5bcdf0230857378631140c4fb387e00ca6dec 65566220 chromium-shell_149.0.7827.155-1~deb13u1_i386.deb 45edb860345faefd2fdc528323c9f5962bf0d4ff 30602 chromium_149.0.7827.155-1~deb13u1_i386-buildd.buildinfo 8a2be73b2c85736a886d31c3cbeda74854b62c88 78100260 chromium_149.0.7827.155-1~deb13u1_i386.deb Checksums-Sha256: 0bd3e7c5c1a5a4b0e6b0ce9f2ac327e722749dd7a5f926f62547eb74195ed3e3 5318468 chromium-common-dbgsym_149.0.7827.155-1~deb13u1_i386.deb 6224ac8a5d2ef12e7a0c58cc4978fa4b91b385476b27af89db92129cbe966ec6 26226660 chromium-common_149.0.7827.155-1~deb13u1_i386.deb 0160e7b60da5f08008b64183244e4fe167ac5fc5623234ae6662072d40ad274b 36225888 chromium-dbgsym_149.0.7827.155-1~deb13u1_i386.deb aa076720f594c91deac4d55957e916f6e37fff7ce58ee290b828a63b46812780 8115580 chromium-driver_149.0.7827.155-1~deb13u1_i386.deb 2efd61d0b5a5f7822f68cbeb31e9c8a1bdfceb22664ac989b3b8e8bdf769b0e5 29801240 chromium-headless-shell-dbgsym_149.0.7827.155-1~deb13u1_i386.deb 1b7a88b57da4c305118379a14abf2b0a265652958a6c915e49d2e7241a5bc96e 59809556 chromium-headless-shell_149.0.7827.155-1~deb13u1_i386.deb fdefa23fe61bee333e53c86f57eae3be9aebd8e74dbcf39e3ab1be89f545ae8d 18984 chromium-sandbox-dbgsym_149.0.7827.155-1~deb13u1_i386.deb b962ce8c1e2f894c4218c2447e08a92599ad9f6476b70216a374d57ae8428986 125848 chromium-sandbox_149.0.7827.155-1~deb13u1_i386.deb 913803b6feca695bbcd2cb0258990f52d0c840c20016844f2b619b95d71ab6f8 32726164 chromium-shell-dbgsym_149.0.7827.155-1~deb13u1_i386.deb 2c4d4ca94de8746dbc8913318187d94300315612cb9f1f4d71b527487d271194 65566220 chromium-shell_149.0.7827.155-1~deb13u1_i386.deb b8f5d1dd4a27c7c4d7d1b68b3c407f6395d9afaa4379ca4598903f50f779fc76 30602 chromium_149.0.7827.155-1~deb13u1_i386-buildd.buildinfo 4d46fe7bcd447a8ccbb41c0863b951588e2c293990d78ad4c8180f43ce2f5fe2 78100260 chromium_149.0.7827.155-1~deb13u1_i386.deb Files: 25c8239036f4dd66bfb6a3587030686f 5318468 debug optional chromium-common-dbgsym_149.0.7827.155-1~deb13u1_i386.deb 22ccbc367979f1f1ddc91f5626fe4cb9 26226660 web optional chromium-common_149.0.7827.155-1~deb13u1_i386.deb a9dff6089c9d4517287fb20f8a636fa0 36225888 debug optional chromium-dbgsym_149.0.7827.155-1~deb13u1_i386.deb cc99e2f953c2b415d132400eca88dc1f 8115580 web optional chromium-driver_149.0.7827.155-1~deb13u1_i386.deb c2df235a11ee5a96d868e589b6a3f08b 29801240 debug optional chromium-headless-shell-dbgsym_149.0.7827.155-1~deb13u1_i386.deb d6212082087446095a69da6f10f48811 59809556 web optional chromium-headless-shell_149.0.7827.155-1~deb13u1_i386.deb 36eabe998bf954e713f830e8eb0e468d 18984 debug optional chromium-sandbox-dbgsym_149.0.7827.155-1~deb13u1_i386.deb 5bbb686a5e66388c60ea6abbc1669873 125848 web optional chromium-sandbox_149.0.7827.155-1~deb13u1_i386.deb fad81613c2c981371bcfb6b524e7b4fc 32726164 debug optional chromium-shell-dbgsym_149.0.7827.155-1~deb13u1_i386.deb bb69cae61f07669211c77283874f95df 65566220 web optional chromium-shell_149.0.7827.155-1~deb13u1_i386.deb cb3de422ca1c519d146169dba1b9ab01 30602 web optional chromium_149.0.7827.155-1~deb13u1_i386-buildd.buildinfo f956a99761c0b555e449971994ba81da 78100260 web optional chromium_149.0.7827.155-1~deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEb5EwsJvHBEjqIJYIbheoBegwXLIFAmo0b34ACgkQbheoBegw XLJTQA/6A9l/ubzm5sCErDvVSET/EI6WM4q2+fw7njtQvvz/T3NsinzP0ahH7QkI jxzHfs1jefb61QLSdgiWVBuq43AXLKPyJ9wSQJyQxmyYN/W8X4ovPuSuyJ3/dAgV mxI5L55knLJRJZeERa3iZuedJGntM2SEW3J/M3zqmfsuy7DSkvOUK0YLTGgRlMZG bKvJdz7cufNRYCU1RXn1+tDArjiRFQ4Dm1MMOa9ek7Y8uYwvykalKcI6Rkn2UqoQ 0lBWymJUaKDJym/5zRwQI1tpTt/+1beFSdiEbV6H6Pv35WwXz9/HFssFVMoHrXNq ukd8yi/cKk0BmN7UISkZllcCkBcLYt2dAJe4fbR/7iesDNyGv/l126WX/2XTIvcj u8K4zx8GrFvGM5IKepJNKtmSkkr7NPVEUdY/1d+YrIRlQmIYEwa12uY2xIASdi4v 5icE0IJ+yrBLaeJMWwhDBYXK0jTGdIcMe5s9b5ud09OB9hPopRlP00mUKti6MvoS c3Sz06jCjyTQFhq8K4v/MrwRHICPnxT7vRLcp4cnU3h5tv9qmz9CGp+/OEZNvVjM /Jh4/GrmiCBjLKB9BWAhj1ORF89YnaKj5wDUVh/kjs2ZdBh0B/wmc7w4UGdPuEqH +ZzNasYAYGBGUU8WzV0L+Vf/13Uq+tASZLtJKQSjNVZdn9Ee0hw= =3tYx -----END PGP SIGNATURE-----