-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 15:06:40 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: arm64 Version: 147.0.7727.101-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (147.0.7727.101-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-6296: Heap buffer overflow in ANGLE. Reported by cinzinga. - CVE-2026-6297: Use after free in Proxy. Reported by heapracer. - CVE-2026-6298: Heap buffer overflow in Skia. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6299: Use after free in Prerender. Reported by Google. - CVE-2026-6358: Use after free in XR. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-6359: Use after free in Video. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6300: Use after free in CSS. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-6301: Type Confusion in Turbofan. Reported by qymag1c. - CVE-2026-6302: Use after free in Video. Reported by Syn4pse. - CVE-2026-6303: Use after free in Codecs. Reported by Google. - CVE-2026-6304: Use after free in Graphite. Reported by Google. - CVE-2026-6305: Heap buffer overflow in PDFium. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6306: Heap buffer overflow in PDFium. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6307: Type Confusion in Turbofan. Reported by Project WhatForLunch (@pjwhatforlunch). - CVE-2026-6308: Out of bounds read in Media. Reported by Google. - CVE-2026-6309: Use after free in Viz. Reported by Google. - CVE-2026-6360: Use after free in FileSystem. Reported by asjidkalam. - CVE-2026-6310: Use after free in Dawn. Reported by Google. - CVE-2026-6311: Uninitialized Use in Accessibility. Reported by Google. - CVE-2026-6312: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-6313: Insufficient policy enforcement in CORS. Reported by Google. - CVE-2026-6314: Out of bounds write in GPU. Reported by Google. - CVE-2026-6315: Use after free in Permissions. Reported by Google. - CVE-2026-6316: Use after free in Forms. Reported by Google. - CVE-2026-6361: Heap buffer overflow in PDFium. Reported by Google. - CVE-2026-6362: Use after free in Codecs. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-6317: Use after free in Cast. Reported by Google. - CVE-2026-6363: Type Confusion in V8. Reported by Google. - CVE-2026-6318: Use after free in Codecs. Reported by Syn4pse. - CVE-2026-6319: Use after free in Payments. Reported by pwn2addr. - CVE-2026-6364: Out of bounds read in Skia. Reported by Google Threat Intelligence. Checksums-Sha1: bef5289b92b633ba756a8a45caf5926e0bc05120 6098672 chromium-common-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 5e1a4463a1c8105cc46730730c93e22d0138320b 29936948 chromium-common_147.0.7727.101-1~deb13u1_arm64.deb 4c98c3c5b6dffdc23a878b4d25698e2d6f740599 33792312 chromium-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 9cb071cef633da3f89aa43b821299c6842a9c179 6614740 chromium-driver_147.0.7727.101-1~deb13u1_arm64.deb fedb2190dfe9976fcba3e7099608d2fbe69f2c5f 28062484 chromium-headless-shell-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 761ab223c7aec5810341988f6101c45b2ab2eabf 54246696 chromium-headless-shell_147.0.7727.101-1~deb13u1_arm64.deb badb9ebd9fb0a93db295c24f652cd8f302064a49 21092 chromium-sandbox-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 0d30b2d6364a619aeba9597590972abec172ad35 114756 chromium-sandbox_147.0.7727.101-1~deb13u1_arm64.deb 614a8b31cc9b38391463d23c7da3eb62e3c7e231 29445596 chromium-shell-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 12b93c3c9e424bfe7301159b11c2962071834a80 53912700 chromium-shell_147.0.7727.101-1~deb13u1_arm64.deb 1a912ee9e4b06b14cd16b0a4bd36046c0e76fa2d 30406 chromium_147.0.7727.101-1~deb13u1_arm64-buildd.buildinfo 000872d75f2dfc417066fadf66825cd3204debd9 72529868 chromium_147.0.7727.101-1~deb13u1_arm64.deb Checksums-Sha256: 7f8318cd19d4b8949514274372f1a9ff2a4c33917efa9291ba18f3a337358a9b 6098672 chromium-common-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 10a0fdf63a9a4cb185f10ee97b8651eb35ae5706cf0f8a064b68a3880e1b76c5 29936948 chromium-common_147.0.7727.101-1~deb13u1_arm64.deb 7813bab0797a90384fde419cc5aa1b7990452dac88a6f92a841280167ddc8a12 33792312 chromium-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 516b64c9d114e940df0b9e4de8d2a376773ddcd754475d624bab493043104f48 6614740 chromium-driver_147.0.7727.101-1~deb13u1_arm64.deb 7c6ac3d06ae0e7b0f63b1c1a9c844bb57bc6cd267549e038026140c53f06de13 28062484 chromium-headless-shell-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 8fdf45f364ea67c75946d62b5e8766052a56a3c270c6660deb951f441feb2a67 54246696 chromium-headless-shell_147.0.7727.101-1~deb13u1_arm64.deb 250639cc444fdb25e7583618c8a08ceae8f474e0ca538b7bb7577095e6d3cec5 21092 chromium-sandbox-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 6a0f31cabf6e14513cc116d1b5729aedf8a6a8d719d45c54d506a9f13eb7fe7e 114756 chromium-sandbox_147.0.7727.101-1~deb13u1_arm64.deb a5d8ca83013dc7117c94755a03bd6e3bd1254f91c9db0b6257561b6a81fe310b 29445596 chromium-shell-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb f2a3b9124865ad4bee403642e1eeec5d56aa5c73271d9b11f47d90a235ad19b1 53912700 chromium-shell_147.0.7727.101-1~deb13u1_arm64.deb f6bf6cb0ccd045e4f65c2a20e50f9097ff280cbbc5ad72c848890df3fa994aa2 30406 chromium_147.0.7727.101-1~deb13u1_arm64-buildd.buildinfo 0c065c6a733bc38b694e08048ebd9af41804883451dacd70bbdc7f1b7466e16d 72529868 chromium_147.0.7727.101-1~deb13u1_arm64.deb Files: 067cc98ce10e4799d6b7a056139d941f 6098672 debug optional chromium-common-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 0d3efb08a97d1d125bea610ef79e7bbb 29936948 web optional chromium-common_147.0.7727.101-1~deb13u1_arm64.deb 5ade3e7b27ddb4228fdcb7c173708e8c 33792312 debug optional chromium-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 643c208905941cb30829cd04abd8e39f 6614740 web optional chromium-driver_147.0.7727.101-1~deb13u1_arm64.deb abc29d2bb218294046067cb402b0ed8e 28062484 debug optional chromium-headless-shell-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 9ed46a3b0dcf4761ec2db67ee7637213 54246696 web optional chromium-headless-shell_147.0.7727.101-1~deb13u1_arm64.deb 05b04798e1ef6d578d3a654a2ba8b033 21092 debug optional chromium-sandbox-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 5d2b266f9132a7c38d8772a976561d3b 114756 web optional chromium-sandbox_147.0.7727.101-1~deb13u1_arm64.deb e0b2972ee3abbecfce88d470f49205f2 29445596 debug optional chromium-shell-dbgsym_147.0.7727.101-1~deb13u1_arm64.deb 61f54e7650f3f873ed722bab5581b64c 53912700 web optional chromium-shell_147.0.7727.101-1~deb13u1_arm64.deb fdec0a22bc891a79248dad249eacf7ec 30406 web optional chromium_147.0.7727.101-1~deb13u1_arm64-buildd.buildinfo c6dfea81d917d63d25954006a978d88f 72529868 web optional chromium_147.0.7727.101-1~deb13u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0Ha//LlsGOpbQ/H4xqCFmsOWgoYFAmnh4pUACgkQxqCFmsOW goZpyA/+L8gApG26PxThhprULhpNOIgdpTpvBvr6TrE9YA/uPbPCRTxGjtvUA/nF 3J+HhJ+gUbCEwu9qMXNrilxFKc/GLB3+TWkgWK+byPb/2ZLyr5teTu8c6POyejTa iZRRTtxh8/xEBWCAzIcAyy3OB+9ZxoiNIMWAhrbPa/4YubLvuVM0ydG08kALWs2G sR9auqEN3v6bveE8KxhOJf8ms3va1HK3HkR5SSCm+/o4oUPWsK9WuNf+fkUww9u7 C1iw+pbVA3r2LzUyIDe+dV+DO5YPaQosaL/GutkFpVsisxrtTdZkxrhuzwMS1YL3 VjD6RE9D/EMTPwc0jNLF25PBXr6UDhbF2aM0okbqWfZMyYA4sme1XzCVSOb+A7ku 2CInDHBb7++/J5/YequPoa/Rl+P+CeLh0RzsWeBDUNtIqvJq5IO4t4RHE2hiFEyt 9TUNt9KNoQmY92lGaZ5bohX+E+3JoXuraQDvDNKxQWD6B49ZO+jUhGGyvEUS3VTB LpGSkOp36RTnqSBEeCU/e9xXo3KXtaF8jkY8L8D35qWCBxAKHteqRttkUT5AK5Xq WXkaeHnCT9tr55B/uujdx7yG2jEH/kb9gkHlwYG8moJZZ6TqV6L7OyH9f5NXqkv+ tY0kqOp70AbYWS7YfgnpXXmDrTK7jKF/5axPjZgjfRzBsHZd3M4= =FDv1 -----END PGP SIGNATURE-----