-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 15:06:40 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 147.0.7727.101-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (147.0.7727.101-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-6296: Heap buffer overflow in ANGLE. Reported by cinzinga. - CVE-2026-6297: Use after free in Proxy. Reported by heapracer. - CVE-2026-6298: Heap buffer overflow in Skia. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6299: Use after free in Prerender. Reported by Google. - CVE-2026-6358: Use after free in XR. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-6359: Use after free in Video. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6300: Use after free in CSS. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-6301: Type Confusion in Turbofan. Reported by qymag1c. - CVE-2026-6302: Use after free in Video. Reported by Syn4pse. - CVE-2026-6303: Use after free in Codecs. Reported by Google. - CVE-2026-6304: Use after free in Graphite. Reported by Google. - CVE-2026-6305: Heap buffer overflow in PDFium. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6306: Heap buffer overflow in PDFium. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6307: Type Confusion in Turbofan. Reported by Project WhatForLunch (@pjwhatforlunch). - CVE-2026-6308: Out of bounds read in Media. Reported by Google. - CVE-2026-6309: Use after free in Viz. Reported by Google. - CVE-2026-6360: Use after free in FileSystem. Reported by asjidkalam. - CVE-2026-6310: Use after free in Dawn. Reported by Google. - CVE-2026-6311: Uninitialized Use in Accessibility. Reported by Google. - CVE-2026-6312: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-6313: Insufficient policy enforcement in CORS. Reported by Google. - CVE-2026-6314: Out of bounds write in GPU. Reported by Google. - CVE-2026-6315: Use after free in Permissions. Reported by Google. - CVE-2026-6316: Use after free in Forms. Reported by Google. - CVE-2026-6361: Heap buffer overflow in PDFium. Reported by Google. - CVE-2026-6362: Use after free in Codecs. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-6317: Use after free in Cast. Reported by Google. - CVE-2026-6363: Type Confusion in V8. Reported by Google. - CVE-2026-6318: Use after free in Codecs. Reported by Syn4pse. - CVE-2026-6319: Use after free in Payments. Reported by pwn2addr. - CVE-2026-6364: Out of bounds read in Skia. Reported by Google Threat Intelligence. Checksums-Sha1: 77108785477d52dc368e5b534927a3102eb0d5c1 5308980 chromium-common-dbgsym_147.0.7727.101-1~deb13u1_i386.deb ed632f4b12018a4fea315dcb51e6ef60cabc837a 25354276 chromium-common_147.0.7727.101-1~deb13u1_i386.deb cb253ca5eebbed35f81f5a1c5bac77522a80f354 35914208 chromium-dbgsym_147.0.7727.101-1~deb13u1_i386.deb 9de29e24d7278ee68ed01e7535fd97a0a8bd2644 7872112 chromium-driver_147.0.7727.101-1~deb13u1_i386.deb faa8a69a83f6ba023c8c357617dd293666ac6931 29668628 chromium-headless-shell-dbgsym_147.0.7727.101-1~deb13u1_i386.deb 2ecd34d4551e58659573912f38de3cbaf3dcb44d 58720272 chromium-headless-shell_147.0.7727.101-1~deb13u1_i386.deb 70cfaed82583b70bb8c2e034370da94e752fee50 18984 chromium-sandbox-dbgsym_147.0.7727.101-1~deb13u1_i386.deb da4f4415ea9976fb8f352aebfdd00e7f351c5c31 113808 chromium-sandbox_147.0.7727.101-1~deb13u1_i386.deb 1ab745335410ba7d13a595cdb1d4bc7c23666e4f 32487636 chromium-shell-dbgsym_147.0.7727.101-1~deb13u1_i386.deb d1ee072614d2724bd05c5a13e5955768465e3d78 64097368 chromium-shell_147.0.7727.101-1~deb13u1_i386.deb 2dc1f9812ee925bb750b26fd96e33b709c2aeba2 30359 chromium_147.0.7727.101-1~deb13u1_i386-buildd.buildinfo b22f7cc9a6d0e2ab3afb9de4ba4c18e438b90b28 76837024 chromium_147.0.7727.101-1~deb13u1_i386.deb Checksums-Sha256: 6a21762b0ff3f823618f60d8eed3403419d513d849995cd38109b3e4b63867fd 5308980 chromium-common-dbgsym_147.0.7727.101-1~deb13u1_i386.deb 49dd9af255656b3f9581412766262677c47eb41061ef57de9a509e7b5def91f1 25354276 chromium-common_147.0.7727.101-1~deb13u1_i386.deb ed8660f64d59b21b6ff1d9c78637bd3c0fa25f687304c9f8c8e4a1186e5e386c 35914208 chromium-dbgsym_147.0.7727.101-1~deb13u1_i386.deb 5844cee1e01cbe53ce16ccc9cdb175581f61cc6c2f7890c30f9c445f547a09d1 7872112 chromium-driver_147.0.7727.101-1~deb13u1_i386.deb 0cd16e3762a316187b8c49cf482d06b59a5baa191fe73478e11debfed95899b8 29668628 chromium-headless-shell-dbgsym_147.0.7727.101-1~deb13u1_i386.deb ed3ffc46670be8fc7d400b8294dcd73896f862c9ed8f723d55e801c16763eeaa 58720272 chromium-headless-shell_147.0.7727.101-1~deb13u1_i386.deb 23e60c15f6a0c89900fcbbf62ef50e273e4b12d8e4c69e719beb7546987f675f 18984 chromium-sandbox-dbgsym_147.0.7727.101-1~deb13u1_i386.deb abecf054de7722088e86b9ad1afc5247113783edfb7a6b241e2456e69f8c55c0 113808 chromium-sandbox_147.0.7727.101-1~deb13u1_i386.deb d7a8167486689f22503e983f17ab88ce6683c758673d65c3eb4f01e2d627b914 32487636 chromium-shell-dbgsym_147.0.7727.101-1~deb13u1_i386.deb 18c6ae824bdb40188b10687826ff437c37d56a0288d003812dd4f3be4736b6ae 64097368 chromium-shell_147.0.7727.101-1~deb13u1_i386.deb d993fb3ccde9919f430b609001302a551929a97ab0b2a5e52dc82a2c9a41b3fc 30359 chromium_147.0.7727.101-1~deb13u1_i386-buildd.buildinfo 6a49ba85b17ebe4f48fdbe1c274e9945e09e1f6806642ccd4278764d1ed09e77 76837024 chromium_147.0.7727.101-1~deb13u1_i386.deb Files: 0dcb4285378683a662aa52fed946afb1 5308980 debug optional chromium-common-dbgsym_147.0.7727.101-1~deb13u1_i386.deb e687f8ffa5f28e9299ee42a7a80152f7 25354276 web optional chromium-common_147.0.7727.101-1~deb13u1_i386.deb 5aec955304fb75244bd001927cf575d4 35914208 debug optional chromium-dbgsym_147.0.7727.101-1~deb13u1_i386.deb 6561d1ce6831ff736f51e3b91d34e83d 7872112 web optional chromium-driver_147.0.7727.101-1~deb13u1_i386.deb f3e157b19fbbfc1d8799d3f4e5fbc8d3 29668628 debug optional chromium-headless-shell-dbgsym_147.0.7727.101-1~deb13u1_i386.deb 16303da3420ce84b3cca7011da8b5c91 58720272 web optional chromium-headless-shell_147.0.7727.101-1~deb13u1_i386.deb 516dc06bb912d48b2ef87524639db093 18984 debug optional chromium-sandbox-dbgsym_147.0.7727.101-1~deb13u1_i386.deb 2b179d398297c132f6baa4c2f1a2ea69 113808 web optional chromium-sandbox_147.0.7727.101-1~deb13u1_i386.deb cad4cb0d9b210a7a07468a38923342c5 32487636 debug optional chromium-shell-dbgsym_147.0.7727.101-1~deb13u1_i386.deb 93cbb212bad86d8b8bc10903070c4da2 64097368 web optional chromium-shell_147.0.7727.101-1~deb13u1_i386.deb 9fefaf2f8618e7a229f5927784c5630f 30359 web optional chromium_147.0.7727.101-1~deb13u1_i386-buildd.buildinfo 8f3b338a7bfa9be0fa777187a14399ce 76837024 web optional chromium_147.0.7727.101-1~deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmnhkNoACgkQTwt/65ON 6zde7Q/+OkWEQ5q3Ux847ObCl0eWTnLqT5aafiS/okgniof8P2bJCjBxQJNhe051 DzX+5aCMYSXSOD1Xav5vVAoF0pdkhposDIXAxdEXQz8ZIufII+uhE+V6SiKJ9DXX 339ODBk7hhYjkod4tn2z2lNPT6GL2iDkPP/Z6S1+TEzN2We8hjjJ4zdAE8X6+Y9O bZDApLHyjPtoig4AMoFFdLtvngq5bDrLi825dABte1biFAG5l4ZFR9RFIDqfe0by in7N19h8ViEF8HVpW6E6H/xnf7HDBQcfKx2o+GFVVO4SU/gwm+kDAzpoyZJrxbdQ mZgfdpHScRYpXt6z6veu+1NvdkZpZWnoSD67mx1cqrHgs43D+qOczOyVSwsRgPSX Q+17uDpv1SXEjjr7KNY3lTos++VHxR+Y9m7SIu7bjPDYWlY0RtitApi8Sb9JJFtH eLwS4+AHjZjb9YDMAfO42GAl55cVQhEfpMDJIF15/WXOpw4z2VxurCTFVtUAH8A/ oV03X5ZG/0gE20yb2KX6BjNY0KEdZQSxTOqhE2/XpqBXtyt0HbV9iNfcQT5qj7/q YlYCrc2Vj3lM1isQ7tqOlFzjZdJuWHouM36AOOGCwJec+SiBNhz2uitjeqnRDUfc h4QNrz7f6R0tBDd8DJwORq1S+YRW8xa54YzgbRSbXRlZClOr9R0= =PdzO -----END PGP SIGNATURE-----