-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 23 Mar 2026 21:26:56 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: amd64 Version: 146.0.7680.164-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (146.0.7680.164-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-4673: Heap buffer overflow in WebAudio. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-4674: Out of bounds read in CSS. Reported by Syn4pse. - CVE-2026-4675: Heap buffer overflow in WebGL. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-4676: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-4677: Out of bounds read in WebAudio. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-4678: Use after free in WebGPU. Reported by Google. - CVE-2026-4679: Integer overflow in Fonts. Reported by GF, Un3xploitable Of DeadSec. - CVE-2026-4680: Use after free in FedCM. Reported by Shaheen Fazim. Checksums-Sha1: 03f08cde2f7d5baa580b5a2214018f21525d03f6 5365832 chromium-common-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb afa49f9cc27685f9471388eed92b5eccb8ad010b 29245576 chromium-common_146.0.7680.164-1~deb12u1_amd64.deb b47a634927854b52213266cfffa81357ba148e66 35357076 chromium-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb e38d0f799b013bdef67e0a9481485a6d8c3aa83b 7445296 chromium-driver_146.0.7680.164-1~deb12u1_amd64.deb 80b799869635705aad8a247f62cb89c44d2e2dbf 29330952 chromium-headless-shell-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb a457a7b65857e92e854a8249e693fd98f958477c 56583844 chromium-headless-shell_146.0.7680.164-1~deb12u1_amd64.deb c30e7f3716d9a67a89f87a0bcc635f17c88586fb 19288 chromium-sandbox-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb 41ca9c5d47dfa3b16911cfbffe50592856364c14 113672 chromium-sandbox_146.0.7680.164-1~deb12u1_amd64.deb b526043aab3aa0218de124c2d0abb392283648b1 32112160 chromium-shell-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb 7c368430dd70ebfcd05484e2bb0dcae1b9f95aac 61624336 chromium-shell_146.0.7680.164-1~deb12u1_amd64.deb 6b77b54ec7e640964f2e6d75fcb797eb917606db 30422 chromium_146.0.7680.164-1~deb12u1_amd64-buildd.buildinfo 048fe7f9a816626aca58cf22efa0fad2089670fb 73002212 chromium_146.0.7680.164-1~deb12u1_amd64.deb Checksums-Sha256: 0df79adf1ff8af644e417acf7b5661cba865c4e7daff019c68c4e21db061049c 5365832 chromium-common-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb 4d1b7d9be64a116fcd419005a09d17dd61772ad0f1a3b04eb17321ff12a8d0d5 29245576 chromium-common_146.0.7680.164-1~deb12u1_amd64.deb c39d360fde634bad6bc24e07136267a924cbc6f8a07f47743920891c5f386558 35357076 chromium-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb a2b54c4520faeadf057880e8edaf9694e26c8e561a986fcd559235f9ad63aed7 7445296 chromium-driver_146.0.7680.164-1~deb12u1_amd64.deb 1a19e76cd3d8ae3a4828fc59be913d8ce365f8a8bfc060c2ea86021e7d4e5900 29330952 chromium-headless-shell-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb b40903206f9ad00f5f3cacf0f1327c1affcee2336e2a75f2710745d90648de02 56583844 chromium-headless-shell_146.0.7680.164-1~deb12u1_amd64.deb 619319a1579f3df4383d255acdbbf05afbac690522d7f728c55de67ea8077fed 19288 chromium-sandbox-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb 084321952ce026d56aa8bf375870e33442b5816e349f6d106a1039478d508322 113672 chromium-sandbox_146.0.7680.164-1~deb12u1_amd64.deb c44ffea5e55dddef311aeb4fd14caf47b27c94af1d8d150d3dc63d3eb7b3fc0c 32112160 chromium-shell-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb 6ec6d612350fa1044025dd6e84f26713448ffc13871adceaa960b04da017b93d 61624336 chromium-shell_146.0.7680.164-1~deb12u1_amd64.deb 94360c8499f1e2aed578c62f2308cd4848d81be9ca76328233bbfa5f3179fc6e 30422 chromium_146.0.7680.164-1~deb12u1_amd64-buildd.buildinfo a94eb589202a2c315e73cbc98a0111f0cb8f943c66af2155d2c7591ba9971a13 73002212 chromium_146.0.7680.164-1~deb12u1_amd64.deb Files: 9a4e605bd7d95379cdebd0cf6fe7a1d1 5365832 debug optional chromium-common-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb 27cd196cc0cd1bc431e1c13a1105d01f 29245576 web optional chromium-common_146.0.7680.164-1~deb12u1_amd64.deb 5e1b15a974d9a0816b8bd9bdd1306ecd 35357076 debug optional chromium-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb 90cfaa0960f4124b89a5197db3aaacd9 7445296 web optional chromium-driver_146.0.7680.164-1~deb12u1_amd64.deb 3e1144f579fe392104556c87c818fc76 29330952 debug optional chromium-headless-shell-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb 93915bbc1fc0bad53792c41e1458bd44 56583844 web optional chromium-headless-shell_146.0.7680.164-1~deb12u1_amd64.deb e02b647c932490ae0b4abfff40e9ff92 19288 debug optional chromium-sandbox-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb 7fc42fbdbb6af727cd265ff1664d8ac7 113672 web optional chromium-sandbox_146.0.7680.164-1~deb12u1_amd64.deb 23d4e4a33c6554f001274d4270f98081 32112160 debug optional chromium-shell-dbgsym_146.0.7680.164-1~deb12u1_amd64.deb 367edc515e3921df226856ed6a621f43 61624336 web optional chromium-shell_146.0.7680.164-1~deb12u1_amd64.deb 32c41e3849c809bcc898e27b35e7e593 30422 web optional chromium_146.0.7680.164-1~deb12u1_amd64-buildd.buildinfo 129add7b7a369773278a0ad6856a5ef1 73002212 web optional chromium_146.0.7680.164-1~deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmnDhpQACgkQTwt/65ON 6zdR9xAAv8GQj+qLWpQO6wn1siQUd0g9BAPgGcPp3eh1m8Jg0A3yap0+3kxi2vYX 4AaBuFp/W1hdLLBcUyWoR+JmR0Xhea2hdPR9wKc2UkDodGVE2BNKa/V7GrvhWDE/ DPzM46Xtjayy3Fg9vYOTsinM+0O7UkA6PKBzQvs0YNA08G137aP2w/Pm1Kt9Olxd ufNoXxP3DFRpznLPpcPNIr9AnkN0NeOaJ6rieHpbv5YdpzCuzOoib+AxS042BA6L 7txmTE8zgoYc9PnHj4P3Q48oS2/se9uuZUnHKFDWrD0Pgfpo+KEjPleELVvi0PPZ RuCgc5pz/e54Vq/8KwOdviG7+1J1LqdZGSG1669tXoLFT/n8+8wPBS20I/magAhR 3ytgOp7Syg4GWRHZbUpqHM7TLzMk16dGoY0Gy9PwQpiA0yi05MjXoMd2sHfYDKbF j/rFfPD+8PJdqH4lV9hUHYm+2U1srgPAJQYDMZvoMPKU67U0ucjpsGOiYh6KJ71q mNCPLtDB0/y8PZLVyUhHUE+LhRDfo+H96TaNn1VZqaddqwDBoejb+hAMPzuIJfc1 nHaeip+zbag0NujwfriJu6Dis08jNggDO+s/MhdNQukgFrAgVD5XwyWJ8HM96KcN Ps7WiLjyH9z95rxQoUbCq3hjZgxjmGmBIbjbw9y0SrsNrXvBalU= =pWmL -----END PGP SIGNATURE-----