-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 15 Apr 2026 15:06:40 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: amd64 Version: 147.0.7727.101-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (147.0.7727.101-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-6296: Heap buffer overflow in ANGLE. Reported by cinzinga. - CVE-2026-6297: Use after free in Proxy. Reported by heapracer. - CVE-2026-6298: Heap buffer overflow in Skia. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6299: Use after free in Prerender. Reported by Google. - CVE-2026-6358: Use after free in XR. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-6359: Use after free in Video. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6300: Use after free in CSS. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-6301: Type Confusion in Turbofan. Reported by qymag1c. - CVE-2026-6302: Use after free in Video. Reported by Syn4pse. - CVE-2026-6303: Use after free in Codecs. Reported by Google. - CVE-2026-6304: Use after free in Graphite. Reported by Google. - CVE-2026-6305: Heap buffer overflow in PDFium. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6306: Heap buffer overflow in PDFium. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-6307: Type Confusion in Turbofan. Reported by Project WhatForLunch (@pjwhatforlunch). - CVE-2026-6308: Out of bounds read in Media. Reported by Google. - CVE-2026-6309: Use after free in Viz. Reported by Google. - CVE-2026-6360: Use after free in FileSystem. Reported by asjidkalam. - CVE-2026-6310: Use after free in Dawn. Reported by Google. - CVE-2026-6311: Uninitialized Use in Accessibility. Reported by Google. - CVE-2026-6312: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-6313: Insufficient policy enforcement in CORS. Reported by Google. - CVE-2026-6314: Out of bounds write in GPU. Reported by Google. - CVE-2026-6315: Use after free in Permissions. Reported by Google. - CVE-2026-6316: Use after free in Forms. Reported by Google. - CVE-2026-6361: Heap buffer overflow in PDFium. Reported by Google. - CVE-2026-6362: Use after free in Codecs. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-6317: Use after free in Cast. Reported by Google. - CVE-2026-6363: Type Confusion in V8. Reported by Google. - CVE-2026-6318: Use after free in Codecs. Reported by Syn4pse. - CVE-2026-6319: Use after free in Payments. Reported by pwn2addr. - CVE-2026-6364: Out of bounds read in Skia. Reported by Google Threat Intelligence. Checksums-Sha1: 99086e58f3db2665cf373d53ac107f3d6ab169a2 5143952 chromium-common-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb ae0dcf78002335548582a7f015f3ab23b73fa079 25403636 chromium-common_147.0.7727.101-1~deb13u1_amd64.deb 57613452a5b24e691112523c8dbc024b0f9ff42d 33116788 chromium-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb ae9e70d77b9235c78eca04d4fbe4151bb07a0a1d 7463132 chromium-driver_147.0.7727.101-1~deb13u1_amd64.deb 97920fa0c89af93011ffc399c2f47538477e20cc 28041720 chromium-headless-shell-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb b76ba40183789071a7790b899a15a8510ee9e344 62266516 chromium-headless-shell_147.0.7727.101-1~deb13u1_amd64.deb 703c67c4069f0e58e8d169103545f15762cc7469 20208 chromium-sandbox-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb fd2ac8dd96d9f853adfc25c7b57a2149cf4b1541 113924 chromium-sandbox_147.0.7727.101-1~deb13u1_amd64.deb 0fb4a44bcb4e9a8d99d63d966af0bf6d97baec64 29562464 chromium-shell-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb ffeac109b4107cb654d57ee1860caf60c2b14fab 61697096 chromium-shell_147.0.7727.101-1~deb13u1_amd64.deb cbf7917a8db1c7755746e3ef781a6c84e7df09da 30437 chromium_147.0.7727.101-1~deb13u1_amd64-buildd.buildinfo 0a3059d5b515dfef2f62a165b4beeab20187ae35 84358428 chromium_147.0.7727.101-1~deb13u1_amd64.deb Checksums-Sha256: aeaedcf8151a9a76b4ddbe6ad65f66197286dbbb067fe1844a19222d8a03f127 5143952 chromium-common-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb d58664b2c51d1a8d87a5c0c05c998677713cfdc09a14c11d97132e30a54b0bc0 25403636 chromium-common_147.0.7727.101-1~deb13u1_amd64.deb 27ac7fe7c7ba7bae211e564c653a93e468a5e16148e1a9d2c544a086af362925 33116788 chromium-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb a781e893687c95a61160bbd35e5d9e32491e42fc7c35369384de2386e564b7d9 7463132 chromium-driver_147.0.7727.101-1~deb13u1_amd64.deb fd3fc9dce83ecffd1985d48228bc4c0b6a23c83884b1b953368de02ff899e496 28041720 chromium-headless-shell-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb ffdbb2701ad0f07b7db609b108460f9535f0c0a9ec329af16626d4640c398dca 62266516 chromium-headless-shell_147.0.7727.101-1~deb13u1_amd64.deb 81d0efc1fb821b6cd9b42aab3672612c02e2c0eb860d0674c97e40e740f750c5 20208 chromium-sandbox-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb f673bee67429aef80d3837530865b58c427c33ab2990ff1d08dc5ccca9de5be6 113924 chromium-sandbox_147.0.7727.101-1~deb13u1_amd64.deb c8d82a3f557f3f325dc34a1f6081d2a3c504676c6cfb7cad8cf4b90175d28518 29562464 chromium-shell-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb ce2937e6303cc41de2ff385624141ff7cca6ca60cfcc60d3113648d1878ffedd 61697096 chromium-shell_147.0.7727.101-1~deb13u1_amd64.deb b51d8b25d2b794202399666b1c294a42a481e60a2a6e4e3e756925a8369b0055 30437 chromium_147.0.7727.101-1~deb13u1_amd64-buildd.buildinfo a656e4859b917b707b8672ac1d4616a463e078c3b0ec76afc25b05312837fa49 84358428 chromium_147.0.7727.101-1~deb13u1_amd64.deb Files: 9018657040c794bbc869fa7d760fc656 5143952 debug optional chromium-common-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb e4f395ec311eed1dd7fdfc1222c97ca7 25403636 web optional chromium-common_147.0.7727.101-1~deb13u1_amd64.deb c7132b839782ba04116ba27faa86c35e 33116788 debug optional chromium-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb 9c54582eea97fd9cdde5533976156ea4 7463132 web optional chromium-driver_147.0.7727.101-1~deb13u1_amd64.deb e8a7f59aa64d799faee010e3843ea616 28041720 debug optional chromium-headless-shell-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb 36b7811e7e709f0535bf151a57b26ffc 62266516 web optional chromium-headless-shell_147.0.7727.101-1~deb13u1_amd64.deb 6bf9f953cc11c534fad579c3f629b643 20208 debug optional chromium-sandbox-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb 35ef3ecebdba32a6a684dbb719c7f9f0 113924 web optional chromium-sandbox_147.0.7727.101-1~deb13u1_amd64.deb 99815758bdb6ed8241e9c08a094e49c5 29562464 debug optional chromium-shell-dbgsym_147.0.7727.101-1~deb13u1_amd64.deb 4d0d54bd2feb7b2f27bee07f001b22c9 61697096 web optional chromium-shell_147.0.7727.101-1~deb13u1_amd64.deb f32e9f1e7e645080c31994b6fd17a1d5 30437 web optional chromium_147.0.7727.101-1~deb13u1_amd64-buildd.buildinfo 90ae34487e6de90d764bb298c35c7c17 84358428 web optional chromium_147.0.7727.101-1~deb13u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmnh0u8ACgkQN8Ugyu9d QiTiFw//btRx1qMaSLuRabN1vt8cw/rC6AC5pfle6Q7nw7n9KHHbUYOf8bTvhNGi noqWq1kgxqqPjPUeUX6Xw8Yp7B/0vHBbdUN66QXaTLQVWrWc6h3xC5d+ZburnOit iV+lvyc4Hxxp281A4rr6mys0H2bXkCl7uFuyZmnTJO8V88XLAYLOkHMbUgK7GEiC G9usPwPBDO9BttEzbDDX2pCTYlscmRhKImFfvv9IFfdWSkji/8umAFo7N0i+Xyo9 kobiG8ClyHgvc9+M4xINTRsOaazj9x39kLPlRrAKt9eKDM8FmyQidKdAuKl09aQk 299BGJB8Sl+HEWNTRXB3aRhP97cIZV/vhE04PA8WEy5Wqmr5lv1328CouTX7kpcv CEFouzSP+2EQhcNvvc/RXyGKbz8YeBuKemOorY+pP931Vbz461/b1SPZfpAjRKko sutWLsis1KXYGXrKW7n55yjYf+fNEZX46gi8icLFZ3+mhPvsfWfwgspYcB9sidfj CPuZZBKUCAW91EMEF13Cn22lTv3fhFPIHjLTlb7Hya63LMhIXu41qAEpEiLjK99d jLsHhfujSqY16k/+DYizGSaW5VKvy4+QI2OnQbre3rCAF3isv6lSkg7GW0RaKSvj gcKYzT20uHXxKJDOL+Jzy0kPXLot+ERh4gMuV8UHMORvXR4IbL0= =RCsN -----END PGP SIGNATURE-----