-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Jun 2026 01:14:44 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 149.0.7827.155-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (149.0.7827.155-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-12437: Use after free in WebShare. Reported by Google. - CVE-2026-12438: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12439: Use after free in Digital Credentials. Reported by Google. - CVE-2026-12440: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12441: Use after free in File Input. Reported by Google. - CVE-2026-12442: Use after free in Passwords. Reported by Google. - CVE-2026-12443: Use after free in Web Authentication. Reported by Google - CVE-2026-12444: Out of bounds read in Chromoting. Reported by Google. - CVE-2026-12445: Use after free in Extensions. Reported by Google. - CVE-2026-12446: Insufficient data validation in Passwords. Reported by Google. - CVE-2026-12447: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12448: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-12449: Use after free in Chromoting. Reported by Google. - CVE-2026-12450: Inappropriate implementation in Media. Reported by Zhixin Tu. - CVE-2026-12451: Use after free in DigitalCredentials. Reported by Google - CVE-2026-12452: Use after free in Downloads. Reported by Google. - CVE-2026-12453: Insufficient validation of untrusted input in Input. Reported by Google. - CVE-2026-12454: Race in Safe Browsing. Reported by Google. - CVE-2026-12455: Use after free in Tab Strip. Reported by Google. - CVE-2026-12456: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-12457: Insufficient data validation in Extensions. Reported by Google. - CVE-2026-12458: Incorrect security UI in Passwords. Reported by Google. - CVE-2026-12459: Inappropriate implementation in Serial. Reported by Google. - CVE-2026-12460: Insufficient policy enforcement in File System Access. Reported by Google. - CVE-2026-12461: Out of bounds read in WebRTC. Reported by Google. - CVE-2026-12462: Use after free in Media. Reported by Google. - CVE-2026-12463: Inappropriate implementation in Views. Reported by Google. - CVE-2026-12464: Use after free in Browser. Reported by Google. - CVE-2026-12465: Insufficient validation of untrusted input in Metrics. Reported by Google. - CVE-2026-12466: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-12467: Use after free in Extensions. Reported by Google. - CVE-2026-12468: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-12469: Uninitialized Use in GPU. Reported by Google. Checksums-Sha1: 0c560dfbb81842f7c191846f2e7cc3e114d777f7 5311776 chromium-common-dbgsym_149.0.7827.155-1~deb12u1_i386.deb edc9c060f4afd29f8b3d09008d0e55309c58d359 26277244 chromium-common_149.0.7827.155-1~deb12u1_i386.deb 99c1d4e786a6fad1877d65e9464839c11db6eed1 36203428 chromium-dbgsym_149.0.7827.155-1~deb12u1_i386.deb 5ec8c7a572c327f0ebfdd8d6fd8b5d3fdf3bd854 8115964 chromium-driver_149.0.7827.155-1~deb12u1_i386.deb e230f86033f04ec1e83bd7906cb66f7339280cf1 29786404 chromium-headless-shell-dbgsym_149.0.7827.155-1~deb12u1_i386.deb b90fce6d7c123e08c07028077543219db3552bbd 59826748 chromium-headless-shell_149.0.7827.155-1~deb12u1_i386.deb 61d572af68cf69e0d2fff338a235e90d5af67abe 17824 chromium-sandbox-dbgsym_149.0.7827.155-1~deb12u1_i386.deb 507f90bb188d83b9153e9f95abad30506d2df865 127868 chromium-sandbox_149.0.7827.155-1~deb12u1_i386.deb 9d09b6c0f56592518db5550d6157e34a58353389 32708424 chromium-shell-dbgsym_149.0.7827.155-1~deb12u1_i386.deb 8d37617444f83a539529ab837c03fa7b17639545 65582588 chromium-shell_149.0.7827.155-1~deb12u1_i386.deb bb3329daf85a864c50bf889f703ff64cc15d24f3 30478 chromium_149.0.7827.155-1~deb12u1_i386-buildd.buildinfo f5ab0fb50917711dfebb8d9606c31e8083093fcb 78094392 chromium_149.0.7827.155-1~deb12u1_i386.deb Checksums-Sha256: 2370b96e5cb1ccecc28ccec2210488c2cbf4ed5c9d0d18af772d3bb92ab934a5 5311776 chromium-common-dbgsym_149.0.7827.155-1~deb12u1_i386.deb 0e765da20bd2c24a58d28c4fde6fd9a21bef203c4a37e2fce805f1be796373d5 26277244 chromium-common_149.0.7827.155-1~deb12u1_i386.deb 67dd28f01b1fca96d67a466c2c86f8bcbc326dee77f9d1e16a8d92a4ad0a691a 36203428 chromium-dbgsym_149.0.7827.155-1~deb12u1_i386.deb 8d8c7992e484861c5e8f0b156b759572d34c2c2e3bd35fbcbb33a068611fd3b7 8115964 chromium-driver_149.0.7827.155-1~deb12u1_i386.deb 553bf02bd9a16cf59079251055501ba11b3cd5f4e5b9cfad6204e36449effb33 29786404 chromium-headless-shell-dbgsym_149.0.7827.155-1~deb12u1_i386.deb 08dbaee7cf93cf56be2af1af0db731057b8d76c7686e7dd1b66795abb6551311 59826748 chromium-headless-shell_149.0.7827.155-1~deb12u1_i386.deb 7aed8a8d1fffb533f8c4b04de90bf1f4b9d622ed5fc76c3685d5e6250c9282bd 17824 chromium-sandbox-dbgsym_149.0.7827.155-1~deb12u1_i386.deb 8bce850f05fd9fa1f5e4b7108af83bb25151545e271ffeccdc0f5ab596032088 127868 chromium-sandbox_149.0.7827.155-1~deb12u1_i386.deb 07c091c1b8de455f6a56bef7cd540cc9b4b13a0dd5f6d257566633f2294d3c39 32708424 chromium-shell-dbgsym_149.0.7827.155-1~deb12u1_i386.deb bd4583b9d967d241f7636cf5e17a536c4165c8bb023705eecd58eb526e537c77 65582588 chromium-shell_149.0.7827.155-1~deb12u1_i386.deb 90f5c6ba0f9909122e39bbfb1330b798bcefa0235ddfba1413f9f22989a9f345 30478 chromium_149.0.7827.155-1~deb12u1_i386-buildd.buildinfo fe6cd6c0163131bd64de642fd7ab5d7d3861345af026a1f56f4ed6888152c262 78094392 chromium_149.0.7827.155-1~deb12u1_i386.deb Files: f9e9ee860f390ef16774f21f464f7ca0 5311776 debug optional chromium-common-dbgsym_149.0.7827.155-1~deb12u1_i386.deb 4ce4247e541393f4d63ea44b23534c1d 26277244 web optional chromium-common_149.0.7827.155-1~deb12u1_i386.deb bd5decb4852c5f7cc912258c6af8a594 36203428 debug optional chromium-dbgsym_149.0.7827.155-1~deb12u1_i386.deb 23909cd979fb8eefd0144d0bc785ab7d 8115964 web optional chromium-driver_149.0.7827.155-1~deb12u1_i386.deb 0af7227133ebaa13c2408e53dffc5298 29786404 debug optional chromium-headless-shell-dbgsym_149.0.7827.155-1~deb12u1_i386.deb e4808bbd34ab43629b1ca320e0127f8c 59826748 web optional chromium-headless-shell_149.0.7827.155-1~deb12u1_i386.deb f00646c2886a68225bf614173f07a9c0 17824 debug optional chromium-sandbox-dbgsym_149.0.7827.155-1~deb12u1_i386.deb d35e09ea296c190de0bfe09218532b5b 127868 web optional chromium-sandbox_149.0.7827.155-1~deb12u1_i386.deb 468e2d5475401becab3905dabcb0e5cc 32708424 debug optional chromium-shell-dbgsym_149.0.7827.155-1~deb12u1_i386.deb 395abd7663aba3e582d7780a214c1ffe 65582588 web optional chromium-shell_149.0.7827.155-1~deb12u1_i386.deb 7ac77286845f76b4dc8d69022f6750b5 30478 web optional chromium_149.0.7827.155-1~deb12u1_i386-buildd.buildinfo ab92f5c193a5ab3b7ff1f7ea9b278b43 78094392 web optional chromium_149.0.7827.155-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmo0oYsACgkQTwt/65ON 6zfInxAAtH7ucasblcCsBzaeAP89nH849RA+pVveICqLIWPRfKQUeneyOpis8cdE Q0CzCExJ0//fmFcsM02S6z0p9CadlEKdLS4iNphwTH/uGyLFpCRBzwVCYg12as3x LiiwkjzDHsuWXHesh6BYeqN2ODSCP2VEdBI3Kf+SpviO4TB+7+1xq29aLVsn1KL6 ER8LzuGoqeLaQH/JmSaJoqxaunbZai9+FCgylcVVgeyMj8yx9jmUlVO4993nP9iH D3wybdefkn+xhRFKrdLspOOO4H23mV1Jx/23/r9uJgS9xlJ+fh7WTB1Su3MYaqdP up8HIHK454zNG8xamMWDx+z7WtUd4qhBHTRaMGmKxx4NJvUiqXfUsFRF+q6W6GRT PUGB9jmt4S3m8+R1g0+N5hgaKXz6q3TAl0zfb+3XkbJ28XQbkv0FABZ+i2s0743S F5PpbHg+xBFHRq7nEVwGYOo2/8XNvsDlvQ8QdiS7Lb3CVH+nKp0FkPLikMNR8+OQ y8blw/t9QapT+IedKjApfY/wAx9KszyaVqyH5rNt+FJjn4WPHoTK3j1OcWUDCk1n +3x6boUalFmpvhGcyj478fWvVQ/t/8qWDIH1jO1SWDel9mFEIOsdl1g1zfkz8AHq qQaYRZxQg1l6vqfRv77jB8dYO9/MY/k9jLtoW8hMehN/4VgbMY8= =XfUP -----END PGP SIGNATURE-----