-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 15 Apr 2026 15:06:40 -0400
Source: chromium
Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym
Architecture: armhf
Version: 147.0.7727.101-1~deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: arm Build Daemon (arm-ubc-05) <buildd_arm64-arm-ubc-05@buildd.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Description:
 chromium   - web browser
 chromium-common - web browser - common resources used by the chromium packages
 chromium-driver - web browser - WebDriver support
 chromium-headless-shell - web browser - old headless shell
 chromium-sandbox - web browser - setuid security sandbox for chromium
 chromium-shell - web browser - minimal shell
Changes:
 chromium (147.0.7727.101-1~deb12u1) bookworm-security; urgency=high
 .
   [ Andres Salomon ]
   * New upstream security release.
     - CVE-2026-6296: Heap buffer overflow in ANGLE. Reported by cinzinga.
     - CVE-2026-6297: Use after free in Proxy. Reported by heapracer.
     - CVE-2026-6298: Heap buffer overflow in Skia.
       Reported by 86ac1f1587b71893ed2ad792cd7dde32.
     - CVE-2026-6299: Use after free in Prerender. Reported by Google.
     - CVE-2026-6358: Use after free in XR. Reported by Jihyeon Jeong
       (Compsec Lab, Seoul National University / Research Intern).
     - CVE-2026-6359: Use after free in Video.
       Reported by 86ac1f1587b71893ed2ad792cd7dde32.
     - CVE-2026-6300: Use after free in CSS.
       Reported by c6eed09fc8b174b0f3eebedcceb1e792.
     - CVE-2026-6301: Type Confusion in Turbofan. Reported by qymag1c.
     - CVE-2026-6302: Use after free in Video. Reported by Syn4pse.
     - CVE-2026-6303: Use after free in Codecs. Reported by Google.
     - CVE-2026-6304: Use after free in Graphite. Reported by Google.
     - CVE-2026-6305: Heap buffer overflow in PDFium.
       Reported by 86ac1f1587b71893ed2ad792cd7dde32.
     - CVE-2026-6306: Heap buffer overflow in PDFium.
       Reported by 86ac1f1587b71893ed2ad792cd7dde32.
     - CVE-2026-6307: Type Confusion in Turbofan.
       Reported by Project WhatForLunch (@pjwhatforlunch).
     - CVE-2026-6308: Out of bounds read in Media. Reported by Google.
     - CVE-2026-6309: Use after free in Viz. Reported by Google.
     - CVE-2026-6360: Use after free in FileSystem. Reported by asjidkalam.
     - CVE-2026-6310: Use after free in Dawn. Reported by Google.
     - CVE-2026-6311: Uninitialized Use in Accessibility. Reported by Google.
     - CVE-2026-6312: Insufficient policy enforcement in Passwords.
       Reported by Google.
     - CVE-2026-6313: Insufficient policy enforcement in CORS.
       Reported by Google.
     - CVE-2026-6314: Out of bounds write in GPU. Reported by Google.
     - CVE-2026-6315: Use after free in Permissions. Reported by Google.
     - CVE-2026-6316: Use after free in Forms. Reported by Google.
     - CVE-2026-6361: Heap buffer overflow in PDFium. Reported by Google.
     - CVE-2026-6362: Use after free in Codecs.
       Reported by c6eed09fc8b174b0f3eebedcceb1e792.
     - CVE-2026-6317: Use after free in Cast. Reported by Google.
     - CVE-2026-6363: Type Confusion in V8. Reported by Google.
     - CVE-2026-6318: Use after free in Codecs. Reported by Syn4pse.
     - CVE-2026-6319: Use after free in Payments. Reported by pwn2addr.
     - CVE-2026-6364: Out of bounds read in Skia.
       Reported by Google Threat Intelligence.
Checksums-Sha1:
 6b0200dfafaec50394da8d0b6bdacadcfa9d3eca 5729432 chromium-common-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 f72667027af6d87e144a796e9fc367411fba5dca 25138756 chromium-common_147.0.7727.101-1~deb12u1_armhf.deb
 8ed86c15c0e81cdd42719faa65a2015fb3454a27 35219268 chromium-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 11992bee6917e64e84530f03f4a37e43f6dc0c45 7161864 chromium-driver_147.0.7727.101-1~deb12u1_armhf.deb
 b770989abe5926f8c791be8068e2208b5c946f83 27467672 chromium-headless-shell-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 1ebea9d7c7f18e4c24bb68c45b483bd20ce9256b 53966440 chromium-headless-shell_147.0.7727.101-1~deb12u1_armhf.deb
 41284cd5bee3cb83f2033b474d8b1ff3071747b9 18000 chromium-sandbox-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 fb6925f6037546ff3149745c2dc468792b427761 115692 chromium-sandbox_147.0.7727.101-1~deb12u1_armhf.deb
 37cc6d780c302ea5a8ecbeb515d4cd2328a582c0 29817684 chromium-shell-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 7a5620454afd3c6bc0620f611e926d042872bdbe 58994724 chromium-shell_147.0.7727.101-1~deb12u1_armhf.deb
 f621230d9dcd790a5d74a683e8c6bdb471e3d00b 30297 chromium_147.0.7727.101-1~deb12u1_armhf-buildd.buildinfo
 e831273b94b6ae70f0ddd95435ec935b23a28c6e 70731988 chromium_147.0.7727.101-1~deb12u1_armhf.deb
Checksums-Sha256:
 0e9ed1a3405e2eaf2a8770bae70022f537e481a60c663c594bce5fdd1c2d5080 5729432 chromium-common-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 8853e7cc99f0978ce9bad068e073da6314c49ea3de42be931df2bd1abd012505 25138756 chromium-common_147.0.7727.101-1~deb12u1_armhf.deb
 8522245094b743be4d4069c79501126911f11914250bae20a5d69ce5e38df77f 35219268 chromium-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 4511c346ab6d1551a6e2914c6141fdfb6728c0ecb92f1d4ea1c622612eeded15 7161864 chromium-driver_147.0.7727.101-1~deb12u1_armhf.deb
 b5b5b328c9abfcd0fd713f73349672c0c397e08a4c5aa8bca46d00c990982ca5 27467672 chromium-headless-shell-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 01acd2510e67db40b664da96b4dc3bd28b850514adaa2c764bdc4dbba4a5c7c7 53966440 chromium-headless-shell_147.0.7727.101-1~deb12u1_armhf.deb
 fc0a3ae1db9cd27504297dd3bdbd66ff7f4af6e45bf0886da9bb43e6ca101122 18000 chromium-sandbox-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 40919582b46618615fe2b7c26ff7302d837d9d90a3910f06c69ab1c9e3676fec 115692 chromium-sandbox_147.0.7727.101-1~deb12u1_armhf.deb
 4be0f7c7d62a449e2a8fc17884d14c7b82d5195af4da1f869917788036bc3030 29817684 chromium-shell-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 98ed0a5e6f129b7a79e6ad7f7856021d1d231f536017e9615fd7f090952d6a98 58994724 chromium-shell_147.0.7727.101-1~deb12u1_armhf.deb
 67b30e629b6e3e5eea92a2a3b7db8aa8b4f6f6a3e4de5b05be395d97b097abac 30297 chromium_147.0.7727.101-1~deb12u1_armhf-buildd.buildinfo
 42fe76bcd022676f074e5a574d1477b29fc7ea5b088a40929d4ee6717294dc11 70731988 chromium_147.0.7727.101-1~deb12u1_armhf.deb
Files:
 46a9cbd5ff21e0cc228493dddfc08156 5729432 debug optional chromium-common-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 21185b4de4ba46975df872adeb21cb04 25138756 web optional chromium-common_147.0.7727.101-1~deb12u1_armhf.deb
 28e067564da85efc1efa87f5614ce06c 35219268 debug optional chromium-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 0c5d3f9e5acb033d9604155b705dcbbb 7161864 web optional chromium-driver_147.0.7727.101-1~deb12u1_armhf.deb
 4a9c17e7d3b22af67296377866f0f831 27467672 debug optional chromium-headless-shell-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 e47698c5d37d7bd096ceda75a08b3b2d 53966440 web optional chromium-headless-shell_147.0.7727.101-1~deb12u1_armhf.deb
 ac798dfa08a084d5676e20d2d919e7f2 18000 debug optional chromium-sandbox-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 7621c4a6f74956265dd11fd211aeb65a 115692 web optional chromium-sandbox_147.0.7727.101-1~deb12u1_armhf.deb
 91daf53649c4e6ac12f2bd5d2c448df2 29817684 debug optional chromium-shell-dbgsym_147.0.7727.101-1~deb12u1_armhf.deb
 80378c9a988fe313210a130277eb3129 58994724 web optional chromium-shell_147.0.7727.101-1~deb12u1_armhf.deb
 4a541f62c678c64539732360e5baa239 30297 web optional chromium_147.0.7727.101-1~deb12u1_armhf-buildd.buildinfo
 0aaf8a1b39087c44de0048b7e0b98c54 70731988 web optional chromium_147.0.7727.101-1~deb12u1_armhf.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEiIG3Q3DxwDgRKKeyLRECdjCZQkcFAmnh7J4ACgkQLRECdjCZ
Qke3sxAAndVHvw6zgCWQAMNc9GGiNVnKfX6iCp/dqA9AC5QAd0b1y0YsQeFls+13
IAxteQmrHhCTI7RMlM1KmiH+Xh8THAaHOtNUBmqb5Pc5ooQXrBUOw7uO1FAD1lRt
+RnEeoTRRoZORLKWrsWP1TGIfDg5o7Sru+5/RyLgc0yS9iUqYkBDaEZBXdNRiKNk
9iYgo5LLZJtFzuSPK1RVhulpq0mBodIhJOQHlP7keW9qtEjzA4HR07vQ9l7kZZNy
hM49jz8QnSR8UF70xGPxiV+RTkLbCyYxVxfuX/GtH50fudEroFd/u6ujINbAOCQp
YJrC4a2w+8CfOpTNryIRVbydSCYji9OLmE+l9HJj10TqL5MzWMCFpxnPFc2pGDUS
7c4h4n9VrAdm6OfgEooACAdo724Df5NHvy1W6h5Fpo701+7owlfiHFPGCkf9IoBO
FuU63c28bo5x0kMyOAmEFKQZMEmh9Xk4jDHYrXgm8zB+tzUztViO7zGcevDqQZZ2
1HfcMbnUqiTIhJPNB2MAZa/A+ecIIzDMC3AmBP1CIhsVFEdvcOI4JxVIqcrQFtgQ
A732x+UBvRwE1XYIrLiaoMYSGE32HILy3mj05vYmsthYDJYHYWFm48kd64/K0ghh
C65ZAmr9aZaV1FfyYrN8kUAAJqDSsWeSZ5JDmmzw+GMv63BGXWo=
=9ftT
-----END PGP SIGNATURE-----
