-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 01 Apr 2026 12:42:51 -0400 Source: chromium Binary: chromium-l10n Architecture: all Version: 146.0.7680.177-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Andres Salomon Description: chromium-l10n - web browser - language packs Changes: chromium (146.0.7680.177-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-5272: Heap buffer overflow in GPU. Reported by inspector-ambitious. - CVE-2026-5273: Use after free in CSS. Reported by Anonymous. - CVE-2026-5274: Integer overflow in Codecs. Reported by heapracer (@heapracer). - CVE-2026-5275: Heap buffer overflow in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5276: Insufficient policy enforcement in WebUSB. Reported by Ariel Simon. - CVE-2026-5277: Integer overflow in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5278: Use after free in Web MIDI. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5279: Object corruption in V8. Reported by Hyeonjun Ahn (@_deayzl). - CVE-2026-5280: Use after free in WebCodecs. Reported by heapracer (@heapracer). - CVE-2026-5281: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-5282: Out of bounds read in WebCodecs. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5283: Inappropriate implementation in ANGLE. Reported by sweetchip. - CVE-2026-5284: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-5285: Use after free in WebGL. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5286: Use after free in Dawn. Reported by sweetchip. - CVE-2026-5287: Use after free in PDF. Reported by Syn4pse. - CVE-2026-5288: Use after free in WebView. Reported by Google. - CVE-2026-5289: Use after free in Navigation. Reported by Google. - CVE-2026-5290: Use after free in Compositing. Reported by Google. - CVE-2026-5291: Inappropriate implementation in WebGL. Reported by heapracer (@heapracer). - CVE-2026-5292: Out of bounds read in WebCodecs. Reported by Google. * d/patches: - upstream/Fix-blink-compilation-for-platforms-other-than-x86-and-arm.patch: drop, merged upstream. - ungoogled/disable-ai.patch: resync with u-c. . [ Daniel Richard G. ] * d/copyright: Exclude *.pb (protobuf) binary files. * d/patches: Various ungoogled-chromium-related updates. - disable/glic.patch: Drop, replaced with disable-ai.patch from the ungoogled-chromium project. - ungoogled/disable-ai.patch: Import new patch from ungoogled-chromium that zaps glic, screen_ai, and various other adjacent AI-based features. - ungoogled/disable-mei-preload.patch: Import patch to allow building without *.pb files. - ungoogled/disable-privacy-sandbox.patch: Update imported patch. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0005-blink-add-audio-vector-support.patch: Fix FBTFS from upstream adding vector-accelerated audio delay functions . [ Jianfeng Liu ] * d/patches/upstream: - Fix-blink-compilation-for-platforms-other-than-x86-and-arm.patch: Fix FBTFS from upstream for blink audio delay function on loong64 Checksums-Sha1: 91ef4417074bcd6e73e4aa06aee2c5899298a4fe 8666644 chromium-l10n_146.0.7680.177-1~deb13u1_all.deb 61f9fb5e584f6df2d65b48cc0f3748c731beaa30 26871 chromium_146.0.7680.177-1~deb13u1_all-buildd.buildinfo Checksums-Sha256: e409515c45cfef5c3fc932b589ab603eef1380566870128661128b6426397595 8666644 chromium-l10n_146.0.7680.177-1~deb13u1_all.deb e09a6a7a1adca00418ac0d5ddb86143530838f9824674b577243186ce18895c4 26871 chromium_146.0.7680.177-1~deb13u1_all-buildd.buildinfo Files: dd1d61c0b49b1c6489ff1bfb51c6ad49 8666644 localization optional chromium-l10n_146.0.7680.177-1~deb13u1_all.deb 38d36a43d278443365d305fb1028394e 26871 web optional chromium_146.0.7680.177-1~deb13u1_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmnOUvkACgkQN8Ugyu9d QiTHmQ/9HlfN/jUvk8t+n5sQGz21xV3RrAPpRYV/kppiJiGIASSFGmoL3IyHl3OU SezHETEqOGTnOCPobLNKoy9XQaya2h2f9iFHRWzX9ACM10+60wvd3yIkcD8yxjtz RrD6DGFPwGOa2pWIu30ljTLBI9mvkJ6fN2VUDWqapb6lMpzepylgQo8+PvLwJwGG H+gNgR5FOdXF4oJpYOD0QVXdiFj4gVLm/we48eDPDQ7HuKR8yiEaBP1qUNsIJJHp sj0qfrrIp2UXxAmsqsaoJV/lHIM/OVZ1jAOFGV2J6tjUCYlRDIsUOYRfGZCzoZj6 71GjWKuH8nVYqYYDKsSd0TNUhxqg5q8kVC2rrBMXrwT5kLDq/qA0bAqjVRpAYmKE ZDTmrVu8rtdrfj+246Tim3CX2ikVze0ZVr0vs+ghThzhsty8S3gAHwrLZWk4wJbt qJgPXBUFawqROiIDygCwQPfE8pqII/ioVe5nZO98C9SgVR+MqlIiWa8oqQLYNB2n RfG/TrE4vgnaEl9naS3MEdEkNW/qRfwbe22hqyyhgj5jdFW7S/VvDMjdw4eLi6b9 aFgLjb7QebRdzIxAi3hrQ2AA9osmmYl0bzuu5C1Szjzjsr/4Ap9WGCyeNNDLrX8n U72D9dvllD3J9bR3vnX35LKi2YK8ZWRctOcqUdSMHK82+iaLbCc= =Duvl -----END PGP SIGNATURE-----