-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 17 Jun 2026 01:14:44 -0400
Source: chromium
Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym
Architecture: amd64
Version: 149.0.7827.155-1~deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: amd64 / i386 Build Daemon (x86-csail-01) <buildd_amd64-x86-csail-01@buildd.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Description:
 chromium   - web browser
 chromium-common - web browser - common resources used by the chromium packages
 chromium-driver - web browser - WebDriver support
 chromium-headless-shell - web browser - old headless shell
 chromium-sandbox - web browser - setuid security sandbox for chromium
 chromium-shell - web browser - minimal shell
Changes:
 chromium (149.0.7827.155-1~deb12u1) bookworm-security; urgency=high
 .
   [ Andres Salomon ]
   * New upstream security release.
     - CVE-2026-12437: Use after free in WebShare. Reported by Google.
     - CVE-2026-12438: Inappropriate implementation in WebView.
       Reported by Google.
     - CVE-2026-12439: Use after free in Digital Credentials.
       Reported by Google.
     - CVE-2026-12440: Use after free in DigitalCredentials. Reported by Google
     - CVE-2026-12441: Use after free in File Input. Reported by Google.
     - CVE-2026-12442: Use after free in Passwords. Reported by Google.
     - CVE-2026-12443: Use after free in Web Authentication. Reported by Google
     - CVE-2026-12444: Out of bounds read in Chromoting. Reported by Google.
     - CVE-2026-12445: Use after free in Extensions. Reported by Google.
     - CVE-2026-12446: Insufficient data validation in Passwords.
       Reported by Google.
     - CVE-2026-12447: Heap buffer overflow in WebRTC. Reported by Google.
     - CVE-2026-12448: Inappropriate implementation in WebView.
       Reported by Google.
     - CVE-2026-12449: Use after free in Chromoting. Reported by Google.
     - CVE-2026-12450: Inappropriate implementation in Media.
       Reported by Zhixin Tu.
     - CVE-2026-12451: Use after free in DigitalCredentials. Reported by Google
     - CVE-2026-12452: Use after free in Downloads. Reported by Google.
     - CVE-2026-12453: Insufficient validation of untrusted input in Input.
       Reported by Google.
     - CVE-2026-12454: Race in Safe Browsing. Reported by Google.
     - CVE-2026-12455: Use after free in Tab Strip. Reported by Google.
     - CVE-2026-12456: Insufficient validation of untrusted input in
       Extensions. Reported by Google.
     - CVE-2026-12457: Insufficient data validation in Extensions.
       Reported by Google.
     - CVE-2026-12458: Incorrect security UI in Passwords. Reported by Google.
     - CVE-2026-12459: Inappropriate implementation in Serial.
       Reported by Google.
     - CVE-2026-12460: Insufficient policy enforcement in File System Access.
       Reported by Google.
     - CVE-2026-12461: Out of bounds read in WebRTC. Reported by Google.
     - CVE-2026-12462: Use after free in Media. Reported by Google.
     - CVE-2026-12463: Inappropriate implementation in Views.
       Reported by Google.
     - CVE-2026-12464: Use after free in Browser. Reported by Google.
     - CVE-2026-12465: Insufficient validation of untrusted input in Metrics.
       Reported by Google.
     - CVE-2026-12466: Heap buffer overflow in WebRTC. Reported by Google.
     - CVE-2026-12467: Use after free in Extensions. Reported by Google.
     - CVE-2026-12468: Inappropriate implementation in Updater.
       Reported by Google.
     - CVE-2026-12469: Uninitialized Use in GPU. Reported by Google.
Checksums-Sha1:
 e7c99d61c600abb97468f9aa2b589afadf98c341 5518744 chromium-common-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 bdd9a7bc176d61eae3a02e812100945234ac0cb2 26309476 chromium-common_149.0.7827.155-1~deb12u1_amd64.deb
 a085b03054ed3b555b5dfc8b4f76e69ab8dfe4be 36002500 chromium-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 6db4b538280a42f7724f12564fc7e053d6ef814f 7743980 chromium-driver_149.0.7827.155-1~deb12u1_amd64.deb
 c22ab79b6a91b3a6dc111a70b8e2397166081fac 29596536 chromium-headless-shell-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 fa8c286e17aaed76390e23b44f875d2c557f7a84 58170688 chromium-headless-shell_149.0.7827.155-1~deb12u1_amd64.deb
 352b085de4d90f4105f793224b11ee2609a8e204 19288 chromium-sandbox-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 cec1ea2fce3bd62e5ff74cb5755322b1ecf8dc50 127980 chromium-sandbox_149.0.7827.155-1~deb12u1_amd64.deb
 217e9bd158c4c1dfa4e130850de11897fa3cd241 32536508 chromium-shell-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 580ee2ee01ebc1c7adda427c63d3757ad8ab31d7 63814864 chromium-shell_149.0.7827.155-1~deb12u1_amd64.deb
 66ff86d0b5ebbc4a7fe18184db020d8e80062075 30496 chromium_149.0.7827.155-1~deb12u1_amd64-buildd.buildinfo
 d465b61dbefd1cf6d74075ba0bdc906123843f16 75556504 chromium_149.0.7827.155-1~deb12u1_amd64.deb
Checksums-Sha256:
 1c28b50ae0136a4d2cc8024c9bf084cd2a342c8b3012ef7ed9483306f6a668d5 5518744 chromium-common-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 ca5dc26ac59b0a781f05204b590eb647fcc7da99962b504685722d94cc95e0ac 26309476 chromium-common_149.0.7827.155-1~deb12u1_amd64.deb
 f3b39af68efb2a8a14a8107f1c74b8f19980969cbd22fefd713e357245863923 36002500 chromium-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 b0bb139e0cd7e37922439edbd95368a7b662c1ededcb6ecffaa24b737451ebbc 7743980 chromium-driver_149.0.7827.155-1~deb12u1_amd64.deb
 0b000569d84e92359bbf84a48abed4252def41a79bf51a0c51d06ebb3588c4f9 29596536 chromium-headless-shell-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 af8cb17c72abc1a76386d35c18a5b1bb723ffe071ca9e8ce80b73bef2d466ef5 58170688 chromium-headless-shell_149.0.7827.155-1~deb12u1_amd64.deb
 cb690a1079e6316e2ac7b38d0a115ede042e75a0dc6e1998c883c6882836125a 19288 chromium-sandbox-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 71ba93669103abbdabd9ad636f28e80d936da170e8ea5df58441b8787e61115b 127980 chromium-sandbox_149.0.7827.155-1~deb12u1_amd64.deb
 04f34898a4b9d0de606b315154dac0e65300660b9e52fa412016d17d5c1cd719 32536508 chromium-shell-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 851d94ddaed323998971d1fa700a6f0f2d8123762e94b3a4b6e6fbe106a66045 63814864 chromium-shell_149.0.7827.155-1~deb12u1_amd64.deb
 041b1ddd17d4bc491e4d24158d6e4dfe4b9e0be3e78ebc356393577092f42f91 30496 chromium_149.0.7827.155-1~deb12u1_amd64-buildd.buildinfo
 0833a11889b139f492d16632bc69e0fa6454feb6714cba262a09ca30987a6fea 75556504 chromium_149.0.7827.155-1~deb12u1_amd64.deb
Files:
 f4cbc9451a638367ffa05cbec738dc7f 5518744 debug optional chromium-common-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 9d05103b0c0ee32ed75e09286907891d 26309476 web optional chromium-common_149.0.7827.155-1~deb12u1_amd64.deb
 840cd365f8e2de8990c1e05048c57176 36002500 debug optional chromium-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 c3f49cf0971b1bb784f539dfbc541455 7743980 web optional chromium-driver_149.0.7827.155-1~deb12u1_amd64.deb
 235b8b900b033b3f63bc813f12ced9e7 29596536 debug optional chromium-headless-shell-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 e2417e8eb0e63368806fe962dc1b1434 58170688 web optional chromium-headless-shell_149.0.7827.155-1~deb12u1_amd64.deb
 a18004b7332b7e8714f3a9f8f1819830 19288 debug optional chromium-sandbox-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 263fcf057844eba37fe10ae7c0aeee83 127980 web optional chromium-sandbox_149.0.7827.155-1~deb12u1_amd64.deb
 005fc2b2dea98f5aa6d09054de0c470a 32536508 debug optional chromium-shell-dbgsym_149.0.7827.155-1~deb12u1_amd64.deb
 8652370e8c7b33f686421e13087e30a9 63814864 web optional chromium-shell_149.0.7827.155-1~deb12u1_amd64.deb
 873417f1e449e1045c14725c9ea357fa 30496 web optional chromium_149.0.7827.155-1~deb12u1_amd64-buildd.buildinfo
 d68aeb0d15dd2eb5ba0ae433a0bd6437 75556504 web optional chromium_149.0.7827.155-1~deb12u1_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEBDWXQb2umOtH4DRpYg9P9sm2dfEFAmo0brsACgkQYg9P9sm2
dfHnGhAAs7AH2kJHsVerMsQWw1SSl79G2Ou3p2yi7HySHoo/HzeqLfZ/pL5933zM
QtcKfRCvRbz+8hTDF7GgVRAvXkropXtdElJeCD6qAwQwmGa5r1cSHy5KzWShZdgB
lIsL7SccftdEIuZlm+6CRvS8SFuskQhx9EsgBcpv8IzTtSVWObWhkcCJiW7Te4+s
2lWjWhUzivS05ljonjLADzpRl802zi5JMgxZuGYAC6f1z7pY2l5qu1jCQRbVSw5E
W83GUbba++Uu9kOpINvZNTqD79fAjFoKw/PIMUKO4NN0HFc4icn7cnqsIvwWRMaI
N4OUePOh4p2qQq/mBEa5vVjqXWjRJpXXWOBHyMDdvjTp1JFQ/HFTRCQDNy+Qpcnf
1+rku58kKpxjBuKQsJlyh+1wF//GI2XqT8aV4E4qBPXUz5gem9ZntiNP2AEWdkfU
gZ2xB1Q1ixH4ij3vhfxZh2RazCLvVFE5NeuSJcpDUwo//1/EpVJHB9KzFAAn7mrp
JCKb1AYBtoRn9n28sX5I376VonWNYtqMCctzbFJoPPLTimoqHYn4vh4szbz764Yu
mBa8Mz0C7id5gLg6WXyy3ZqDWcwVuzzEQn/NLgqlYepcwgrhYzpcCtqqCvbQNpBD
F8Rhq8pb8YE+cIIVLbr9w/rkhjWQHR5Vs8Knt9bIjQ8MS71+PnY=
=43KZ
-----END PGP SIGNATURE-----
