-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 23 Mar 2026 21:26:56 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 146.0.7680.164-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (146.0.7680.164-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-4673: Heap buffer overflow in WebAudio. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-4674: Out of bounds read in CSS. Reported by Syn4pse. - CVE-2026-4675: Heap buffer overflow in WebGL. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-4676: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-4677: Out of bounds read in WebAudio. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-4678: Use after free in WebGPU. Reported by Google. - CVE-2026-4679: Integer overflow in Fonts. Reported by GF, Un3xploitable Of DeadSec. - CVE-2026-4680: Use after free in FedCM. Reported by Shaheen Fazim. Checksums-Sha1: 984a5cbd55a06fff3d2c2fb733b5db69fca33793 5175208 chromium-common-dbgsym_146.0.7680.164-1~deb12u1_i386.deb cb133aacb5ae76935f65fc78b7cddb5d16af8537 29391888 chromium-common_146.0.7680.164-1~deb12u1_i386.deb d775e9b8ee33eed3837c837526df7c11d19f5a87 35583024 chromium-dbgsym_146.0.7680.164-1~deb12u1_i386.deb f7e6e620ce6ea1e60baae1868b4f87d32ba200c2 7780720 chromium-driver_146.0.7680.164-1~deb12u1_i386.deb 5f5f23cf85fe0c4709a4983e61b8d48b7479bd9b 29508252 chromium-headless-shell-dbgsym_146.0.7680.164-1~deb12u1_i386.deb 29fca38dee5094a850d3d3b441b662b1aaccd58c 58169232 chromium-headless-shell_146.0.7680.164-1~deb12u1_i386.deb 931256f34b095a8d37f14205e36ad74dd3df07e6 17824 chromium-sandbox-dbgsym_146.0.7680.164-1~deb12u1_i386.deb 37e2f1b8b39b4f4dade74d169f1254f5071749cf 113560 chromium-sandbox_146.0.7680.164-1~deb12u1_i386.deb 631b0c84c949532f3dd7b57c4276cb706610dc93 32289392 chromium-shell-dbgsym_146.0.7680.164-1~deb12u1_i386.deb dc24ecfd1318b0e094ff619231de9f93a041b442 63401172 chromium-shell_146.0.7680.164-1~deb12u1_i386.deb 2fc773ca9eb01e068e49654a152dec6cec6061be 30404 chromium_146.0.7680.164-1~deb12u1_i386-buildd.buildinfo 779660984fc4ecff5793abf6f9643a257ea4b475 75573612 chromium_146.0.7680.164-1~deb12u1_i386.deb Checksums-Sha256: 99818fe95823d5a7b09b807babe3c01b38fe156394ae2c545ba5b6ca2a8b0d70 5175208 chromium-common-dbgsym_146.0.7680.164-1~deb12u1_i386.deb ca3ae7eca67a1e34f66458c4f99380eb28c7ed16dfb50c739065146d5f9422b4 29391888 chromium-common_146.0.7680.164-1~deb12u1_i386.deb b8685a689a9ab56558be59ff64ae78895a5a1679ccc306dbac2a6565bf089bf9 35583024 chromium-dbgsym_146.0.7680.164-1~deb12u1_i386.deb 53f77418ccf18003a2012428d1bb1bbdf3f1790fef0940ec341ea621b82886b6 7780720 chromium-driver_146.0.7680.164-1~deb12u1_i386.deb a594989eb52cf0df19265dc3e2a30b16594b11e991e6ef447d66bc9d00b0a193 29508252 chromium-headless-shell-dbgsym_146.0.7680.164-1~deb12u1_i386.deb e644407a5b55ed80524e74c4cbd85b3e57f31d060dcd51b1236386d44c3c9aab 58169232 chromium-headless-shell_146.0.7680.164-1~deb12u1_i386.deb 5d4491bd4cbfd8adf277916fa336a55cad0dc6daec9110f66f08aea4f5ed473e 17824 chromium-sandbox-dbgsym_146.0.7680.164-1~deb12u1_i386.deb 6c6ffcb4fb1ce02a013844b8ff6c7c5b165835c405ce452629c34f19d7bb0d4d 113560 chromium-sandbox_146.0.7680.164-1~deb12u1_i386.deb 3eb14dee4e01c3036235b4ecb95266dab0b68343196803d45c119eefc34ba394 32289392 chromium-shell-dbgsym_146.0.7680.164-1~deb12u1_i386.deb 9596308740ee71ba4264593bc60bb98532ffeff49afa6fcb5c4667b438f506da 63401172 chromium-shell_146.0.7680.164-1~deb12u1_i386.deb 752363d93abc5889ad79213762ef211f51c7a8cbbefa2e5100b9227fc7fb291f 30404 chromium_146.0.7680.164-1~deb12u1_i386-buildd.buildinfo b33303668b57a82661d1d452cbee2f0db68b3be8938b222e0795375cda397ced 75573612 chromium_146.0.7680.164-1~deb12u1_i386.deb Files: 668bd23219b2e81a93823443543873c0 5175208 debug optional chromium-common-dbgsym_146.0.7680.164-1~deb12u1_i386.deb 4b11b86c561196ba3ce4005670c267aa 29391888 web optional chromium-common_146.0.7680.164-1~deb12u1_i386.deb 0eca360a1154c72f3afdea578e5f330f 35583024 debug optional chromium-dbgsym_146.0.7680.164-1~deb12u1_i386.deb e2af5e7f9b1573a009713f442d5153a9 7780720 web optional chromium-driver_146.0.7680.164-1~deb12u1_i386.deb 974e4534bb6517637fcf90341651b5bc 29508252 debug optional chromium-headless-shell-dbgsym_146.0.7680.164-1~deb12u1_i386.deb 7ee8d99eace3cebe01c864b7f51dd0d7 58169232 web optional chromium-headless-shell_146.0.7680.164-1~deb12u1_i386.deb 2163ce85fc986ec94cc36d68c4463c63 17824 debug optional chromium-sandbox-dbgsym_146.0.7680.164-1~deb12u1_i386.deb dbd9db7a5e78ce68b38e9f2ef6d6e462 113560 web optional chromium-sandbox_146.0.7680.164-1~deb12u1_i386.deb 74162ea4b8155b33a0b2ba1a9b4e2a46 32289392 debug optional chromium-shell-dbgsym_146.0.7680.164-1~deb12u1_i386.deb 4b4fbcb52469ea48febe9140eedc0019 63401172 web optional chromium-shell_146.0.7680.164-1~deb12u1_i386.deb 4adf46795470db54a6e5826e502863f8 30404 web optional chromium_146.0.7680.164-1~deb12u1_i386-buildd.buildinfo f049f6ff6bb6de70e013aece240c57c1 75573612 web optional chromium_146.0.7680.164-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBDWXQb2umOtH4DRpYg9P9sm2dfEFAmnDnCIACgkQYg9P9sm2 dfEKqw/6AglKtZOJM6a2SRUe+oQ9kJ4A6EXI1zhPxySVgdPC4jh/ARtoCLTnwUuz iYRWENw5YzfN43d/6BMBGNSKDG/Cki4A9iB0Z3KVBZIqYXZzXNd5fE0vhLNA6hCC vSLcnib6qu7HUlQYMYMM0Mx2TShPfnRkRVUBVZ9FhlzTTue9j8lCSm656+ORC/7B xQp0JgJWL5eg5ludnCqob1jUnP3uzMbA72ZYoVC0OrC6fpOfTfn6L91vko+f+zbN zulAbAFnYyD0EDlc3afMFt6na4DmwHm4imJNdgDue2CDrjcNs/p2RQmrZXi7J3Nj P7/RaeI8XNGtIk2HBGXQ6EL21GmjD4jS7Z36bistiJgpO3x6bsvm8i838r/LSlAy VnJv9JKgd5/aMKkKv/V6sQMVemohAJwKirjp1zhht39rqNVgkSG70IFapsicW4GO clbb6RUlnNN623zLDFt+ZUSNWGUoniM0yF9yFj2+09he/uMbFSFwN2dPOoxBTeNu MdE44ycyJEBSw2kl688kUpqI/mdcvEwhaTbrPFfKQ9V7L9uVz12d4j0ZklZhTF49 W0lIH5Zs3X5MGAXS7rxh/JB6hALuZNg5fDsva7Yku60yeunz9W5xqSWX48yrWoqA Jse49qCrjsvXKmfFtcMDlE5e8OibVIWNM28rCrLs7E+suTYeY00= =eQkS -----END PGP SIGNATURE-----