-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 21 Jul 2026 23:21:54 -0400
Source: chromium
Binary: chromium-l10n
Architecture: all
Version: 150.0.7871.181-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: all Build Daemon (x86-grnet-02) <buildd_all-x86-grnet-02@buildd.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Description:
 chromium-l10n - web browser - language packs
Changes:
 chromium (150.0.7871.181-1~deb13u1) trixie-security; urgency=high
 .
   [ Andres Salomon ]
   * New upstream security release.
     - CVE-2026-15899: Use after free in CameraCapture. Reported by Google.
     - CVE-2026-15900: Use after free in GPU. Reported by Google.
     - CVE-2026-15901: Use after free in Network. Reported by Google.
     - CVE-2026-15902: Use after free in Cast. Reported by Google.
     - CVE-2026-15903: Out of bounds read and write in V8.
       Reported by OpenAI Codex Security (amyb).
     - CVE-2026-15904: Use after free in Ozone. Reported by Google.
     - CVE-2026-15905: Use after free in Aura. Reported by Google.
     - CVE-2026-16420: Type Confusion in WebAudio.
       Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt.
     - CVE-2026-16421: Inappropriate implementation in WebAudio.
       Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt.
     - CVE-2026-16413: Out of bounds write in ANGLE. Reported by Google.
     - CVE-2026-16414: Insufficient validation of untrusted input in
       Chromecast. Reported by Google.
     - CVE-2026-16415: Insufficient validation of untrusted input in
       Extensions. Reported by Google.
     - CVE-2026-16416: Integer overflow in Chromecast. Reported by Google.
     - CVE-2026-16417: Uninitialized Use in Skia. Reported by Google.
     - CVE-2026-16418: Stack buffer overflow in V8. Reported by Google.
     - CVE-2026-16419: Out of bounds read and write in ANGLE.
       Reported by Google.
     - CVE-2026-16422: Insufficient validation of untrusted input in
       Certificate. Reported by Google.
     - CVE-2026-16423: Use after free in UI. Reported by Google.
     - CVE-2026-16424: Use after free in GPU. Reported by Google.
Checksums-Sha1:
 ceede6721dca3c0da48f8964521df830469cf461 8872708 chromium-l10n_150.0.7871.181-1~deb13u1_all.deb
 96b8d4d7933988170da54f02eec72c17aef6c359 27427 chromium_150.0.7871.181-1~deb13u1_all-buildd.buildinfo
Checksums-Sha256:
 3412f29107df05464ded102ca0ce3943d9599ba3ac90449eaf96c7f9eb0c196e 8872708 chromium-l10n_150.0.7871.181-1~deb13u1_all.deb
 87b37d15014f7b29d1d7c8c72946d9b100ba77651a55c48e5ff2b453a4d4dc84 27427 chromium_150.0.7871.181-1~deb13u1_all-buildd.buildinfo
Files:
 1c2189f970d0f395619c194de939c848 8872708 localization optional chromium-l10n_150.0.7871.181-1~deb13u1_all.deb
 70a9de7df4a3bc455bc174e1f705d3cf 27427 web optional chromium_150.0.7871.181-1~deb13u1_all-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmphAEcACgkQmgPNRvTf
/zd/jQ/9HxroBsML3Nz0cB8TzhXnKkEQKx4tyiEhKgtitsuVAQoy1/sxUcbi9NDb
SbN9xzMfD8UYIZ8S9tlfp+0fTRWy6QRP0UL9zqD2FJl17P7i3wyp8lsZAd89IiwJ
u9ckFd2/vLNjr9IaLkXcVYWF//KzBrbBVRr0HuRhEhL9TPufHvzKtIstXqhI0NWv
vCur7QJvdAxTNidqfZOqXPuDD4clZSo5WaK/YBQV+wYKFvQzDYNl+j595tc7Pkr+
bGhiewZ6MgIVgfquo3QrzF7jf2CPGrYpb0G6Yg2T6eD5iPeFuctIxDY/gl6SF9e2
+aL6zkz6+3boJlzhQl6/Xg1GGYE7jsDL4FqwUUdsfYqT/bM/2RAqtIquOzRD8kRO
TheW3AfJmgPNy/Yzq9GTkMJxbKpz4MMwHxVRQtD8Wc3XwwHe/5bCnnpwONlK70vB
OcDpE7kJjLB4g64mejIpVLLYsywZ3zsksv9mKFvxWJ6TbqgxcV5xIm2Fj05sTmOA
KmcO07YqC+QQcb+6DvC+bYfTunqrGqEqWAz36mk/qqoz0elZbqt1fE4j0np5azhm
qGjJWN3r/JvGxUxvEXi6HrEg8XE/CB7fj+433Jbjp/+mJXIxVJ/496Hyg1tc5wTU
wTij4JshMgvki3spxrUigYuCDCX18jcSuZT+vw9Ay23+8gZFpBE=
=WIZX
-----END PGP SIGNATURE-----
