head 1.5; access; symbols pkgsrc-2025Q1:1.1.0.2 pkgsrc-2025Q1-base:1.1; locks; strict; comment @# @; 1.5 date 2026.10.02.11.43.19; author kikadf; state Exp; branches; next 1.4; commitid H2vrlX55cZdkCTXG; 1.4 date 2026.09.29.07.42.45; author kikadf; state Exp; branches; next 1.3; commitid hkmJ6D1WIKxgnuXG; 1.3 date 2026.09.22.13.41.17; author kikadf; state Exp; branches; next 1.2; commitid NyittFkZkmblACWG; 1.2 date 2025.05.16.16.08.14; author wiz; state dead; branches; next 1.1; commitid Y2DygAA6jkhRe9VF; 1.1 date 2025.02.06.09.57.38; author wiz; state Exp; branches; next ; commitid ItsQhJhMSErRpoIF; desc @@ 1.5 log @chromium: update to 154.0.8037.97 * 154.0.8037.92 This update includes 32 security fixes. Please see the Chrome Security Page for more information. [TBD][551673541] Critical CVE-2026-102331: Buffer overflow in ANGLE. Reported by @@mfx on 2026-08-24 [N/A][517312707] High CVE-2026-102317: Improper privilege management in Mojo. Reported by Google on 2026-05-28 [TBD][551668264] High CVE-2026-102312: UI misrepresentation in Omnibox. Reported by jodyritonga on 2026-08-24 [N/A][556789073] High CVE-2026-102313: Uninitialized resource in ANGLE. Reported by Google on 2026-09-03 [TBD][556908674] High CVE-2026-102299: Type confusion in V8. Reported by Andrew Boni on 2026-09-04 [N/A][556926296] High CVE-2026-102306: Use after free in Bluetooth. Reported by Google on 2026-09-04 [N/A][556959073] High CVE-2026-102307: Uninitialized resource in Dawn. Reported by Google on 2026-09-04 [TBD][559266114] High CVE-2026-102323: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-10 [N/A][559727039] High CVE-2026-102303: Uninitialized resource in GPU. Reported by Google on 2026-09-10 [N/A][559737160] High CVE-2026-102311: Uninitialized resource in GPU. Reported by Google on 2026-09-10 [TBD][560062638] High CVE-2026-102300: Uninitialized resource in WebGPU. Reported by Arni Hardarson (Neonix Security) on 2026-09-11 [TBD][560233248] High CVE-2026-102326: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-11 [TBD][560238698] High CVE-2026-102316: Use after free in Views. Reported by Xinyang Ge on 2026-09-11 [TBD][560251736] High CVE-2026-102304: Use after free in Passwords. Reported by Xinyang Ge on 2026-09-11 [TBD][560536732] High CVE-2026-102328: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-12 [TBD][560867085] High CVE-2026-102309: Use after free in FullScreen. Reported by sean geofrey on 2026-09-13 [N/A][561994362] High CVE-2026-102325: Uninitialized resource in Skia. Reported by Google on 2026-09-15 [N/A][561997480] High CVE-2026-102308: Use after free in Views. Reported by Google on 2026-09-15 [N/A][562004351] High CVE-2026-102301: Out of bounds write in GPU. Reported by Google on 2026-09-15 [N/A][562042411] High CVE-2026-102319: Uninitialized resource in GPU. Reported by Google on 2026-09-15 [TBD][562174487] High CVE-2026-102324: Use after free in PictureInPicture. Reported by Blockian Creator of Kritt and Open-Kritt on 2026-09-15 [N/A][562279351] High CVE-2026-102318: Out of bounds read in WebGL. Reported by Google on 2026-09-16 [TBD][563297615] High CVE-2026-102329: Cross-site scripting in WebUI. Reported by chipsec on 2026-09-18 [N/A][563351482] High CVE-2026-102315: Uninitialized resource in Media. Reported by Google on 2026-09-18 [N/A][563716534] High CVE-2026-102302: Buffer overflow in V8. Reported by Google on 2026-09-19 [TBD][565328105] High CVE-2026-102321: Type confusion in V8. Reported by Taisic Yun (@@taisic_) of Theori, with Xint on 2026-09-23 [TBD][554038924] Medium CVE-2026-102320: Missing authorization in CORS. Reported by Anonymous on 2026-08-28 [$1,000][477726837] Low CVE-2026-102310: Missing authorization in Payments. Reported by Autodidact on 2026-01-22 [N/A][496212975] Low CVE-2026-102327: Incorrect authorization in WebView. Reported by Google on 2026-03-25 [N/A][498793976] Low CVE-2026-102330: Incorrect authorization in SiteIsolation. Reported by Google on 2026-04-02 [N/A][514059780] Low CVE-2026-102314: UI misrepresentation in TabStrip. Reported by Google on 2026-05-17 [N/A][533021953] Low CVE-2026-102305: UI misrepresentation in SignIn. Reported by Google on 2026-07-09 * 154.0.8037.97 See: https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html @ text @$NetBSD$ * Part of patchset to build chromium on NetBSD * Based on OpenBSD's chromium patches, and pkgsrc's qt5-qtwebengine patches --- .gn.orig 2026-09-22 00:09:16.000000000 +0000 +++ .gn @@@@ -9,7 +9,7 @@@@ import("//third_party/angle/dotfile_sett buildconfig = "//build/config/BUILDCONFIG.gn" # The hermetic Python interpreter to use by default. -script_executable = "//third_party/cpython3/host/bin/python3" +script_executable = "python3" # These arguments override the default values for items in a declare_args # block. "gn args" in turn can override these. @ 1.4 log @ chromium: update to 154.0.8037.57 * 154.0.8037.57 This update includes 108 security fixes. Please see the Chrome Security Page for more information. See: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html @ text @@ 1.3 log @ chromium: update to 153.0.8010.52 * 153.0.8010.36 This update includes 230 security fixes. Please see the Chrome Security Page for more information. See: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html Google is aware that an exploit for CVE-2026-87491 exists in the wild: [$2,500][543557673] Medium CVE-2026-87491: Out of bounds write in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-06 * 153.0.8010.47 This update includes 42 security fixes. Please see the Chrome Security Page for more information. [N/A][556870863] Critical CVE-2026-91726: Out of bounds read in WebGL. Reported by Google on 2026-09-03 [TBD][557320614] Critical CVE-2026-91721: Use after free in Internals. Reported by xinyang on 2026-09-04 [TBD][558456602] Critical CVE-2026-91749: Use after free in Workers. Reported by WinD39 - Huynh Dinh Vu on 2026-09-08 [$1,500][552283275] High CVE-2026-91724: Use after free in Input. Reported by Hafiizh on 2026-08-25 [$1,000][556715288] High CVE-2026-91728: Integer overflow in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-09-03 [N/A][516780835] High CVE-2026-91734: Incorrect authorization in Core. Reported by Google on 2026-05-26 [N/A][516893912] High CVE-2026-91727: Incorrect reference resolution in Extensions. Reported by Google on 2026-05-26 [N/A][516947138] High CVE-2026-91743: Race condition in Core. Reported by Google on 2026-05-27 [N/A][520019273] High CVE-2026-91744: Race condition in PlatformIntegration. Reported by Google on 2026-06-04 [N/A][521486621] High CVE-2026-91712: Race condition in Extensions. Reported by Google on 2026-06-08 [N/A][521559611] High CVE-2026-91748: Race condition in Extensions. Reported by Google on 2026-06-09 [N/A][523470135] High CVE-2026-91720: Uninitialized resource in ANGLE. Reported by Google on 2026-06-13 [N/A][523554372] High CVE-2026-91731: Type confusion in Compositing. Reported by Google on 2026-06-13 [N/A][540016074] High CVE-2026-91747: Use after free in Skia. Reported by Google on 2026-07-28 [N/A][540021213] High CVE-2026-91733: Improper state validation in Skia. Reported by Google on 2026-07-28 [TBD][546413288] High CVE-2026-91741: Type confusion in CacheStorage. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-14 [TBD][547815507] High CVE-2026-91709: Type confusion in ServiceWorker. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17 [TBD][549225472] High CVE-2026-91717: Missing authorization in Android. Reported by jodyritonga on 2026-08-20 [N/A][552416113] High CVE-2026-91735: Incorrect authorization in WebUI. Reported by Google on 2026-08-25 [N/A][553115724] High CVE-2026-91708: Race condition in Network. Reported by Google on 2026-08-26 [N/A][553121008] High CVE-2026-91736: Use after free in DOM. Reported by Google on 2026-08-26 [N/A][553122373] High CVE-2026-91740: Uninitialized resource in Skia. Reported by Google on 2026-08-26 [N/A][553132148] High CVE-2026-91710: Use after free in WebAppInstalls. Reported by Google on 2026-08-26 [N/A][553133215] High CVE-2026-91718: Use after free in Core. Reported by Google on 2026-08-26 [N/A][554558368] High CVE-2026-91716: Use after free in Auth. Reported by Google on 2026-08-29 [N/A][556260782] High CVE-2026-91746: Integer overflow in Compositing. Reported by Google on 2026-09-02 [TBD][557206809] High CVE-2026-91729: Use after free in DigitalCredentials. Reported by sean geofrey on 2026-09-04 [TBD][558036280] High CVE-2026-91737: Use after free in PDF. Reported by SeungMyung Lee (@@sm1ee), Siung kim (@@ksw9722) on 2026-09-06 [TBD][558342353] High CVE-2026-91711: Out of bounds write in ServiceWorker. Reported by Cristian Di Nicola (@@crih.exe) on 2026-09-07 [TBD][558367547] High CVE-2026-91715: Type confusion in ServiceWorker. Reported by Cristian Di Nicola (@@crih.exe) on 2026-09-07 [N/A][558734727] High CVE-2026-91745: Use after free in V8. Reported by Google on 2026-09-08 [TBD][474131239] Medium CVE-2026-91723: Race condition in WebAppInstalls. Reported by Luan Herrera (@@lbherrera_) on 2026-01-07 [TBD][511062248] Medium CVE-2026-91732: Missing authorization in AppManifest. Reported by pakhunov.anton.n on 2026-05-08 [N/A][513858387] Medium CVE-2026-91742: Confused deputy in PriceTracking. Reported by Google on 2026-05-16 [N/A][517710554] Medium CVE-2026-91714: Observable discrepancy in Fonts. Reported by Google on 2026-05-29 [N/A][518032534] Medium CVE-2026-91725: Observable discrepancy in CSS. Reported by Google on 2026-05-29 [N/A][521951328] Medium CVE-2026-91739: Missing authorization in Transactions Platform. Reported by Google on 2026-06-09 [N/A][523715133] Medium CVE-2026-91713: Missing authorization in Browser. Reported by Google on 2026-06-14 [N/A][536450979] Medium CVE-2026-91738: Improper input validation in ANGLE. Reported by Google on 2026-07-19 [TBD][543640868] Medium CVE-2026-91730: Incomplete cleanup in GetUserMedia. Reported by Keita Sode and Daisuke Hatakeyama (SYZD Research) on 2026-08-07 [TBD][554953456] Medium CVE-2026-91722: Use after free in Input. Reported by TIENPA on 2026-08-31 [TBD][542115030] Low CVE-2026-91719: Code injection in XML. Reported by Zabith Mohammed (@@nmzabith) on 2026-08-03 * 153.0.8010.52 This update includes 16 security fixes. Please see the Chrome Security Page for more information. [TBD][500417361] Critical CVE-2026-93374: Use after free in Dawn. Reported by Florian Schweitzer on 2026-04-08 [N/A][548085797] Critical CVE-2026-93372: Buffer overflow in WebGL. Reported by Google on 2026-08-17 [$3,000][550839154] High CVE-2026-93375: Incorrect reference resolution in Tracing. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-08-22 [TBD][541707261] High CVE-2026-93382: Use after free in PDFium. Reported by WinD39 - Huynh Dinh Vu on 2026-08-02 [N/A][553130676] High CVE-2026-93387: Improper state validation in Skia. Reported by Google on 2026-08-26 [N/A][553132214] High CVE-2026-93373: Use after free in Extensions. Reported by Google on 2026-08-26 [TBD][556853443] High CVE-2026-93381: Buffer overflow in PDFium. Reported by SeungMyung Lee (@@sm1ee), Siung kim (@@ksw9722) on 2026-09-03 [TBD][560039872] High CVE-2026-93379: Incorrect authorization in ORB. Reported by OGINOME Tomohito on 2026-09-11 [N/A][560121552] High CVE-2026-93377: Type confusion in V8. Reported by Google on 2026-09-11 [N/A][498411599] Medium CVE-2026-93380: Race condition in FileSystem. Reported by Google on 2026-04-01 [N/A][511832293] Medium CVE-2026-93384: Server-side request forgery in Omnibox. Reported by Google on 2026-05-10 [N/A][515493668] Medium CVE-2026-93383: Information leak in Permissions. Reported by Google on 2026-05-22 [N/A][520521197] Medium CVE-2026-93376: Out of bounds read in DataTransfer. Reported by Google on 2026-06-05 [N/A][540051167] Medium CVE-2026-93378: Missing authorization in Storage. Reported by Google on 2026-07-28 [N/A][553136980] Medium CVE-2026-93385: Information leak in Paint. Reported by Google on 2026-08-26 [N/A][513996595] Low CVE-2026-93386: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-17 @ text @d7 1 a7 1 --- .gn.orig 2026-09-14 22:17:16.000000000 +0000 @ 1.2 log @www/chromium: update to 136.0.7103.113 Provided by Robert Bagdan in wip. * 131.0.6778.264 This update includes 4 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$55000][383356864] High CVE-2025-0291: Type Confusion in V8. Reported by Popax21 on 2024-12-11 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel. As usual, our ongoing internal security work was responsible for a wide range of fixes: [388088544] Various fixes from internal audits, fuzzing and other initiatives * 132.0.6834.83 This update includes 16 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$7000][374627491] High CVE-2025-0434: Out of bounds memory access in V8. Reported by ddme on 2024-10-21 [$7000][379652406] High CVE-2025-0435: Inappropriate implementation in Navigation. Reported by Alesandro Ortiz on 2024-11-18 [$3000][382786791] High CVE-2025-0436: Integer overflow in Skia. Reported by Han Zheng (HexHive) on 2024-12-08 [$2000][378623799] High CVE-2025-0437: Out of bounds read in Metrics. Reported by Xiantong Hou of Wuheng Lab and Pisanbao on 2024-11-12 [TBD][384186539] High CVE-2025-0438: Stack buffer overflow in Tracing. Reported by Han Zheng (HexHive) on 2024-12-15 [$5000][371247941] Medium CVE-2025-0439: Race in Frames. Reported by Hafiizh on 2024-10-03 [$5000][40067914] Medium CVE-2025-0440: Inappropriate implementation in Fullscreen. Reported by Umar Farooq on 2023-07-22 [$2000][368628042] Medium CVE-2025-0441: Inappropriate implementation in Fenced Frames. Reported by someoneverycurious on 2024-09-21 [$2000][40940854] Medium CVE-2025-0442: Inappropriate implementation in Payments. Reported by Ahmed ElMasry on 2023-11-08 [$1000][376625003] Medium CVE-2025-0443: Insufficient data validation in Extensions. Reported by Anonymous on 2024-10-31 [$1000][359949844] Low CVE-2025-0446: Inappropriate implementation in Extensions. Reported by Hafiizh on 2024-08-15 [$1000][375550814] Low CVE-2025-0447: Inappropriate implementation in Navigation. Reported by Khiem Tran (@@duckhiem) on 2024-10-25 [$1000][377948403] Low CVE-2025-0448: Inappropriate implementation in Compositing. Reported by Dahyeon Park on 2024-11-08 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel. As usual, our ongoing internal security work was responsible for a wide range of fixes: [389761478] Various fixes from internal audits, fuzzing and other initiatives * 132.0.6834.110 This update includes 3 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$11000][386143468] High CVE-2025-0611: Object corruption in V8. Reported by 303f06e3 on 2024-12-26 [$8000][385155406] High CVE-2025-0612: Out of bounds memory access in V8. Reported by Alan Goodman on 2024-12-20 As usual, our ongoing internal security work was responsible for a wide range of fixes: [391144311] Various fixes from internal audits, fuzzing and other initiatives * 132.0.6834.159 This update includes 2 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$2000][384844003] Medium CVE-2025-0762: Use after free in DevTools. Reported by Sakana.S on 2024-12-18 As usual, our ongoing internal security work was responsible for a wide range of fixes: [392630675] Various fixes from internal audits, fuzzing and other initiatives * 133.0.6943.53 This update includes 12 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$7000][390889644] High CVE-2025-0444: Use after free in Skia. Reported by Francisco Alonso (@@revskills) on 2025-01-19 [TBD][392521083] High CVE-2025-0445: Use after free in V8. Reported by 303f06e3 on 2025-01-27 [$2000][40061026] Medium CVE-2025-0451: Inappropriate implementation in Extensions API. Reported by Vitor Torres and Alesandro Ortiz on 2022-09-18 As usual, our ongoing internal security work was responsible for a wide range of fixes: [394135363] Various fixes from internal audits, fuzzing and other initiatives * 133.0.6943.98 This update includes 4 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$55000][391907159] High CVE-2025-0995: Use after free in V8. Reported by Popax21 on 2025-01-24 [TBD][391788835] High CVE-2025-0996: Inappropriate implementation in Browser UI. Reported by yuki yamaoto on 2025-01-23 [TBD][391666328] High CVE-2025-0997: Use after free in Navigation. Reported by asnine on 2025-01-23 [TBD][386857213] High CVE-2025-0998: Out of bounds memory access in V8. Reported by Alan Goodman on 2024-12-31 * 133.0.6943.126 This update includes 3 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$11000][394350433] High CVE-2025-0999: Heap buffer overflow in V8. Reported by Seunghyun Lee (@@0x10n) on 2025-02-04 [TBD][383465163] High CVE-2025-1426: Heap buffer overflow in GPU. Reported by un3xploitable && GF on 2024-12-11 [$4000][390590778] Medium CVE-2025-1006: Use after free in Network. Reported by Tal Keren, Sam Agranat, Eran Rom, Edouard Bochin, Adam Hatsir of Palo Alto Networks on 2025-01-18 * 133.0.6943.141 This update includes 1 security fix. Please see the Chrome Security Page for more information. As usual, our ongoing internal security work was responsible for a wide range of fixes: [399107077]Various fixes from internal audits, fuzzing and other initiatives * 134.0.6998.35 This update includes 14 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$7000][397731718] High CVE-2025-1914: Out of bounds read in V8. Reported by Zhenghang Xiao (@@Kipreyyy) and Nan Wang (@@eternalsakura13) on 2025-02-20 [$4000][391114799] Medium CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools. Reported by Topi Lassila on 2025-01-20 [$3000][376493203] Medium CVE-2025-1916: Use after free in Profiles. Reported by parkminchan, SSD Labs Korea on 2024-10-31 [$2000][329476341] Medium CVE-2025-1917: Inappropriate Implementation in Browser UI. Reported by Khalil Zhani on 2024-03-14 [$2000][388557904] Medium CVE-2025-1918: Out of bounds read in PDFium. AReported by asnine on 2025-01-09 [$2000][392375312] Medium CVE-2025-1919: Out of bounds read in Media. Reported by @@Bl1nnnk and @@Pisanbao on 2025-01-26 [$1000][387583503] Medium CVE-2025-1921: Inappropriate Implementation in Media Stream. Reported by Kaiido on 2025-01-04 [$5000][384033062] Low CVE-2025-1922: Inappropriate Implementation in Selection. Reported by Alesandro Ortiz on 2024-12-14 [$1000][382540635] Low CVE-2025-1923: Inappropriate Implementation in Permission Prompts. Reported by Khalil Zhani on 2024-12-06 As usual, our ongoing internal security work was responsible for a wide range of fixes: [400559715] Various fixes from internal audits, fuzzing and other initiatives * 134.0.6998.88 This update includes 5 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$7000][398065918] High CVE-2025-1920: Type Confusion in V8. Reported by Excello s.r.o. on 2025-02-21 [TBD][400052777] High CVE-2025-2135: Type Confusion in V8. Reported by Zhenghang Xiao (@@Kipreyyy) and Nan Wang (@@eternalsakura13) on 2025-03-02 [NA][401059730] High CVE-2025-24201: Out of bounds write in GPU on Mac. Reported by Apple Security Engineering and Architecture (SEAR) on 2025-03-05 [$3000][395032416] Medium CVE-2025-2136: Use after free in Inspector. Reported by Sakana.S on 2025-02-10 [$2000][398999390] Medium CVE-2025-2137: Out of bounds read in V8. Reported by zeroxiaobai@@ on 2025-02-25 Google is aware of reports that an exploit for CVE-2025-24201 exists in the wild. * 134.0.6998.117 This update includes 2 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [TBD][401029609] Critical CVE-2025-2476: Use after free in Lens. Reported by SungKwon Lee of Enki Whitehat on 2025-03-05 As usual, our ongoing internal security work was responsible for a wide range of fixes: [404324707] Various fixes from internal audits, fuzzing and other initiatives * 134.0.6998.165 This update doesn't include security fix. * 135.0.7049.52 This update includes 13 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$10000][376491759] Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs. Reported by Philipp Beer (TU Wien) on 2024-10-31 [$2000][401823929] Medium CVE-2025-3068: Inappropriate implementation in Intents. Reported by Simon Rawet on 2025-03-09 [$1000][40060076] Medium CVE-2025-3069: Inappropriate implementation in Extensions. Reported by NDevTK on 2022-06-26 [$1000][40086360] Medium CVE-2025-3070: Insufficient validation of untrusted input in Extensions. Reported by Anonymous on 2017-01-01 [$2000][40051596] Low CVE-2025-3071: Inappropriate implementation in Navigations. Reported by David Erceg on 2020-02-23 [$1000][362545037] Low CVE-2025-3072: Inappropriate implementation in Custom Tabs. Reported by Om Apip on 2024-08-27 [$500][388680893] Low CVE-2025-3073: Inappropriate implementation in Autofill. Reported by Hafiizh on 2025-01-09 [$500][392818696] Low CVE-2025-3074: Inappropriate implementation in Downloads. Reported by Farras Givari on 2025-01-28 As usual, our ongoing internal security work was responsible for a wide range of fixes: [407621901]Various fixes from internal audits, fuzzing and other initiatives * 135.0.7049.84 This update includes 2 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$4000][405140652] High CVE-2025-3066: Use after free in Site Isolation. Reported by Sven Dysthe (@@svn-dys) on 2025-03-21 As usual, our ongoing internal security work was responsible for a wide range of fixes: [409114118] Various fixes from internal audits, fuzzing and other initiatives * 135.0.7049.95 This update includes 2 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [TBD][409619251] Critical CVE-2025-3619: Heap buffer overflow in Codecs. Reported by Elias Hohl on 2025-04-09 [TBD][405292639] High CVE-2025-3620: Use after free in USB. Reported by @@retsew0x01 on 2025-03-21 * 135.0.7049.114 This update includes 1 security fix. Please see the Chrome Security Page for more information. Our ongoing internal security work was responsible for a wide range of fixes: [412443038] Various fixes from internal audits, fuzzing and other initiatives * 136.0.7103.59 This update includes 8 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$5000][409911705] High CVE-2025-4096: Heap buffer overflow in HTML. Reported by Anonymous on 2025-04-11 [$2000][409342999] Medium CVE-2025-4050: Out of bounds memory access in DevTools. Reported by Anonymous on 2025-04-09 [$2000][404000989] Medium CVE-2025-4051: Insufficient data validation in DevTools. Reported by Daniel Fröjdendahl on 2025-03-16 [$1000][401927528] Low CVE-2025-4052: Inappropriate implementation in DevTools. Reported by vanillawebdev on 2025-03-10 As usual, our ongoing internal security work was responsible for a wide range of fixes: [414433561]Various fixes from internal audits, fuzzing and other initiatives * 136.0.7103.92 This update includes 2 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [$7000][412057896] Medium CVE-2025-4372: Use after free in WebAudio. Reported by Huang Xilin of Ant Group Light-Year Security Lab on 2025-04-20 As usual, our ongoing internal security work was responsible for a wide range of fixes: [415837391] Various fixes from internal audits, fuzzing and other initiatives * 136.0.7103.113 This update includes 4 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. [N/A][415810136] High CVE-2025-4664: Insufficient policy enforcement in Loader. Source: X post from @@slonser_ on 2025-05-05 [TBD][412578726] High CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo. Reported by Micky on 2025-04-22 Google is aware of reports that an exploit for CVE-2025-4664 exists in the wild. As usual, our ongoing internal security work was responsible for a wide range of fixes: [417268830] Various fixes from internal audits, fuzzing and other initiatives @ text @d1 1 a1 1 $NetBSD: patch-.gn,v 1.1 2025/02/06 09:57:38 wiz Exp $ d7 1 a7 1 --- .gn.orig 2024-12-17 17:58:49.000000000 +0000 d9 2 a10 1 @@@@ -172,4 +172,6 @@@@ exec_script_whitelist = d12 6 a17 5 "//tools/grit/grit_rule.gni", "//tools/gritsettings/BUILD.gn", + + "//third_party/icu/BUILD.gn", ] @ 1.1 log @www/chromium: import chromium-131.0.6778.204nb1 Packaged by Robert Bagdan in wip. Thank you! Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all Internet users to experience the web. @ text @d1 1 a1 1 $NetBSD$ @