head 1.3; access; symbols; locks; strict; comment @// @; 1.3 date 2026.10.02.11.43.28; author kikadf; state Exp; branches; next 1.2; commitid H2vrlX55cZdkCTXG; 1.2 date 2026.09.29.07.42.55; author kikadf; state Exp; branches; next 1.1; commitid hkmJ6D1WIKxgnuXG; 1.1 date 2026.09.22.13.41.24; author kikadf; state Exp; branches; next ; commitid NyittFkZkmblACWG; desc @@ 1.3 log @chromium: update to 154.0.8037.97 * 154.0.8037.92 This update includes 32 security fixes. Please see the Chrome Security Page for more information. [TBD][551673541] Critical CVE-2026-102331: Buffer overflow in ANGLE. Reported by @@mfx on 2026-08-24 [N/A][517312707] High CVE-2026-102317: Improper privilege management in Mojo. Reported by Google on 2026-05-28 [TBD][551668264] High CVE-2026-102312: UI misrepresentation in Omnibox. Reported by jodyritonga on 2026-08-24 [N/A][556789073] High CVE-2026-102313: Uninitialized resource in ANGLE. Reported by Google on 2026-09-03 [TBD][556908674] High CVE-2026-102299: Type confusion in V8. Reported by Andrew Boni on 2026-09-04 [N/A][556926296] High CVE-2026-102306: Use after free in Bluetooth. Reported by Google on 2026-09-04 [N/A][556959073] High CVE-2026-102307: Uninitialized resource in Dawn. Reported by Google on 2026-09-04 [TBD][559266114] High CVE-2026-102323: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-10 [N/A][559727039] High CVE-2026-102303: Uninitialized resource in GPU. Reported by Google on 2026-09-10 [N/A][559737160] High CVE-2026-102311: Uninitialized resource in GPU. Reported by Google on 2026-09-10 [TBD][560062638] High CVE-2026-102300: Uninitialized resource in WebGPU. Reported by Arni Hardarson (Neonix Security) on 2026-09-11 [TBD][560233248] High CVE-2026-102326: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-11 [TBD][560238698] High CVE-2026-102316: Use after free in Views. Reported by Xinyang Ge on 2026-09-11 [TBD][560251736] High CVE-2026-102304: Use after free in Passwords. Reported by Xinyang Ge on 2026-09-11 [TBD][560536732] High CVE-2026-102328: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-12 [TBD][560867085] High CVE-2026-102309: Use after free in FullScreen. Reported by sean geofrey on 2026-09-13 [N/A][561994362] High CVE-2026-102325: Uninitialized resource in Skia. Reported by Google on 2026-09-15 [N/A][561997480] High CVE-2026-102308: Use after free in Views. Reported by Google on 2026-09-15 [N/A][562004351] High CVE-2026-102301: Out of bounds write in GPU. Reported by Google on 2026-09-15 [N/A][562042411] High CVE-2026-102319: Uninitialized resource in GPU. Reported by Google on 2026-09-15 [TBD][562174487] High CVE-2026-102324: Use after free in PictureInPicture. Reported by Blockian Creator of Kritt and Open-Kritt on 2026-09-15 [N/A][562279351] High CVE-2026-102318: Out of bounds read in WebGL. Reported by Google on 2026-09-16 [TBD][563297615] High CVE-2026-102329: Cross-site scripting in WebUI. Reported by chipsec on 2026-09-18 [N/A][563351482] High CVE-2026-102315: Uninitialized resource in Media. Reported by Google on 2026-09-18 [N/A][563716534] High CVE-2026-102302: Buffer overflow in V8. Reported by Google on 2026-09-19 [TBD][565328105] High CVE-2026-102321: Type confusion in V8. Reported by Taisic Yun (@@taisic_) of Theori, with Xint on 2026-09-23 [TBD][554038924] Medium CVE-2026-102320: Missing authorization in CORS. Reported by Anonymous on 2026-08-28 [$1,000][477726837] Low CVE-2026-102310: Missing authorization in Payments. Reported by Autodidact on 2026-01-22 [N/A][496212975] Low CVE-2026-102327: Incorrect authorization in WebView. Reported by Google on 2026-03-25 [N/A][498793976] Low CVE-2026-102330: Incorrect authorization in SiteIsolation. Reported by Google on 2026-04-02 [N/A][514059780] Low CVE-2026-102314: UI misrepresentation in TabStrip. Reported by Google on 2026-05-17 [N/A][533021953] Low CVE-2026-102305: UI misrepresentation in SignIn. Reported by Google on 2026-07-09 * 154.0.8037.97 See: https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html @ text @$NetBSD$ * Part of patchset to build chromium on NetBSD * Based on OpenBSD's chromium patches, and pkgsrc's qt5-qtwebengine patches --- components/private_ai/proto_utils/client_metadata_utils.cc.orig 2026-09-22 00:09:16.000000000 +0000 +++ components/private_ai/proto_utils/client_metadata_utils.cc @@@@ -41,7 +41,7 @@@@ proto::ChromeClientMetadata::Platform Ge return proto::ChromeClientMetadata::PLATFORM_ANDROID; #elif BUILDFLAG(IS_IOS) return proto::ChromeClientMetadata::PLATFORM_IOS; -#elif BUILDFLAG(IS_LINUX) +#elif BUILDFLAG(IS_LINUX) || BUILDFLAG(IS_BSD) return proto::ChromeClientMetadata::PLATFORM_LINUX; #else return proto::ChromeClientMetadata::PLATFORM_UNKNOWN; @ 1.2 log @ chromium: update to 154.0.8037.57 * 154.0.8037.57 This update includes 108 security fixes. Please see the Chrome Security Page for more information. See: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html @ text @@ 1.1 log @ chromium: update to 153.0.8010.52 * 153.0.8010.36 This update includes 230 security fixes. Please see the Chrome Security Page for more information. See: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html Google is aware that an exploit for CVE-2026-87491 exists in the wild: [$2,500][543557673] Medium CVE-2026-87491: Out of bounds write in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-06 * 153.0.8010.47 This update includes 42 security fixes. Please see the Chrome Security Page for more information. [N/A][556870863] Critical CVE-2026-91726: Out of bounds read in WebGL. Reported by Google on 2026-09-03 [TBD][557320614] Critical CVE-2026-91721: Use after free in Internals. Reported by xinyang on 2026-09-04 [TBD][558456602] Critical CVE-2026-91749: Use after free in Workers. Reported by WinD39 - Huynh Dinh Vu on 2026-09-08 [$1,500][552283275] High CVE-2026-91724: Use after free in Input. Reported by Hafiizh on 2026-08-25 [$1,000][556715288] High CVE-2026-91728: Integer overflow in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-09-03 [N/A][516780835] High CVE-2026-91734: Incorrect authorization in Core. Reported by Google on 2026-05-26 [N/A][516893912] High CVE-2026-91727: Incorrect reference resolution in Extensions. Reported by Google on 2026-05-26 [N/A][516947138] High CVE-2026-91743: Race condition in Core. Reported by Google on 2026-05-27 [N/A][520019273] High CVE-2026-91744: Race condition in PlatformIntegration. Reported by Google on 2026-06-04 [N/A][521486621] High CVE-2026-91712: Race condition in Extensions. Reported by Google on 2026-06-08 [N/A][521559611] High CVE-2026-91748: Race condition in Extensions. Reported by Google on 2026-06-09 [N/A][523470135] High CVE-2026-91720: Uninitialized resource in ANGLE. Reported by Google on 2026-06-13 [N/A][523554372] High CVE-2026-91731: Type confusion in Compositing. Reported by Google on 2026-06-13 [N/A][540016074] High CVE-2026-91747: Use after free in Skia. Reported by Google on 2026-07-28 [N/A][540021213] High CVE-2026-91733: Improper state validation in Skia. Reported by Google on 2026-07-28 [TBD][546413288] High CVE-2026-91741: Type confusion in CacheStorage. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-14 [TBD][547815507] High CVE-2026-91709: Type confusion in ServiceWorker. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17 [TBD][549225472] High CVE-2026-91717: Missing authorization in Android. Reported by jodyritonga on 2026-08-20 [N/A][552416113] High CVE-2026-91735: Incorrect authorization in WebUI. Reported by Google on 2026-08-25 [N/A][553115724] High CVE-2026-91708: Race condition in Network. Reported by Google on 2026-08-26 [N/A][553121008] High CVE-2026-91736: Use after free in DOM. Reported by Google on 2026-08-26 [N/A][553122373] High CVE-2026-91740: Uninitialized resource in Skia. Reported by Google on 2026-08-26 [N/A][553132148] High CVE-2026-91710: Use after free in WebAppInstalls. Reported by Google on 2026-08-26 [N/A][553133215] High CVE-2026-91718: Use after free in Core. Reported by Google on 2026-08-26 [N/A][554558368] High CVE-2026-91716: Use after free in Auth. Reported by Google on 2026-08-29 [N/A][556260782] High CVE-2026-91746: Integer overflow in Compositing. Reported by Google on 2026-09-02 [TBD][557206809] High CVE-2026-91729: Use after free in DigitalCredentials. Reported by sean geofrey on 2026-09-04 [TBD][558036280] High CVE-2026-91737: Use after free in PDF. Reported by SeungMyung Lee (@@sm1ee), Siung kim (@@ksw9722) on 2026-09-06 [TBD][558342353] High CVE-2026-91711: Out of bounds write in ServiceWorker. Reported by Cristian Di Nicola (@@crih.exe) on 2026-09-07 [TBD][558367547] High CVE-2026-91715: Type confusion in ServiceWorker. Reported by Cristian Di Nicola (@@crih.exe) on 2026-09-07 [N/A][558734727] High CVE-2026-91745: Use after free in V8. Reported by Google on 2026-09-08 [TBD][474131239] Medium CVE-2026-91723: Race condition in WebAppInstalls. Reported by Luan Herrera (@@lbherrera_) on 2026-01-07 [TBD][511062248] Medium CVE-2026-91732: Missing authorization in AppManifest. Reported by pakhunov.anton.n on 2026-05-08 [N/A][513858387] Medium CVE-2026-91742: Confused deputy in PriceTracking. Reported by Google on 2026-05-16 [N/A][517710554] Medium CVE-2026-91714: Observable discrepancy in Fonts. Reported by Google on 2026-05-29 [N/A][518032534] Medium CVE-2026-91725: Observable discrepancy in CSS. Reported by Google on 2026-05-29 [N/A][521951328] Medium CVE-2026-91739: Missing authorization in Transactions Platform. Reported by Google on 2026-06-09 [N/A][523715133] Medium CVE-2026-91713: Missing authorization in Browser. Reported by Google on 2026-06-14 [N/A][536450979] Medium CVE-2026-91738: Improper input validation in ANGLE. Reported by Google on 2026-07-19 [TBD][543640868] Medium CVE-2026-91730: Incomplete cleanup in GetUserMedia. Reported by Keita Sode and Daisuke Hatakeyama (SYZD Research) on 2026-08-07 [TBD][554953456] Medium CVE-2026-91722: Use after free in Input. Reported by TIENPA on 2026-08-31 [TBD][542115030] Low CVE-2026-91719: Code injection in XML. Reported by Zabith Mohammed (@@nmzabith) on 2026-08-03 * 153.0.8010.52 This update includes 16 security fixes. Please see the Chrome Security Page for more information. [TBD][500417361] Critical CVE-2026-93374: Use after free in Dawn. Reported by Florian Schweitzer on 2026-04-08 [N/A][548085797] Critical CVE-2026-93372: Buffer overflow in WebGL. Reported by Google on 2026-08-17 [$3,000][550839154] High CVE-2026-93375: Incorrect reference resolution in Tracing. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-08-22 [TBD][541707261] High CVE-2026-93382: Use after free in PDFium. Reported by WinD39 - Huynh Dinh Vu on 2026-08-02 [N/A][553130676] High CVE-2026-93387: Improper state validation in Skia. Reported by Google on 2026-08-26 [N/A][553132214] High CVE-2026-93373: Use after free in Extensions. Reported by Google on 2026-08-26 [TBD][556853443] High CVE-2026-93381: Buffer overflow in PDFium. Reported by SeungMyung Lee (@@sm1ee), Siung kim (@@ksw9722) on 2026-09-03 [TBD][560039872] High CVE-2026-93379: Incorrect authorization in ORB. Reported by OGINOME Tomohito on 2026-09-11 [N/A][560121552] High CVE-2026-93377: Type confusion in V8. Reported by Google on 2026-09-11 [N/A][498411599] Medium CVE-2026-93380: Race condition in FileSystem. Reported by Google on 2026-04-01 [N/A][511832293] Medium CVE-2026-93384: Server-side request forgery in Omnibox. Reported by Google on 2026-05-10 [N/A][515493668] Medium CVE-2026-93383: Information leak in Permissions. Reported by Google on 2026-05-22 [N/A][520521197] Medium CVE-2026-93376: Out of bounds read in DataTransfer. Reported by Google on 2026-06-05 [N/A][540051167] Medium CVE-2026-93378: Missing authorization in Storage. Reported by Google on 2026-07-28 [N/A][553136980] Medium CVE-2026-93385: Information leak in Paint. Reported by Google on 2026-08-26 [N/A][513996595] Low CVE-2026-93386: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-17 @ text @d7 1 a7 1 --- components/private_ai/proto_utils/client_metadata_utils.cc.orig 2026-09-14 22:17:16.000000000 +0000 @