head 1.4; access; symbols pkgsrc-2026Q3:1.1.0.2 pkgsrc-2026Q3-base:1.1; locks; strict; comment @ * @; 1.4 date 2026.10.02.11.43.29; author kikadf; state Exp; branches; next 1.3; commitid H2vrlX55cZdkCTXG; 1.3 date 2026.09.29.07.42.55; author kikadf; state Exp; branches; next 1.2; commitid hkmJ6D1WIKxgnuXG; 1.2 date 2026.09.22.13.41.25; author kikadf; state Exp; branches; next 1.1; commitid NyittFkZkmblACWG; 1.1 date 2026.09.02.13.13.30; author kikadf; state Exp; branches; next ; commitid NYx0jggsE4OL43UG; desc @@ 1.4 log @chromium: update to 154.0.8037.97 * 154.0.8037.92 This update includes 32 security fixes. Please see the Chrome Security Page for more information. [TBD][551673541] Critical CVE-2026-102331: Buffer overflow in ANGLE. Reported by @@mfx on 2026-08-24 [N/A][517312707] High CVE-2026-102317: Improper privilege management in Mojo. Reported by Google on 2026-05-28 [TBD][551668264] High CVE-2026-102312: UI misrepresentation in Omnibox. Reported by jodyritonga on 2026-08-24 [N/A][556789073] High CVE-2026-102313: Uninitialized resource in ANGLE. Reported by Google on 2026-09-03 [TBD][556908674] High CVE-2026-102299: Type confusion in V8. Reported by Andrew Boni on 2026-09-04 [N/A][556926296] High CVE-2026-102306: Use after free in Bluetooth. Reported by Google on 2026-09-04 [N/A][556959073] High CVE-2026-102307: Uninitialized resource in Dawn. Reported by Google on 2026-09-04 [TBD][559266114] High CVE-2026-102323: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-10 [N/A][559727039] High CVE-2026-102303: Uninitialized resource in GPU. Reported by Google on 2026-09-10 [N/A][559737160] High CVE-2026-102311: Uninitialized resource in GPU. Reported by Google on 2026-09-10 [TBD][560062638] High CVE-2026-102300: Uninitialized resource in WebGPU. Reported by Arni Hardarson (Neonix Security) on 2026-09-11 [TBD][560233248] High CVE-2026-102326: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-11 [TBD][560238698] High CVE-2026-102316: Use after free in Views. Reported by Xinyang Ge on 2026-09-11 [TBD][560251736] High CVE-2026-102304: Use after free in Passwords. Reported by Xinyang Ge on 2026-09-11 [TBD][560536732] High CVE-2026-102328: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-12 [TBD][560867085] High CVE-2026-102309: Use after free in FullScreen. Reported by sean geofrey on 2026-09-13 [N/A][561994362] High CVE-2026-102325: Uninitialized resource in Skia. Reported by Google on 2026-09-15 [N/A][561997480] High CVE-2026-102308: Use after free in Views. Reported by Google on 2026-09-15 [N/A][562004351] High CVE-2026-102301: Out of bounds write in GPU. Reported by Google on 2026-09-15 [N/A][562042411] High CVE-2026-102319: Uninitialized resource in GPU. Reported by Google on 2026-09-15 [TBD][562174487] High CVE-2026-102324: Use after free in PictureInPicture. Reported by Blockian Creator of Kritt and Open-Kritt on 2026-09-15 [N/A][562279351] High CVE-2026-102318: Out of bounds read in WebGL. Reported by Google on 2026-09-16 [TBD][563297615] High CVE-2026-102329: Cross-site scripting in WebUI. Reported by chipsec on 2026-09-18 [N/A][563351482] High CVE-2026-102315: Uninitialized resource in Media. Reported by Google on 2026-09-18 [N/A][563716534] High CVE-2026-102302: Buffer overflow in V8. Reported by Google on 2026-09-19 [TBD][565328105] High CVE-2026-102321: Type confusion in V8. Reported by Taisic Yun (@@taisic_) of Theori, with Xint on 2026-09-23 [TBD][554038924] Medium CVE-2026-102320: Missing authorization in CORS. Reported by Anonymous on 2026-08-28 [$1,000][477726837] Low CVE-2026-102310: Missing authorization in Payments. Reported by Autodidact on 2026-01-22 [N/A][496212975] Low CVE-2026-102327: Incorrect authorization in WebView. Reported by Google on 2026-03-25 [N/A][498793976] Low CVE-2026-102330: Incorrect authorization in SiteIsolation. Reported by Google on 2026-04-02 [N/A][514059780] Low CVE-2026-102314: UI misrepresentation in TabStrip. Reported by Google on 2026-05-17 [N/A][533021953] Low CVE-2026-102305: UI misrepresentation in SignIn. Reported by Google on 2026-07-09 * 154.0.8037.97 See: https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html @ text @$NetBSD$ * Part of patchset to build chromium on NetBSD * Based on OpenBSD's chromium patches, and pkgsrc's qt5-qtwebengine patches --- components/startup_metric_utils/browser/startup_metric_utils.h.orig 2026-09-22 00:09:16.000000000 +0000 +++ components/startup_metric_utils/browser/startup_metric_utils.h @@@@ -197,7 +197,7 @@@@ class COMPONENT_EXPORT(STARTUP_METRIC_UT // Only permit construction from within GetBrowser(). BrowserStartupMetricRecorder(); -#if BUILDFLAG(IS_WIN) || BUILDFLAG(IS_MAC) || BUILDFLAG(IS_LINUX) +#if BUILDFLAG(IS_WIN) || BUILDFLAG(IS_MAC) || BUILDFLAG(IS_LINUX) || BUILDFLAG(IS_BSD) // Returns the hard fault count of the current process, or nullopt if it can't // be determined. std::optional GetHardFaultCountForCurrentProcess(); @ 1.3 log @ chromium: update to 154.0.8037.57 * 154.0.8037.57 This update includes 108 security fixes. Please see the Chrome Security Page for more information. See: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html @ text @@ 1.2 log @ chromium: update to 153.0.8010.52 * 153.0.8010.36 This update includes 230 security fixes. Please see the Chrome Security Page for more information. See: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html Google is aware that an exploit for CVE-2026-87491 exists in the wild: [$2,500][543557673] Medium CVE-2026-87491: Out of bounds write in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-06 * 153.0.8010.47 This update includes 42 security fixes. Please see the Chrome Security Page for more information. [N/A][556870863] Critical CVE-2026-91726: Out of bounds read in WebGL. Reported by Google on 2026-09-03 [TBD][557320614] Critical CVE-2026-91721: Use after free in Internals. Reported by xinyang on 2026-09-04 [TBD][558456602] Critical CVE-2026-91749: Use after free in Workers. Reported by WinD39 - Huynh Dinh Vu on 2026-09-08 [$1,500][552283275] High CVE-2026-91724: Use after free in Input. Reported by Hafiizh on 2026-08-25 [$1,000][556715288] High CVE-2026-91728: Integer overflow in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-09-03 [N/A][516780835] High CVE-2026-91734: Incorrect authorization in Core. Reported by Google on 2026-05-26 [N/A][516893912] High CVE-2026-91727: Incorrect reference resolution in Extensions. Reported by Google on 2026-05-26 [N/A][516947138] High CVE-2026-91743: Race condition in Core. Reported by Google on 2026-05-27 [N/A][520019273] High CVE-2026-91744: Race condition in PlatformIntegration. Reported by Google on 2026-06-04 [N/A][521486621] High CVE-2026-91712: Race condition in Extensions. Reported by Google on 2026-06-08 [N/A][521559611] High CVE-2026-91748: Race condition in Extensions. Reported by Google on 2026-06-09 [N/A][523470135] High CVE-2026-91720: Uninitialized resource in ANGLE. Reported by Google on 2026-06-13 [N/A][523554372] High CVE-2026-91731: Type confusion in Compositing. Reported by Google on 2026-06-13 [N/A][540016074] High CVE-2026-91747: Use after free in Skia. Reported by Google on 2026-07-28 [N/A][540021213] High CVE-2026-91733: Improper state validation in Skia. Reported by Google on 2026-07-28 [TBD][546413288] High CVE-2026-91741: Type confusion in CacheStorage. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-14 [TBD][547815507] High CVE-2026-91709: Type confusion in ServiceWorker. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17 [TBD][549225472] High CVE-2026-91717: Missing authorization in Android. Reported by jodyritonga on 2026-08-20 [N/A][552416113] High CVE-2026-91735: Incorrect authorization in WebUI. Reported by Google on 2026-08-25 [N/A][553115724] High CVE-2026-91708: Race condition in Network. Reported by Google on 2026-08-26 [N/A][553121008] High CVE-2026-91736: Use after free in DOM. Reported by Google on 2026-08-26 [N/A][553122373] High CVE-2026-91740: Uninitialized resource in Skia. Reported by Google on 2026-08-26 [N/A][553132148] High CVE-2026-91710: Use after free in WebAppInstalls. Reported by Google on 2026-08-26 [N/A][553133215] High CVE-2026-91718: Use after free in Core. Reported by Google on 2026-08-26 [N/A][554558368] High CVE-2026-91716: Use after free in Auth. Reported by Google on 2026-08-29 [N/A][556260782] High CVE-2026-91746: Integer overflow in Compositing. Reported by Google on 2026-09-02 [TBD][557206809] High CVE-2026-91729: Use after free in DigitalCredentials. Reported by sean geofrey on 2026-09-04 [TBD][558036280] High CVE-2026-91737: Use after free in PDF. Reported by SeungMyung Lee (@@sm1ee), Siung kim (@@ksw9722) on 2026-09-06 [TBD][558342353] High CVE-2026-91711: Out of bounds write in ServiceWorker. Reported by Cristian Di Nicola (@@crih.exe) on 2026-09-07 [TBD][558367547] High CVE-2026-91715: Type confusion in ServiceWorker. Reported by Cristian Di Nicola (@@crih.exe) on 2026-09-07 [N/A][558734727] High CVE-2026-91745: Use after free in V8. Reported by Google on 2026-09-08 [TBD][474131239] Medium CVE-2026-91723: Race condition in WebAppInstalls. Reported by Luan Herrera (@@lbherrera_) on 2026-01-07 [TBD][511062248] Medium CVE-2026-91732: Missing authorization in AppManifest. Reported by pakhunov.anton.n on 2026-05-08 [N/A][513858387] Medium CVE-2026-91742: Confused deputy in PriceTracking. Reported by Google on 2026-05-16 [N/A][517710554] Medium CVE-2026-91714: Observable discrepancy in Fonts. Reported by Google on 2026-05-29 [N/A][518032534] Medium CVE-2026-91725: Observable discrepancy in CSS. Reported by Google on 2026-05-29 [N/A][521951328] Medium CVE-2026-91739: Missing authorization in Transactions Platform. Reported by Google on 2026-06-09 [N/A][523715133] Medium CVE-2026-91713: Missing authorization in Browser. Reported by Google on 2026-06-14 [N/A][536450979] Medium CVE-2026-91738: Improper input validation in ANGLE. Reported by Google on 2026-07-19 [TBD][543640868] Medium CVE-2026-91730: Incomplete cleanup in GetUserMedia. Reported by Keita Sode and Daisuke Hatakeyama (SYZD Research) on 2026-08-07 [TBD][554953456] Medium CVE-2026-91722: Use after free in Input. Reported by TIENPA on 2026-08-31 [TBD][542115030] Low CVE-2026-91719: Code injection in XML. Reported by Zabith Mohammed (@@nmzabith) on 2026-08-03 * 153.0.8010.52 This update includes 16 security fixes. Please see the Chrome Security Page for more information. [TBD][500417361] Critical CVE-2026-93374: Use after free in Dawn. Reported by Florian Schweitzer on 2026-04-08 [N/A][548085797] Critical CVE-2026-93372: Buffer overflow in WebGL. Reported by Google on 2026-08-17 [$3,000][550839154] High CVE-2026-93375: Incorrect reference resolution in Tracing. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-08-22 [TBD][541707261] High CVE-2026-93382: Use after free in PDFium. Reported by WinD39 - Huynh Dinh Vu on 2026-08-02 [N/A][553130676] High CVE-2026-93387: Improper state validation in Skia. Reported by Google on 2026-08-26 [N/A][553132214] High CVE-2026-93373: Use after free in Extensions. Reported by Google on 2026-08-26 [TBD][556853443] High CVE-2026-93381: Buffer overflow in PDFium. Reported by SeungMyung Lee (@@sm1ee), Siung kim (@@ksw9722) on 2026-09-03 [TBD][560039872] High CVE-2026-93379: Incorrect authorization in ORB. Reported by OGINOME Tomohito on 2026-09-11 [N/A][560121552] High CVE-2026-93377: Type confusion in V8. Reported by Google on 2026-09-11 [N/A][498411599] Medium CVE-2026-93380: Race condition in FileSystem. Reported by Google on 2026-04-01 [N/A][511832293] Medium CVE-2026-93384: Server-side request forgery in Omnibox. Reported by Google on 2026-05-10 [N/A][515493668] Medium CVE-2026-93383: Information leak in Permissions. Reported by Google on 2026-05-22 [N/A][520521197] Medium CVE-2026-93376: Out of bounds read in DataTransfer. Reported by Google on 2026-06-05 [N/A][540051167] Medium CVE-2026-93378: Missing authorization in Storage. Reported by Google on 2026-07-28 [N/A][553136980] Medium CVE-2026-93385: Information leak in Paint. Reported by Google on 2026-08-26 [N/A][513996595] Low CVE-2026-93386: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-17 @ text @d7 1 a7 1 --- components/startup_metric_utils/browser/startup_metric_utils.h.orig 2026-09-14 22:17:16.000000000 +0000 @ 1.1 log @ chromium: update to 152.0.7977.75 * 152.0.7977.75 This update includes 26 security fixes. Please see the Chrome Security Page for more information. [N/A][522307103] Critical CVE-2026-84353: Use after free in Shared Tab Groups. Reported by Google on 2026-06-10 [N/A][546260492] Critical CVE-2026-84352: Use after free in WebGL. Reported by Google on 2026-08-14 [N/A][498839176] High CVE-2026-84354: Incorrect authorization in FileSystem. Reported by Google on 2026-04-02 [N/A][514078656] High CVE-2026-84359: Information leak in Skia. Reported by Google on 2026-05-17 [N/A][523208474] High CVE-2026-84357: Improper input validation in Omnibox. Reported by Google on 2026-06-12 [N/A][533534913] High CVE-2026-84324: Use after free in Proxy. Reported by Google on 2026-07-10 [N/A][537105664] High CVE-2026-84349: Use after free in Browser. Reported by Google on 2026-07-21 [TBD][547936520] High CVE-2026-84326: Uninitialized resource in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17 [N/A][549311485] High CVE-2026-84333: Use after free in Dawn. Reported by Google on 2026-08-19 [TBD][551593376] High CVE-2026-84351: Buffer overflow in GPU. Reported by Cassio Lima on 2026-08-24 [N/A][553117928] High CVE-2026-84325: Improper input validation in DataTransfer. Reported by Google on 2026-08-26 [N/A][498710886] Medium CVE-2026-84328: Missing authorization in FileSystem. Reported by Google on 2026-04-01 [N/A][501679156] Medium CVE-2026-84347: Use after free in WebRTC. Reported by Google on 2026-04-11 [N/A][502411391] Medium CVE-2026-84323: Missing authorization in FileSystem. Reported by Google on 2026-04-14 [N/A][511774376] Medium CVE-2026-84355: Incorrect authorization in Navigation. Reported by Google on 2026-05-10 [N/A][514006886] Medium CVE-2026-84358: Improper privilege management in Downloads. Reported by Google on 2026-05-17 [N/A][514489238] Medium CVE-2026-84332: Incorrect authorization in SiteSettings. Reported by Google on 2026-05-19 [N/A][517091927] Medium CVE-2026-84330: UI misrepresentation in FullScreen. Reported by Google on 2026-05-27 [N/A][517798926] Medium CVE-2026-84334: Incorrect authorization in Chromoting. Reported by Google on 2026-05-29 [N/A][518100026] Medium CVE-2026-84348: Information leak in MediaCapture. Reported by Google on 2026-05-30 [N/A][522302504] Medium CVE-2026-84335: Incorrect authorization in TabStrip. Reported by Google on 2026-06-10 [N/A][498725213] Low CVE-2026-84327: Incorrect authorization in Autofill. Reported by Google on 2026-04-01 [N/A][498850269] Low CVE-2026-84329: Confused deputy in CredentialProvider. Reported by Google on 2026-04-02 [TBD][503787232] Low CVE-2026-84356: UI misrepresentation in FullScreen. Reported by Francesco Topol (k4tedu) on 2026-04-18 [N/A][513713427] Low CVE-2026-84350: Use after free in TabStrip. Reported by Google on 2026-05-16 [N/A][521753402] Low CVE-2026-84331: Incorrect authorization in Actor. Reported by Google on 2026-06-09 * 152.0.7977.64 This update includes 327 security fixes. Please see the Chrome Security Page for more information. See: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html @ text @d7 1 a7 1 --- components/startup_metric_utils/browser/startup_metric_utils.h.orig 2026-08-31 22:47:51.000000000 +0000 @