head	1.10;
access;
symbols
	pkgsrc-2026Q3:1.7.0.2
	pkgsrc-2026Q3-base:1.7
	pkgsrc-2026Q2:1.3.0.2
	pkgsrc-2026Q2-base:1.3;
locks; strict;
comment	@# @;


1.10
date	2026.10.02.11.43.37;	author kikadf;	state Exp;
branches;
next	1.9;
commitid	H2vrlX55cZdkCTXG;

1.9
date	2026.09.29.07.43.05;	author kikadf;	state Exp;
branches;
next	1.8;
commitid	hkmJ6D1WIKxgnuXG;

1.8
date	2026.09.22.13.41.32;	author kikadf;	state Exp;
branches;
next	1.7;
commitid	NyittFkZkmblACWG;

1.7
date	2026.09.02.13.13.37;	author kikadf;	state Exp;
branches;
next	1.6;
commitid	NYx0jggsE4OL43UG;

1.6
date	2026.08.09.06.31.23;	author kikadf;	state Exp;
branches;
next	1.5;
commitid	8RN084OnLnGuCVQG;

1.5
date	2026.07.08.13.42.30;	author kikadf;	state Exp;
branches;
next	1.4;
commitid	TrothZVUWCiZ0RMG;

1.4
date	2026.07.06.13.06.58;	author kikadf;	state Exp;
branches;
next	1.3;
commitid	5JFQu3OxURxXTAMG;

1.3
date	2026.06.08.13.12.47;	author kikadf;	state Exp;
branches;
next	1.2;
commitid	Zzd0Bp9ZEsatPZIG;

1.2
date	2026.06.01.10.09.21;	author kikadf;	state Exp;
branches;
next	1.1;
commitid	48lBuM9fEuUE15IG;

1.1
date	2026.05.10.15.30.05;	author kikadf;	state Exp;
branches;
next	;
commitid	SyX3h0lYaSxpwhFG;


desc
@@


1.10
log
@chromium: update to 154.0.8037.97

* 154.0.8037.92
This update includes 32 security fixes. Please see the Chrome Security Page for more information.

[TBD][551673541] Critical CVE-2026-102331: Buffer overflow in ANGLE. Reported by @@mfx on 2026-08-24
[N/A][517312707] High CVE-2026-102317: Improper privilege management in Mojo. Reported by Google on 2026-05-28
[TBD][551668264] High CVE-2026-102312: UI misrepresentation in Omnibox. Reported by jodyritonga on 2026-08-24
[N/A][556789073] High CVE-2026-102313: Uninitialized resource in ANGLE. Reported by Google on 2026-09-03
[TBD][556908674] High CVE-2026-102299: Type confusion in V8. Reported by Andrew Boni on 2026-09-04
[N/A][556926296] High CVE-2026-102306: Use after free in Bluetooth. Reported by Google on 2026-09-04
[N/A][556959073] High CVE-2026-102307: Uninitialized resource in Dawn. Reported by Google on 2026-09-04
[TBD][559266114] High CVE-2026-102323: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-10
[N/A][559727039] High CVE-2026-102303: Uninitialized resource in GPU. Reported by Google on 2026-09-10
[N/A][559737160] High CVE-2026-102311: Uninitialized resource in GPU. Reported by Google on 2026-09-10
[TBD][560062638] High CVE-2026-102300: Uninitialized resource in WebGPU. Reported by Arni Hardarson (Neonix Security) on 2026-09-11
[TBD][560233248] High CVE-2026-102326: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-11
[TBD][560238698] High CVE-2026-102316: Use after free in Views. Reported by Xinyang Ge on 2026-09-11
[TBD][560251736] High CVE-2026-102304: Use after free in Passwords. Reported by Xinyang Ge on 2026-09-11
[TBD][560536732] High CVE-2026-102328: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-12
[TBD][560867085] High CVE-2026-102309: Use after free in FullScreen. Reported by sean geofrey on 2026-09-13
[N/A][561994362] High CVE-2026-102325: Uninitialized resource in Skia. Reported by Google on 2026-09-15
[N/A][561997480] High CVE-2026-102308: Use after free in Views. Reported by Google on 2026-09-15
[N/A][562004351] High CVE-2026-102301: Out of bounds write in GPU. Reported by Google on 2026-09-15
[N/A][562042411] High CVE-2026-102319: Uninitialized resource in GPU. Reported by Google on 2026-09-15
[TBD][562174487] High CVE-2026-102324: Use after free in PictureInPicture. Reported by Blockian Creator of Kritt and Open-Kritt on 2026-09-15
[N/A][562279351] High CVE-2026-102318: Out of bounds read in WebGL. Reported by Google on 2026-09-16
[TBD][563297615] High CVE-2026-102329: Cross-site scripting in WebUI. Reported by chipsec on 2026-09-18
[N/A][563351482] High CVE-2026-102315: Uninitialized resource in Media. Reported by Google on 2026-09-18
[N/A][563716534] High CVE-2026-102302: Buffer overflow in V8. Reported by Google on 2026-09-19
[TBD][565328105] High CVE-2026-102321: Type confusion in V8. Reported by Taisic Yun (@@taisic_) of Theori, with Xint on 2026-09-23
[TBD][554038924] Medium CVE-2026-102320: Missing authorization in CORS. Reported by Anonymous on 2026-08-28
[$1,000][477726837] Low CVE-2026-102310: Missing authorization in Payments. Reported by Autodidact on 2026-01-22
[N/A][496212975] Low CVE-2026-102327: Incorrect authorization in WebView. Reported by Google on 2026-03-25
[N/A][498793976] Low CVE-2026-102330: Incorrect authorization in SiteIsolation. Reported by Google on 2026-04-02
[N/A][514059780] Low CVE-2026-102314: UI misrepresentation in TabStrip. Reported by Google on 2026-05-17
[N/A][533021953] Low CVE-2026-102305: UI misrepresentation in SignIn. Reported by Google on 2026-07-09

* 154.0.8037.97

See: https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop.html
@
text
@$NetBSD$

* Part of patchset to build chromium on NetBSD
* Based on OpenBSD's chromium patches, and
  pkgsrc's qt5-qtwebengine patches

--- third_party/litert/features.gni.orig	2026-09-22 00:09:16.000000000 +0000
+++ third_party/litert/features.gni
@@@@ -4,5 +4,5 @@@@
 
 declare_args() {
   # This enables building LiteRT with XNNPACK.
-  build_litert_with_xnnpack = current_cpu != "arm" && !is_fuchsia
+  build_litert_with_xnnpack = current_cpu != "arm" && !is_fuchsia && !is_bsd
 }
@


1.9
log
@
chromium: update to 154.0.8037.57

* 154.0.8037.57
This update includes 108 security fixes. Please see the Chrome Security Page for more information.

See: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html
@
text
@@


1.8
log
@
chromium: update to 153.0.8010.52

* 153.0.8010.36
This update includes 230 security fixes. Please see the Chrome Security Page for more information.

See: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html

Google is aware that an exploit for CVE-2026-87491 exists in the wild:
[$2,500][543557673] Medium CVE-2026-87491: Out of bounds write in V8.
Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-06

* 153.0.8010.47
This update includes 42 security fixes. Please see the Chrome Security Page for more information.

[N/A][556870863] Critical CVE-2026-91726: Out of bounds read in WebGL. Reported by Google on 2026-09-03
[TBD][557320614] Critical CVE-2026-91721: Use after free in Internals. Reported by xinyang on 2026-09-04
[TBD][558456602] Critical CVE-2026-91749: Use after free in Workers. Reported by WinD39 - Huynh Dinh Vu on 2026-09-08
[$1,500][552283275] High CVE-2026-91724: Use after free in Input. Reported by Hafiizh on 2026-08-25
[$1,000][556715288] High CVE-2026-91728: Integer overflow in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-09-03
[N/A][516780835] High CVE-2026-91734: Incorrect authorization in Core. Reported by Google on 2026-05-26
[N/A][516893912] High CVE-2026-91727: Incorrect reference resolution in Extensions. Reported by Google on 2026-05-26
[N/A][516947138] High CVE-2026-91743: Race condition in Core. Reported by Google on 2026-05-27
[N/A][520019273] High CVE-2026-91744: Race condition in PlatformIntegration. Reported by Google on 2026-06-04
[N/A][521486621] High CVE-2026-91712: Race condition in Extensions. Reported by Google on 2026-06-08
[N/A][521559611] High CVE-2026-91748: Race condition in Extensions. Reported by Google on 2026-06-09
[N/A][523470135] High CVE-2026-91720: Uninitialized resource in ANGLE. Reported by Google on 2026-06-13
[N/A][523554372] High CVE-2026-91731: Type confusion in Compositing. Reported by Google on 2026-06-13
[N/A][540016074] High CVE-2026-91747: Use after free in Skia. Reported by Google on 2026-07-28
[N/A][540021213] High CVE-2026-91733: Improper state validation in Skia. Reported by Google on 2026-07-28
[TBD][546413288] High CVE-2026-91741: Type confusion in CacheStorage. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-14
[TBD][547815507] High CVE-2026-91709: Type confusion in ServiceWorker. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17
[TBD][549225472] High CVE-2026-91717: Missing authorization in Android. Reported by jodyritonga on 2026-08-20
[N/A][552416113] High CVE-2026-91735: Incorrect authorization in WebUI. Reported by Google on 2026-08-25
[N/A][553115724] High CVE-2026-91708: Race condition in Network. Reported by Google on 2026-08-26
[N/A][553121008] High CVE-2026-91736: Use after free in DOM. Reported by Google on 2026-08-26
[N/A][553122373] High CVE-2026-91740: Uninitialized resource in Skia. Reported by Google on 2026-08-26
[N/A][553132148] High CVE-2026-91710: Use after free in WebAppInstalls. Reported by Google on 2026-08-26
[N/A][553133215] High CVE-2026-91718: Use after free in Core. Reported by Google on 2026-08-26
[N/A][554558368] High CVE-2026-91716: Use after free in Auth. Reported by Google on 2026-08-29
[N/A][556260782] High CVE-2026-91746: Integer overflow in Compositing. Reported by Google on 2026-09-02
[TBD][557206809] High CVE-2026-91729: Use after free in DigitalCredentials. Reported by sean geofrey on 2026-09-04
[TBD][558036280] High CVE-2026-91737: Use after free in PDF. Reported by SeungMyung Lee (@@sm1ee), Siung kim (@@ksw9722) on 2026-09-06
[TBD][558342353] High CVE-2026-91711: Out of bounds write in ServiceWorker. Reported by Cristian Di Nicola (@@crih.exe) on 2026-09-07
[TBD][558367547] High CVE-2026-91715: Type confusion in ServiceWorker. Reported by Cristian Di Nicola (@@crih.exe) on 2026-09-07
[N/A][558734727] High CVE-2026-91745: Use after free in V8. Reported by Google on 2026-09-08
[TBD][474131239] Medium CVE-2026-91723: Race condition in WebAppInstalls. Reported by Luan Herrera (@@lbherrera_) on 2026-01-07
[TBD][511062248] Medium CVE-2026-91732: Missing authorization in AppManifest. Reported by pakhunov.anton.n on 2026-05-08
[N/A][513858387] Medium CVE-2026-91742: Confused deputy in PriceTracking. Reported by Google on 2026-05-16
[N/A][517710554] Medium CVE-2026-91714: Observable discrepancy in Fonts. Reported by Google on 2026-05-29
[N/A][518032534] Medium CVE-2026-91725: Observable discrepancy in CSS. Reported by Google on 2026-05-29
[N/A][521951328] Medium CVE-2026-91739: Missing authorization in Transactions Platform. Reported by Google on 2026-06-09
[N/A][523715133] Medium CVE-2026-91713: Missing authorization in Browser. Reported by Google on 2026-06-14
[N/A][536450979] Medium CVE-2026-91738: Improper input validation in ANGLE. Reported by Google on 2026-07-19
[TBD][543640868] Medium CVE-2026-91730: Incomplete cleanup in GetUserMedia. Reported by Keita Sode and Daisuke Hatakeyama (SYZD Research) on 2026-08-07
[TBD][554953456] Medium CVE-2026-91722: Use after free in Input. Reported by TIENPA on 2026-08-31
[TBD][542115030] Low CVE-2026-91719: Code injection in XML. Reported by Zabith Mohammed (@@nmzabith) on 2026-08-03

* 153.0.8010.52
This update includes 16 security fixes. Please see the Chrome Security Page for more information.

[TBD][500417361] Critical CVE-2026-93374: Use after free in Dawn. Reported by Florian Schweitzer on 2026-04-08
[N/A][548085797] Critical CVE-2026-93372: Buffer overflow in WebGL. Reported by Google on 2026-08-17
[$3,000][550839154] High CVE-2026-93375: Incorrect reference resolution in Tracing. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-08-22
[TBD][541707261] High CVE-2026-93382: Use after free in PDFium. Reported by WinD39 - Huynh Dinh Vu on 2026-08-02
[N/A][553130676] High CVE-2026-93387: Improper state validation in Skia. Reported by Google on 2026-08-26
[N/A][553132214] High CVE-2026-93373: Use after free in Extensions. Reported by Google on 2026-08-26
[TBD][556853443] High CVE-2026-93381: Buffer overflow in PDFium. Reported by SeungMyung Lee (@@sm1ee), Siung kim (@@ksw9722) on 2026-09-03
[TBD][560039872] High CVE-2026-93379: Incorrect authorization in ORB. Reported by OGINOME Tomohito on 2026-09-11
[N/A][560121552] High CVE-2026-93377: Type confusion in V8. Reported by Google on 2026-09-11
[N/A][498411599] Medium CVE-2026-93380: Race condition in FileSystem. Reported by Google on 2026-04-01
[N/A][511832293] Medium CVE-2026-93384: Server-side request forgery in Omnibox. Reported by Google on 2026-05-10
[N/A][515493668] Medium CVE-2026-93383: Information leak in Permissions. Reported by Google on 2026-05-22
[N/A][520521197] Medium CVE-2026-93376: Out of bounds read in DataTransfer. Reported by Google on 2026-06-05
[N/A][540051167] Medium CVE-2026-93378: Missing authorization in Storage. Reported by Google on 2026-07-28
[N/A][553136980] Medium CVE-2026-93385: Information leak in Paint. Reported by Google on 2026-08-26
[N/A][513996595] Low CVE-2026-93386: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-05-17
@
text
@d7 1
a7 1
--- third_party/litert/features.gni.orig	2026-09-14 22:17:16.000000000 +0000
@


1.7
log
@
chromium: update to 152.0.7977.75

* 152.0.7977.75
This update includes 26 security fixes. Please see the Chrome Security Page for more information.

[N/A][522307103] Critical CVE-2026-84353: Use after free in Shared Tab Groups. Reported by Google on 2026-06-10
[N/A][546260492] Critical CVE-2026-84352: Use after free in WebGL. Reported by Google on 2026-08-14
[N/A][498839176] High CVE-2026-84354: Incorrect authorization in FileSystem. Reported by Google on 2026-04-02
[N/A][514078656] High CVE-2026-84359: Information leak in Skia. Reported by Google on 2026-05-17
[N/A][523208474] High CVE-2026-84357: Improper input validation in Omnibox. Reported by Google on 2026-06-12
[N/A][533534913] High CVE-2026-84324: Use after free in Proxy. Reported by Google on 2026-07-10
[N/A][537105664] High CVE-2026-84349: Use after free in Browser. Reported by Google on 2026-07-21
[TBD][547936520] High CVE-2026-84326: Uninitialized resource in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17
[N/A][549311485] High CVE-2026-84333: Use after free in Dawn. Reported by Google on 2026-08-19
[TBD][551593376] High CVE-2026-84351: Buffer overflow in GPU. Reported by Cassio Lima on 2026-08-24
[N/A][553117928] High CVE-2026-84325: Improper input validation in DataTransfer. Reported by Google on 2026-08-26
[N/A][498710886] Medium CVE-2026-84328: Missing authorization in FileSystem. Reported by Google on 2026-04-01
[N/A][501679156] Medium CVE-2026-84347: Use after free in WebRTC. Reported by Google on 2026-04-11
[N/A][502411391] Medium CVE-2026-84323: Missing authorization in FileSystem. Reported by Google on 2026-04-14
[N/A][511774376] Medium CVE-2026-84355: Incorrect authorization in Navigation. Reported by Google on 2026-05-10
[N/A][514006886] Medium CVE-2026-84358: Improper privilege management in Downloads. Reported by Google on 2026-05-17
[N/A][514489238] Medium CVE-2026-84332: Incorrect authorization in SiteSettings. Reported by Google on 2026-05-19
[N/A][517091927] Medium CVE-2026-84330: UI misrepresentation in FullScreen. Reported by Google on 2026-05-27
[N/A][517798926] Medium CVE-2026-84334: Incorrect authorization in Chromoting. Reported by Google on 2026-05-29
[N/A][518100026] Medium CVE-2026-84348: Information leak in MediaCapture. Reported by Google on 2026-05-30
[N/A][522302504] Medium CVE-2026-84335: Incorrect authorization in TabStrip. Reported by Google on 2026-06-10
[N/A][498725213] Low CVE-2026-84327: Incorrect authorization in Autofill. Reported by Google on 2026-04-01
[N/A][498850269] Low CVE-2026-84329: Confused deputy in CredentialProvider. Reported by Google on 2026-04-02
[TBD][503787232] Low CVE-2026-84356: UI misrepresentation in FullScreen. Reported by Francesco Topol (k4tedu) on 2026-04-18
[N/A][513713427] Low CVE-2026-84350: Use after free in TabStrip. Reported by Google on 2026-05-16
[N/A][521753402] Low CVE-2026-84331: Incorrect authorization in Actor. Reported by Google on 2026-06-09

* 152.0.7977.64
This update includes 327 security fixes. Please see the Chrome Security Page for more information.

See: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
@
text
@d7 1
a7 1
--- third_party/litert/features.gni.orig	2026-08-31 22:47:51.000000000 +0000
@


1.6
log
@
chromium: update to 151.0.7922.108

* 151.0.7922.108
This update includes 41 security fixes. Please see the Chrome Security Page for more information.

[TBD][499602793] Critical CVE-2026-19137: Use after free in WebGL. Reported by anonymous on 2026-04-05
[N/A][524824288] Critical CVE-2026-19149: Use after free in Aura. Reported by Google on 2026-06-17
[N/A][532941869] Critical CVE-2026-19154: Use after free in Skia. Reported by Google on 2026-07-09
[N/A][534903095] Critical CVE-2026-19157: Out of bounds write in ANGLE. Reported by Google on 2026-07-14
[TBD][537729021] Critical CVE-2026-19170: Use after free in WebGL. Reported by Muhammad Alifa Ramdhan, Pan ZhenPeng, Billy Jheng Bing Jhong of STAR Labs SG Pte. Ltd. on 2026-07-22
[N/A][537838324] Critical CVE-2026-19172: Use after free in Views. Reported by Google on 2026-07-22
[$5000][537390933] High CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks. Reported by Sven Dysthe (@@svn-dys) on 2026-07-21
[$500][536945254] High CVE-2026-19168: Inappropriate implementation in V8. Reported by XBOW and triaged by Andrés Luksenberg on 2026-07-20
[N/A][500097298] High CVE-2026-19138: Heap buffer overflow in CrashReporting. Reported by Google on 2026-04-06
[N/A][511731805] High CVE-2026-19139: Race in CredentialProvider. Reported by Google on 2026-05-10
[N/A][513044017] High CVE-2026-19140: Use after free in GPU. Reported by Google on 2026-05-14
[N/A][513602949] High CVE-2026-19141: Use after free in Resources. Reported by Google on 2026-05-15
[N/A][515428251] High CVE-2026-19142: Use after free in Views. Reported by Google on 2026-05-21
[N/A][517772612] High CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs. Reported by Google on 2026-05-29
[N/A][520167277] High CVE-2026-19144: Use after free in HTML. Reported by Google on 2026-06-05
[N/A][521878431] High CVE-2026-19145: Use after free in Translate. Reported by Google on 2026-06-09
[N/A][523713150] High CVE-2026-19146: Uninitialized Use in GPU. Reported by Google on 2026-06-14
[N/A][524439798] High CVE-2026-19147: Use after free in Aura. Reported by Google on 2026-06-16
[N/A][524460000] High CVE-2026-19148: Out of bounds write in GPU. Reported by Google on 2026-06-16
[N/A][526380803] High CVE-2026-19150: Inappropriate implementation in V8. Reported by Google on 2026-06-22
[N/A][530663440] High CVE-2026-19151: Use after free in V8. Reported by Google on 2026-07-02
[N/A][531165110] High CVE-2026-19152: Inappropriate implementation in Navigation. Reported by Google on 2026-07-04
[N/A][532939327] High CVE-2026-19153: Insufficient validation of untrusted input in Workers. Reported by Google on 2026-07-09
[N/A][533053621] High CVE-2026-19155: Use after free in Payments. Reported by Google on 2026-07-09
[TBD][533331920] High CVE-2026-19156: Heap buffer overflow in Base. Reported by Viktoria Zlatinova on 2026-07-10
[N/A][535749174] High CVE-2026-19158: Use after free in Views. Reported by Google on 2026-07-17
[N/A][536067175] High CVE-2026-19159: Use after free in Views. Reported by Google on 2026-07-17
[N/A][536068737] High CVE-2026-19160: Uninitialized Use in Skia. Reported by Google on 2026-07-17
[N/A][536165038] High CVE-2026-19161: Uninitialized Use in Skia. Reported by Google on 2026-07-18
[TBD][536271629] High CVE-2026-19162: Out of bounds write in V8. Reported by OpenAI Codex Security (amyb) on 2026-07-19
[N/A][536449742] High CVE-2026-19163: Use after free in Media. Reported by Google on 2026-07-19
[N/A][536470854] High CVE-2026-19164: Insufficient validation of untrusted input in Codecs. Reported by Google on 2026-07-19
[TBD][536512612] High CVE-2026-19165: Use after free in Extensions. Reported by @@bean5oup on 2026-07-19
[TBD][536584251] High CVE-2026-19166: Use after free in Web Authentication. Reported by heesun on 2026-07-20
[N/A][536666274] High CVE-2026-19167: Integer overflow in GPU. Reported by Google on 2026-07-20
[N/A][537832446] High CVE-2026-19171: Use after free in Media. Reported by Google on 2026-07-22
[TBD][538332338] High CVE-2026-19173: Out of bounds write in Skia. Reported by Vu Van Tien (@@n0_Be3r) on 2026-07-24
[TBD][538378084] High CVE-2026-19174: Integer overflow in V8. Reported by Seunghyun Lee (@@0x10n) of QED Audit (qedaudit.io) on 2026-07-24
[N/A][540138836] High CVE-2026-19175: Use after free in Payments. Reported by Google on 2026-07-29
[TBD][540157141] High CVE-2026-19176: Use after free in Skia. Reported by WinD39 - Huynh Dinh Vu on 2026-07-29
[TBD][540289900] High CVE-2026-19177: Insufficient validation of untrusted input in UI. Reported by Fabian Wahle (Hap Security) on 2026-07-29

* 151.0.7922.71
This update includes 370 security fixes. Please see the Chrome Security Page for more information.

See: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
@
text
@d7 1
a7 1
--- third_party/litert/features.gni.orig	2026-08-05 20:17:42.000000000 +0000
@


1.5
log
@
chromium: update to 150.0.7871.100

This update doesn't include security fixes.
A full list of changes in this build is available in
https://chromium.googlesource.com/chromium/src/+log/150.0.7871.47..150.0.7871.101?pretty=fuller&n=10000
@
text
@d7 1
a7 1
--- third_party/litert/features.gni.orig	2026-07-06 22:58:46.000000000 +0000
@


1.4
log
@
chromium: update to 150.0.7871.46

This update includes 433 security fixes. Please see the Chrome Security Page for more information.
@
text
@d7 1
a7 1
--- third_party/litert/features.gni.orig	2026-06-23 23:37:18.000000000 +0000
@


1.3
log
@
www/chromium: update to 149.0.7827.53

* 149.0.7827.53
This update includes 429 security fixes. Below, we highlight fixes
that were contributed by external researchers.
Please see the Chrome Security Page for more information.

* Fix build with wayland support: add missing include
@
text
@d7 1
a7 1
--- third_party/litert/features.gni.orig	2026-05-28 23:24:11.000000000 +0000
@


1.2
log
@
chromium: update to 148.0.7778.215

* 148.0.7778.215
This update includes 151 security fixes. Below, we highlight fixes
that were contributed by external researchers.
Please see the Chrome Security Page for more information.

* 148.0.7778.178
This update includes 16 security fixes. Below, we highlight fixes
that were contributed by external researchers.
Please see the Chrome Security Page for more information.

* pkgsrc: enable wayland support
@
text
@d7 1
a7 1
--- third_party/litert/features.gni.orig	2026-05-26 20:39:02.000000000 +0000
@


1.1
log
@
www/chromium: update to 148.0.7778.96

* 148.0.7778.96
This update includes 127 security fixes. Below, we highlight fixes
that were contributed by external researchers. Please see the Chrome Security Page for more information.

Many of our security bugs are detected using AddressSanitizer, MemorySanitizer,
UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

[$43000][493747582] Critical CVE-2026-7896: Integer overflow in Blink. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-18

[N/A][504069514] Critical CVE-2026-7897: Use after free in Mobile. Reported by Google on 2026-04-18

[N/A][504587882] Critical CVE-2026-7898: Use after free in Chromoting. Reported by Google on 2026-04-20

[$55000][505481948] High CVE-2026-7899: Out of bounds read and write in V8. Reported by Project WhatForLunch (@@pjwhatforlunch) on 2026-04-23

[$16000][496503799] High CVE-2026-7900: Heap buffer overflow in ANGLE. Reported by Anonymous on 2026-03-26

[$16000][497724490] High CVE-2026-7901: Use after free in ANGLE. Reported by Syn4pse (@@ret2happy) on 2026-03-30

[$8000][502030575] High CVE-2026-7902: Out of bounds memory access in V8. Reported by JunYoung Park(@@candymate) of KAIST Hacking Lab on 2026-04-13

[TBD][491760376] High CVE-2026-7903: Integer overflow in ANGLE. Reported by heesun on 2026-03-11

[TBD][492350406] High CVE-2026-7904: Out of bounds read in Fonts. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-13

[N/A][495259842] High CVE-2026-7905: Insufficient validation of untrusted input in Media. Reported by Google on 2026-03-23

[N/A][496284584] High CVE-2026-7906: Use after free in SVG. Reported by Google on 2026-03-25

[N/A][496292089] High CVE-2026-7907: Use after free in DOM. Reported by Google on 2026-03-25

[N/A][497436531] High CVE-2026-7908: Use after free in Fullscreen. Reported by Google on 2026-03-29

[N/A][497437113] High CVE-2026-7909: Inappropriate implementation in ServiceWorker. Reported by Google on 2026-03-29

[N/A][497543810] High CVE-2026-7910: Use after free in Views. Reported by Google on 2026-03-29

[N/A][497548912] High CVE-2026-7911: Use after free in Aura. Reported by Google on 2026-03-29

[N/A][497639714] High CVE-2026-7912: Integer overflow in GPU. Reported by Google on 2026-03-30

[N/A][497936728] High CVE-2026-7913: Insufficient policy enforcement in DevTools. Reported by Google on 2026-03-30

[N/A][498401609] High CVE-2026-7914: Type Confusion in Accessibility. Reported by Google on 2026-04-01

[N/A][498454478] High CVE-2026-7915: Insufficient data validation in DevTools. Reported by Google on 2026-04-01

[N/A][498720754] High CVE-2026-7916: Insufficient data validation in InterestGroups. Reported by Google on 2026-04-01

[N/A][498752242] High CVE-2026-7917: Use after free in Fullscreen. Reported by Google on 2026-04-02

[N/A][498780188] High CVE-2026-7918: Use after free in GPU. Reported by Google on 2026-04-02

[N/A][498832921] High CVE-2026-7919: Use after free in Aura. Reported by Google on 2026-04-02

[N/A][498989348] High CVE-2026-7920: Use after free in Skia. Reported by Google on 2026-04-02

[N/A][499062376] High CVE-2026-7921: Use after free in Passwords. Reported by Google on 2026-04-02

[N/A][499449324] High CVE-2026-7922: Use after free in ServiceWorker. Reported by Google on 2026-04-04

[N/A][500080194] High CVE-2026-7923: Out of bounds write in Skia. Reported by Google on 2026-04-06

[N/A][500087204] High CVE-2026-7924: Uninitialized Use in Dawn. Reported by Google on 2026-04-06

[N/A][501833981] High CVE-2026-7925: Use after free in Chromoting. Reported by Google on 2026-04-12

[TBD][502249087] High CVE-2026-7926: Use after free in PresentationAPI. Reported by anonymous on 2026-04-14

[N/A][502830119] High CVE-2026-7927: Type Confusion in Runtime. Reported by Google on 2026-04-15

[N/A][504612429] High CVE-2026-7928: Use after free in WebRTC. Reported by Google on 2026-04-20

[N/A][504660052] High CVE-2026-7929: Use after free in MediaRecording. Reported by Google on 2026-04-20

[TBD][434825208] Medium CVE-2026-7930: Insufficient validation of untrusted input in Cookies. Reported by Satoki on 2025-07-29

[TBD][474338157] Medium CVE-2026-7931: Insufficient validation of untrusted input in iOS. Reported by Qadhafy Muhammad Tera on 2026-01-08

[TBD][481634116] Medium CVE-2026-7932: Insufficient policy enforcement in Downloads. Reported by Povcfe of Tencent Security Xuanwu Lab on 2026-02-04

[TBD][488585490] Medium CVE-2026-7933: Out of bounds read in WebCodecs. Reported by heapracer (@@heapracer) on 2026-03-01

[N/A][489023922] Medium CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker. Reported by Google on 2026-03-02

[TBD][489624550] Medium CVE-2026-7935: Inappropriate implementation in Speech. Reported by Qadhafy Muhammad Tera on 2026-03-04

[TBD][490485402] Medium CVE-2026-7936: Object lifecycle issue in V8. Reported by Christian Holler on 2026-03-07

[TBD][491766258] Medium CVE-2026-7937: Insufficient policy enforcement in DevTools. Reported by lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab on 2026-03-11

[TBD][492735384] Medium CVE-2026-7938: Use after free in CSS. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-15

[TBD][492963096] Medium CVE-2026-7939: Inappropriate implementation in SanitizerAPI. Reported by s3zer0 on 2026-03-15

[TBD][493631402] Medium CVE-2026-7940: Use after free in V8. Reported by sakana on 2026-03-17

[TBD][493955234] Medium CVE-2026-7941: Insufficient validation of untrusted input in Mobile. Reported by Adithya Kotian on 2026-03-19

[N/A][495363705] Medium CVE-2026-7942: Integer overflow in ANGLE. Reported by Google on 2026-03-23

[TBD][495373657] Medium CVE-2026-7943: Insufficient validation of untrusted input in ANGLE. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-23

[N/A][495783187] Medium CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache. Reported by Google on 2026-03-24

[N/A][495802788] Medium CVE-2026-7945: Insufficient validation of untrusted input in COOP. Reported by Google on 2026-03-24

[N/A][496016840] Medium CVE-2026-7946: Insufficient policy enforcement in WebUI. Reported by Google on 2026-03-25

[N/A][496169594] Medium CVE-2026-7947: Insufficient validation of untrusted input in Network. Reported by Google on 2026-03-25

[N/A][496193452] Medium CVE-2026-7948: Race in Chromoting. Reported by Google on 2026-03-25

[N/A][496206134] Medium CVE-2026-7949: Out of bounds read in Skia. Reported by Google on 2026-03-25

[N/A][496259890] Medium CVE-2026-7950: Out of bounds read and write in GFX. Reported by Google on 2026-03-25

[TBD][496266456] Medium CVE-2026-7951: Out of bounds write in WebRTC. Reported by soft.connect.fr on 2026-03-26

[N/A][496279876] Medium CVE-2026-7952: Insufficient policy enforcement in Extensions. Reported by Google on 2026-03-25

[N/A][496379792] Medium CVE-2026-7953: Insufficient validation of untrusted input in Omnibox. Reported by Google on 2026-03-26

[N/A][496380960] Medium CVE-2026-7954: Race in Shared Storage. Reported by Google on 2026-03-26

[N/A][496441232] Medium CVE-2026-7955: Uninitialized Use in GPU. Reported by Google on 2026-03-26

[N/A][496463315] Medium CVE-2026-7956: Use after free in Navigation. Reported by Google on 2026-03-26

[N/A][496607380] Medium CVE-2026-7957: Out of bounds write in Media. Reported by Google on 2026-03-26

[N/A][496632973] Medium CVE-2026-7958: Inappropriate implementation in ServiceWorker. Reported by Google on 2026-03-26

[N/A][496645205] Medium CVE-2026-7959: Inappropriate implementation in Navigation. Reported by Google on 2026-03-26

[N/A][497007825] Medium CVE-2026-7960: Race in Speech. Reported by Google on 2026-03-27

[N/A][497008295] Medium CVE-2026-7961: Insufficient validation of untrusted input in Permissions. Reported by Google on 2026-03-27

[N/A][497081987] Medium CVE-2026-7962: Insufficient policy enforcement in DirectSockets. Reported by Google on 2026-03-28

[N/A][497250399] Medium CVE-2026-7963: Inappropriate implementation in ServiceWorker. Reported by Google on 2026-03-28

[N/A][497254383] Medium CVE-2026-7964: Insufficient validation of untrusted input in FileSystem. Reported by Google on 2026-03-28

[N/A][497255035] Medium CVE-2026-7965: Insufficient validation of untrusted input in DevTools. Reported by Google on 2026-03-28

[N/A][497341787] Medium CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation. Reported by Google on 2026-03-29

[N/A][497365545] Medium CVE-2026-7967: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-03-29

[N/A][497432281] Medium CVE-2026-7968: Insufficient validation of untrusted input in CORS. Reported by Google on 2026-03-29

[N/A][497450574] Medium CVE-2026-7969: Integer overflow in Network. Reported by Google on 2026-03-29

[N/A][497487462] Medium CVE-2026-7970: Use after free in TopChrome. Reported by Google on 2026-03-29

[N/A][497529290] Medium CVE-2026-7971: Inappropriate implementation in ORB. Reported by Google on 2026-03-29

[N/A][497546281] Medium CVE-2026-7972: Uninitialized Use in GPU. Reported by Google on 2026-03-29

[N/A][497565944] Medium CVE-2026-7973: Integer overflow in Dawn. Reported by Google on 2026-03-29

[N/A][497649372] Medium CVE-2026-7974: Use after free in Blink. Reported by Google on 2026-03-30

[N/A][497735587] Medium CVE-2026-7975: Use after free in DevTools. Reported by Google on 2026-03-30

[N/A][497736679] Medium CVE-2026-7976: Use after free in Views. Reported by Google on 2026-03-30

[N/A][497821223] Medium CVE-2026-7977: Inappropriate implementation in Canvas. Reported by Google on 2026-03-30

[N/A][497828892] Medium CVE-2026-7978: Inappropriate implementation in Companion. Reported by Google on 2026-03-30

[N/A][497849876] Medium CVE-2026-7979: Inappropriate implementation in Media. Reported by Google on 2026-03-30

[N/A][497859275] Medium CVE-2026-7980: Use after free in WebAudio. Reported by Google on 2026-03-30

[N/A][497926602] Medium CVE-2026-7981: Out of bounds read in Codecs. Reported by Google on 2026-03-30

[N/A][497952533] Medium CVE-2026-7982: Uninitialized Use in WebCodecs. Reported by Google on 2026-03-30

[N/A][497975608] Medium CVE-2026-7983: Out of bounds read in Dawn. Reported by Google on 2026-03-31

[N/A][498277368] Medium CVE-2026-7984: Use after free in ReadingMode. Reported by Google on 2026-03-31

[N/A][498352423] Medium CVE-2026-7985: Use after free in GPU. Reported by Google on 2026-03-31

[N/A][498396238] Medium CVE-2026-7986: Insufficient policy enforcement in Autofill. Reported by Google on 2026-04-01

[N/A][498696266] Medium CVE-2026-7987: Use after free in WebRTC. Reported by Google on 2026-04-01

[N/A][498753456] Medium CVE-2026-7988: Type Confusion in WebRTC. Reported by Google on 2026-04-02

[N/A][498765082] Medium CVE-2026-7989: Insufficient data validation in DataTransfer. Reported by Google on 2026-04-02

[N/A][498892267] Medium CVE-2026-7990: Insufficient validation of untrusted input in Updater. Reported by Google on 2026-04-02

[N/A][499065126] Medium CVE-2026-7991: Use after free in UI. Reported by Google on 2026-04-02

[N/A][499067529] Medium CVE-2026-7992: Insufficient validation of untrusted input in UI. Reported by Google on 2026-04-02

[N/A][499099003] Medium CVE-2026-7993: Insufficient validation of untrusted input in Payments. Reported by Google on 2026-04-03

[N/A][499116954] Medium CVE-2026-7994: Inappropriate implementation in Chromoting. Reported by Google on 2026-04-03

[N/A][501745798] Medium CVE-2026-7995: Out of bounds read in AdFilter. Reported by Google on 2026-04-11

[TBD][484547631] Low CVE-2026-7996: Insufficient validation of untrusted input in SSL. Reported by heesun on 2026-02-15

[TBD][487960705] Low CVE-2026-7997: Insufficient validation of untrusted input in Updater. Reported by ochkofficial on 2026-02-26

[TBD][491676472] Low CVE-2026-7998: Insufficient validation of untrusted input in Dialog. Reported by Tianyi Hu on 2026-03-11

[TBD][493099941] Low CVE-2026-7999: Inappropriate implementation in V8. Reported by Taisic Yun (@@taisic) of Theori on 2026-03-16

[TBD][494464734] Low CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver. Reported by Ryan Jupp - HAAO on 2026-03-20

[TBD][494764371] Low CVE-2026-8001: Use after free in Printing. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-21

[N/A][495779613] Low CVE-2026-8002: Use after free in Audio. Reported by Google on 2026-03-24

[N/A][495985532] Low CVE-2026-8003: Insufficient validation of untrusted input in TabGroups. Reported by Google on 2026-03-25

[N/A][496189510] Low CVE-2026-8004: Insufficient policy enforcement in DevTools. Reported by Google on 2026-03-25

[N/A][496298665] Low CVE-2026-8005: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-03-25

[N/A][496373088] Low CVE-2026-8006: Insufficient policy enforcement in DevTools. Reported by Google on 2026-03-26

[N/A][496399759] Low CVE-2026-8007: Insufficient validation of untrusted input in Cast. Reported by Google on 2026-03-26

[N/A][496426191] Low CVE-2026-8008: Inappropriate implementation in DevTools. Reported by Google on 2026-03-26

[N/A][496555077] Low CVE-2026-8009: Inappropriate implementation in Cast. Reported by Google on 2026-03-26

[N/A][496624084] Low CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation. Reported by Google on 2026-03-26

[N/A][496626029] Low CVE-2026-8011: Insufficient policy enforcement in Search. Reported by Google on 2026-03-26

[N/A][496628298] Low CVE-2026-8012: Inappropriate implementation in MHTML. Reported by Google on 2026-03-26

[N/A][497427430] Low CVE-2026-8013: Insufficient validation of untrusted input in FedCM. Reported by Google on 2026-03-29

[N/A][497490364] Low CVE-2026-8014: Inappropriate implementation in Preload. Reported by Google on 2026-03-29

[N/A][497548558] Low CVE-2026-8015: Inappropriate implementation in Media. Reported by Google on 2026-03-29

[N/A][497695401] Low CVE-2026-8016: Use after free in WebRTC. Reported by Google on 2026-03-30

[N/A][497722578] Low CVE-2026-8017: Side-channel information leakage in Media. Reported by Google on 2026-03-30

[N/A][498292657] Low CVE-2026-8018: Insufficient policy enforcement in DevTools. Reported by Google on 2026-03-31

[N/A][498353173] Low CVE-2026-8019: Insufficient policy enforcement in WebApp. Reported by Google on 2026-03-31

[N/A][498382925] Low CVE-2026-8020: Uninitialized Use in GPU. Reported by Google on 2026-04-01

[N/A][498417031] Low CVE-2026-8021: Script injection in UI. Reported by Google on 2026-04-01

[N/A][499194407] Low CVE-2026-8022: Inappropriate implementation in MHTML. Reported by Google on 2026-04-03
@
text
@d7 1
a7 1
--- third_party/litert/features.gni.orig	2026-04-28 23:05:57.000000000 +0200
@

