pkgsrc-WIP-changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

chromium: update to 150.0.7871.186



Module Name:	pkgsrc-wip
Committed By:	kikadf <kikadf.01%gmail.com@localhost>
Pushed By:	kikadf
Date:		Tue Jul 28 13:30:40 2026 +0200
Changeset:	7c0a9f505a375c3d423c1c78ddbf53d61911e900

Modified Files:
	chromium/COMMIT_MSG
	chromium/Makefile
	chromium/distinfo

Log Message:
chromium: update to 150.0.7871.186

To see a diff of this commit:
https://wip.pkgsrc.org/cgi-bin/gitweb.cgi?p=pkgsrc-wip.git;a=commitdiff;h=7c0a9f505a375c3d423c1c78ddbf53d61911e900

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

diffstat:
 chromium/COMMIT_MSG | 80 +++++++++++++++--------------------------------------
 chromium/Makefile   |  2 +-
 chromium/distinfo   | 12 ++++----
 3 files changed, 29 insertions(+), 65 deletions(-)

diffs:
diff --git a/chromium/COMMIT_MSG b/chromium/COMMIT_MSG
index 23f930b0ef..b91f0aa61f 100644
--- a/chromium/COMMIT_MSG
+++ b/chromium/COMMIT_MSG
@@ -1,62 +1,26 @@
-www/chromium: update to 150.0.7871.128
+www/chromium: update to 150.0.7871.186
 
-* 150.0.7871.128
-This update includes 7 security fixes. Please see the Chrome Security Page for more information.
+* 150.0.7871.186
+This update includes 4 security fixes. Please see the Chrome Security Page for more information.
 
-[N/A][516987782] Critical CVE-2026-15899: Use after free in CameraCapture. Reported by Google on 2026-05-27
-[N/A][523750584] Critical CVE-2026-15900: Use after free in GPU. Reported by Google on 2026-06-14
-[N/A][533446300] Critical CVE-2026-15901: Use after free in Network. Reported by Google on 2026-07-10
-[N/A][522436154] High CVE-2026-15902: Use after free in Cast. Reported by Google on 2026-06-10
-[TBD][531503216] High CVE-2026-15903: Out of bounds read and write in V8. Reported by OpenAI Codex Security (amyb) on 2026-07-06
-[N/A][532925350] High CVE-2026-15904: Use after free in Ozone. Reported by Google on 2026-07-09
-[N/A][532970574] High CVE-2026-15905: Use after free in Aura. Reported by Google on 2026-07-09
+[N/A][518237034] High CVE-2026-16807: Out of bounds write in Codecs. Reported by Google on 2026-05-30
+[N/A][522064153] High CVE-2026-16806: Use after free in WebMCP. Reported by Google on 2026-06-10
+[N/A][523292588] High CVE-2026-16805: Use after free in Blink. Reported by Google on 2026-06-12
+[N/A][524721670] High CVE-2026-16804: Use after free in Input. Reported by Google on 2026-06-16
 
-* 150.0.7871.124
-This update includes 15 security fixes. Please see the Chrome Security Page for more information.
+* 150.0.7871.181
+This update includes 12 security fixes. Below, we highlight fixes that were contributed by
+external researchers. Please see the Chrome Security Page for more information.
 
-[N/A][517100492] Critical CVE-2026-15764: Use after free in Ozone. Reported by Google on 2026-05-27
-[N/A][518007484] Critical CVE-2026-15765: Use after free in Ozone. Reported by Google on 2026-05-29
-[N/A][514010477] High CVE-2026-15766: Uninitialized Use in Skia. Reported by Google on 2026-05-17
-[N/A][514748734] High CVE-2026-15767: Heap buffer overflow in libyuv. Reported by Google on 2026-05-19
-[N/A][517931625] High CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas. Reported by Google on 2026-05-29
-[N/A][519731111] High CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming. Reported by Google on 2026-06-03
-[N/A][524792614] High CVE-2026-15770: Uninitialized Use in V8. Reported by Google on 2026-06-17
-[N/A][525177160] High CVE-2026-15771: Insufficient validation of untrusted input in Media. Reported by Google on 2026-06-18
-[N/A][525317502] High CVE-2026-15772: Use after free in GPU. Reported by Google on 2026-06-18
-[TBD][527676561] High CVE-2026-15773: Use after free in Core. Reported by xinchaotian of Microsoft on 2026-06-25
-[N/A][530646115] High CVE-2026-15774: Use after free in Skia. Reported by Google on 2026-07-03
-[TBD][531319201] High CVE-2026-15775: Insufficient policy enforcement in V8. Reported by wang1r923096443%gmail.com@localhost on 2026-07-05
-[TBD][532595489] High CVE-2026-15776: Type Confusion in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-07-08
-[N/A][532929679] High CVE-2026-15777: Use after free in UI. Reported by Google on 2026-07-09
-[N/A][513795122] Medium CVE-2026-15778: Insufficient validation of untrusted input in Navigation. Reported by Google on 2026-05-16
-
-* 150.0.7871.114
-This update includes 27 security fixes. Please see the Chrome Security Page for more information.
-
-[N/A][518006275] Critical CVE-2026-15112: Use after free in Ozone. Reported by Google on 2026-05-29
-[N/A][524045160] Critical CVE-2026-15129: Use after free in Views. Reported by Google on 2026-06-15
-[$500][527385397] High CVE-2026-15132: Uninitialized Use in V8. Reported by Pierre Langlois from Arm on 2026-06-24
-[$500][527406824] High CVE-2026-15133: Use after free in InterestGroups. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-06-24
-[N/A][515443146] High CVE-2026-15108: Integer overflow in Extensions API. Reported by Google on 2026-05-21
-[N/A][516899138] High CVE-2026-15109: Uninitialized Use in ANGLE. Reported by Google on 2026-05-26
-[N/A][516948486] High CVE-2026-15110: Use after free in Extensions. Reported by Google on 2026-05-27
-[N/A][517508651] High CVE-2026-15111: Use after free in Views. Reported by Google on 2026-05-28
-[N/A][520540744] High CVE-2026-15113: Use after free in Autofill. Reported by Google on 2026-06-05
-[N/A][520565945] High CVE-2026-15114: Out of bounds read and write in Codecs. Reported by Google on 2026-06-06
-[N/A][520576676] High CVE-2026-15115: Insufficient validation of untrusted input in WebAppInstalls. Reported by Google on 2026-06-06
-[N/A][522092013] High CVE-2026-15116: Use after free in Actor. Reported by Google on 2026-06-10
-[N/A][522568496] High CVE-2026-15117: Use after free in Payments. Reported by Google on 2026-06-11
-[N/A][523238265] High CVE-2026-15118: Use after free in Input. Reported by Google on 2026-06-12
-[N/A][523505418] High CVE-2026-15119: Inappropriate implementation in GetUserMedia. Reported by Google on 2026-06-13
-[N/A][523609602] High CVE-2026-15120: Use after free in Core. Reported by Google on 2026-06-13
-[N/A][523712556] High CVE-2026-15121: Use after free in WebRTC. Reported by Google on 2026-06-14
-[N/A][523717219] High CVE-2026-15122: Insufficient validation of untrusted input in Codecs. Reported by Google on 2026-06-14
-[N/A][523729553] High CVE-2026-15123: Insufficient data validation in DOM. Reported by Google on 2026-06-14
-[N/A][523735038] High CVE-2026-15124: Insufficient policy enforcement in Passwords. Reported by Google on 2026-06-14
-[N/A][523737685] High CVE-2026-15125: Inappropriate implementation in Forms. Reported by Google on 2026-06-14
-[N/A][523748081] High CVE-2026-15126: Use after free in Forms. Reported by Google on 2026-06-14
-[N/A][523752265] High CVE-2026-15127: Inappropriate implementation in WebGL. Reported by Google on 2026-06-14
-[N/A][523756329] High CVE-2026-15128: Inappropriate implementation in Forms. Reported by Google on 2026-06-14
-[N/A][526541544] High CVE-2026-15130: Insufficient policy enforcement in Navigation. Reported by Google on 2026-06-22
-[$2000][503553615] Medium CVE-2026-15107: Use after free in IndexedDB. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab on 2026-04-17
-[N/A][526542464] Medium CVE-2026-15131: Insufficient data validation in Navigation. Reported by Google on 2026-06-22
+[$500][527930356] High CVE-2026-16420: Type Confusion in WebAudio. Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt on 2026-06-26
+[$500][528276487] High CVE-2026-16421: Inappropriate implementation in WebAudio. Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt on 2026-06-26
+[N/A][517359779] High CVE-2026-16413: Out of bounds write in ANGLE. Reported by Google on 2026-05-28
+[N/A][517651910] High CVE-2026-16414: Insufficient validation of untrusted input in Chromecast. Reported by Google on 2026-05-28
+[N/A][519244446] High CVE-2026-16415: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-06-02
+[N/A][520172356] High CVE-2026-16416: Integer overflow in Chromecast. Reported by Google on 2026-06-05
+[N/A][521491024] High CVE-2026-16417: Uninitialized Use in Skia. Reported by Google on 2026-06-08
+[N/A][522125255] High CVE-2026-16418: Stack buffer overflow in V8. Reported by Google on 2026-06-10
+[N/A][523435970] High CVE-2026-16419: Out of bounds read and write in ANGLE. Reported by Google on 2026-06-13
+[N/A][533515002] High CVE-2026-16422: Insufficient validation of untrusted input in Certificate. Reported by Google on 2026-07-10
+[N/A][534582496] High CVE-2026-16423: Use after free in UI. Reported by Google on 2026-07-14
+[N/A][534858939] High CVE-2026-16424: Use after free in GPU. Reported by Google on 2026-07-14
diff --git a/chromium/Makefile b/chromium/Makefile
index 95c0ff4e95..32837ee8df 100644
--- a/chromium/Makefile
+++ b/chromium/Makefile
@@ -1,7 +1,7 @@
 # $NetBSD: Makefile,v 1.52 2026/04/10 17:31:46 kikadf Exp $
 
 DISTNAME=			chromium-${VERSION}
-VERSION=			150.0.7871.128
+VERSION=			150.0.7871.186
 CATEGORIES=			www
 MASTER_SITES=			https://commondatastorage.googleapis.com/chromium-browser-official/
 EXTRACT_SUFX_C=			.tar.xz
diff --git a/chromium/distinfo b/chromium/distinfo
index e5749c3438..faf3e6d5f7 100644
--- a/chromium/distinfo
+++ b/chromium/distinfo
@@ -66,12 +66,12 @@ Size (cc-1.2.61.crate) = 97163 bytes
 BLAKE2s (cfg-if-1.0.4.crate) = 517b7cff4f133f9b02492c0db281822fd02c24941a7aa4f9b1502895dc5e58d9
 SHA512 (cfg-if-1.0.4.crate) = 176e04df7ba783b7143bb84397b777f5c5a1305c08a5c3a218d4a66830620be89ed68992ba27686165bcd3fb2f34b2daf80b2a1d4b481ecc267c988e84d28e9d
 Size (cfg-if-1.0.4.crate) = 9360 bytes
-BLAKE2s (chromium-150.0.7871.128-lite.tar.xz) = 51664bfdfcefa3d720cea0f69c531a606c85fc01d1c6425ad9ffc1b37710d876
-SHA512 (chromium-150.0.7871.128-lite.tar.xz) = ee69d03ee170eb57a2e2fd9b6ce691d08a5cd72a738044d7ac2d58c53cbec33d39369b6f543bf9d44934f62e33240e2e5a0f0b093ee5b846de1a0e9d1ad48b0d
-Size (chromium-150.0.7871.128-lite.tar.xz) = 1670339852 bytes
-BLAKE2s (chromium-150.0.7871.128-testdata.tar.xz) = 10aaa0ec680d6f7b300682f3b353b925bda2337068b208433304ae230aa1f1da
-SHA512 (chromium-150.0.7871.128-testdata.tar.xz) = ac983c117b51925a068b97a14bef33b0cececc268137426bcef5680fb642a4d9485490ed66a61307ba0b67b27a705a00661c42484d7022680eda09c8a00873d9
-Size (chromium-150.0.7871.128-testdata.tar.xz) = 1314346616 bytes
+BLAKE2s (chromium-150.0.7871.186-lite.tar.xz) = 587de0bd43e05f3ff6064737a4675ea33d21c336125fa59789322d81978cafb1
+SHA512 (chromium-150.0.7871.186-lite.tar.xz) = 2b0a70340947bf237144d9d3ac8ef364479b2e8fd8883a76b5296a88dbfff803bba347d8583c20cddae90c1000c59cb802ee761a45fb929ee6fd11315bb50f58
+Size (chromium-150.0.7871.186-lite.tar.xz) = 1668536212 bytes
+BLAKE2s (chromium-150.0.7871.186-testdata.tar.xz) = 74bfe692489a689ea9f7b5562047f19bba04c734bd1467c1b4b7621ff668b0a3
+SHA512 (chromium-150.0.7871.186-testdata.tar.xz) = ceff00f326735871979e10ed4e638262379486bf8a96e0756100d6ff300ade5687d208671b403b8ca0f4ce499c7aab68d5f73be7dc8915fd1363eaca998eeb63
+Size (chromium-150.0.7871.186-testdata.tar.xz) = 1314381172 bytes
 BLAKE2s (cmake-0.1.58.crate) = a4568b73f30075a127114fb24a891b182573483d81080643888ecbd5e954efe7
 SHA512 (cmake-0.1.58.crate) = 49420a5d7d71ddccc21b71373769e1e28ab98c9af1a0c5d59fc3127e6dcc45cb1b7c6b5a37c9110907daceda7fd10bb59344f2bb8f041b18d62b16c22c5d0d60
 Size (cmake-0.1.58.crate) = 20474 bytes


Home | Main Index | Thread Index | Old Index