[Git][security-tracker-team/security-tracker][master] more chromium issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Jul 2 11:55:07 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fd15551e by Moritz Muehlenhoff at 2026-07-02T12:54:40+02:00
more chromium issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -121,109 +121,168 @@ CVE-2026-14440 (Description:     To issue and renew TLS certificates on behalf o
 CVE-2026-14439 (A path traversal vulnerability exists in the Git Service component sha ...)
 	TODO: check
 CVE-2026-14432 (Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14431 (Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14430 (Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14429 (Insufficient validation of untrusted input in Skia in Google Chrome pr ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-14428 (Insufficient validation of untrusted input in Dawn in Google Chrome on ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14427 (Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 a ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-14426 (Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14425 (Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowe ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14424 (Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46  ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14423 (Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14422 (Out of bounds read and write in Tint in Google Chrome prior to 150.0.7 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14421 (Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0. ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14420 (Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14419 (Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-14418 (Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 all ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14417 (Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14416 (Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 all ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14415 (Inappropriate implementation in V8 in Google Chrome prior to 150.0.787 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14414 (Insufficient validation of untrusted input in Skia in Google Chrome pr ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-14413 (Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 all ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14412 (Insufficient validation of untrusted input in ANGLE in Google Chrome p ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14411 (Insufficient validation of untrusted input in ANGLE in Google Chrome p ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14410 (Inappropriate implementation in Skia in Google Chrome prior to 150.0.7 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-14409 (Inappropriate implementation in V8 in Google Chrome prior to 150.0.787 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14408 (Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allo ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14407 (Inappropriate implementation in V8 in Google Chrome prior to 150.0.787 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14406 (Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allow ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14405 (Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowe ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14404 (Inappropriate implementation in PDFium in Google Chrome prior to 150.0 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14403 (Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14402 (Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0. ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14401 (Insufficient validation of untrusted input in ANGLE in Google Chrome o ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14400 (Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 a ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14399 (Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allo ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14398 (Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowe ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14397 (Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.78 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14396 (Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 al ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14395 (Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allo ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14394 (Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14393 (Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14392 (Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 al ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14391 (Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14390 (Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowe ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14389 (Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allow ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-14388 (Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 al ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14387 (Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allow ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-14386 (Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 al ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14385 (Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14384 (Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14383 (Inappropriate implementation in V8 in Google Chrome prior to 150.0.787 ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14382 (Insufficient validation of untrusted input in ANGLE in Google Chrome p ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14381 (Incorrect security UI in WebAppInstalls in Google Chrome prior to 150. ...)
-	TODO: check
+	- chromium <unfixed>
+	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-14363 (Improper neutralization of special elements used in an SQL command ('S ...)
 	NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-14340 (An incorrect authorization vulnerability was identified in GitHub Ente ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd15551ec5b1ce941c0788fc25758a3913ad159a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd15551ec5b1ce941c0788fc25758a3913ad159a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260702/61da6d50/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list