Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package chromium for openSUSE:Factory checked in at 2026-09-17 15:18:04 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/chromium (Old) and /work/SRC/openSUSE:Factory/.chromium.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "chromium" Thu Sep 17 15:18:04 2026 rev:547 rq:1378234 version:153.0.8010.47 Changes: -------- --- /work/SRC/openSUSE:Factory/chromium/chromium.changes 2026-09-15 12:48:38.667493118 +0200 +++ /work/SRC/openSUSE:Factory/.chromium.new.383539/chromium.changes 2026-09-17 15:19:26.038016364 +0200 @@ -1,0 +2,47 @@ +Wed Sep 16 02:53:44 UTC 2026 - Andreas Stieger <[email protected]> + +- Chromium 153.0.8010.47 (boo#1280687): + * CVE-2026-91726: Out of bounds read in WebGL + * CVE-2026-91721: Use after free in Internals + * CVE-2026-91749: Use after free in Workers + * CVE-2026-91724: Use after free in Input + * CVE-2026-91728: Integer overflow in V8 + * CVE-2026-91734: Incorrect authorization in Core + * CVE-2026-91727: Incorrect reference resolution in Extensions + * CVE-2026-91743: Race condition in Core + * CVE-2026-91744: Race condition in PlatformIntegration + * CVE-2026-91712: Race condition in Extensions + * CVE-2026-91748: Race condition in Extensions + * CVE-2026-91720: Uninitialized resource in ANGLE + * CVE-2026-91731: Type confusion in Compositing + * CVE-2026-91747: Use after free in Skia + * CVE-2026-91733: Improper state validation in Skia + * CVE-2026-91741: Type confusion in CacheStorage + * CVE-2026-91709: Type confusion in ServiceWorker + * CVE-2026-91717: Missing authorization in Android + * CVE-2026-91735: Incorrect authorization in WebUI + * CVE-2026-91708: Race condition in Network + * CVE-2026-91736: Use after free in DOM + * CVE-2026-91740: Uninitialized resource in Skia + * CVE-2026-91710: Use after free in WebAppInstalls + * CVE-2026-91718: Use after free in Core + * CVE-2026-91716: Use after free in Auth + * CVE-2026-91746: Integer overflow in Compositing + * CVE-2026-91729: Use after free in DigitalCredentials + * CVE-2026-91737: Use after free in PDF + * CVE-2026-91711: Out of bounds write in ServiceWorker + * CVE-2026-91715: Type confusion in ServiceWorker + * CVE-2026-91745: Use after free in V8 + * CVE-2026-91723: Race condition in WebAppInstalls + * CVE-2026-91732: Missing authorization in AppManifest + * CVE-2026-91742: Confused deputy in PriceTracking + * CVE-2026-91714: Observable discrepancy in Fonts + * CVE-2026-91725: Observable discrepancy in CSS + * CVE-2026-91739: Missing authorization in Transactions Platform + * CVE-2026-91713: Missing authorization in Browser + * CVE-2026-91738: Improper input validation in ANGLE + * CVE-2026-91730: Incomplete cleanup in GetUserMedia + * CVE-2026-91722: Use after free in Input + * CVE-2026-91719: Code injection in XML + +------------------------------------------------------------------- Old: ---- chromium-153.0.8010.36-linux.tar.xz New: ---- chromium-153.0.8010.47-linux.tar.xz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ chromium.spec ++++++ --- /var/tmp/diff_new_pack.OUelBb/_old 2026-09-17 15:19:43.122733142 +0200 +++ /var/tmp/diff_new_pack.OUelBb/_new 2026-09-17 15:19:43.126733310 +0200 @@ -139,7 +139,7 @@ %global official_build 1 Name: chromium%{n_suffix} -Version: 153.0.8010.36 +Version: 153.0.8010.47 Release: 0 Summary: Google's open source browser project License: BSD-3-Clause AND LGPL-2.1-or-later ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.OUelBb/_old 2026-09-17 15:19:43.303740736 +0200 +++ /var/tmp/diff_new_pack.OUelBb/_new 2026-09-17 15:19:43.307740904 +0200 @@ -1,7 +1,7 @@ -mtime: 1789384024 -commit: 1e276890ec0ab570abcfb43b42a8e5201944859ee9971c07053e1db4b14920ea +mtime: 1789529168 +commit: dae3548272c1c8461c5ab44f544281db2c913617b24c49d2a8f0d942b086b61b url: https://src.opensuse.org/chromium/chromium -revision: 1e276890ec0ab570abcfb43b42a8e5201944859ee9971c07053e1db4b14920ea +revision: dae3548272c1c8461c5ab44f544281db2c913617b24c49d2a8f0d942b086b61b trackingbranch: main projectscmsync: https://src.opensuse.org/chromium/_ObsPrj.git ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-16 05:26:08.000000000 +0200 @@ -0,0 +1,4 @@ +.osc +*.patch~ +*-build/ +.*.swp ++++++ chromium-153.0.8010.36-linux.tar.xz -> chromium-153.0.8010.47-linux.tar.xz ++++++ /work/SRC/openSUSE:Factory/chromium/chromium-153.0.8010.36-linux.tar.xz /work/SRC/openSUSE:Factory/.chromium.new.383539/chromium-153.0.8010.47-linux.tar.xz differ: char 15, line 1
