git: 4e032f579c52 - main - security/vuxml: add www/*chromium < 149.0.7827.114
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Mon, 15 Jun 2026 12:00:40 UTC
The branch main has been updated by rnagy:
URL: https://cgit.FreeBSD.org/ports/commit/?id=4e032f579c529bc601eeab306d1359f28f7f3414
commit 4e032f579c529bc601eeab306d1359f28f7f3414
Author: Robert Nagy <rnagy@FreeBSD.org>
AuthorDate: 2026-06-15 12:00:12 +0000
Commit: Robert Nagy <rnagy@FreeBSD.org>
CommitDate: 2026-06-15 12:00:35 +0000
security/vuxml: add www/*chromium < 149.0.7827.114
Obtained from: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html
---
security/vuxml/vuln/2026.xml | 87 ++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 87 insertions(+)
diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index dab212c5b851..8ccae89e74a7 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,90 @@
+ <vuln vid="1466c84c-68b1-11f1-8de5-a8a1599412c6">
+ <topic>chromium -- security fixes</topic>
+ <affects>
+ <package>
+ <name>chromium</name>
+ <range><lt>149.0.7827.102</lt></range>
+ </package>
+ <package>
+ <name>ungoogled-chromium</name>
+ <range><lt>149.0.7827.102</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Chrome Releases reports:</p>
+ <blockquote cite="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html">
+ <p>This update includes 28 security fixes:</p>
+ <ul>
+ <li>[516731749] Critical CVE-2026-12007: Use after free Core. Reported by Google on 2026-05-26</li>
+ <li>[516942828] Critical CVE-2026-12008: Use after free DigitalCredentials. Reported by Google on 2026-05-27</li>
+ <li>[517332006] Critical CVE-2026-12009: Insufficient validation of untrusted input ccessibility. Reported by Google on 2026-05-28</li>
+ <li>[517531647] Critical CVE-2026-12010: Heap buffer overflow GPU. Reported by Google on 2026-05-28</li>
+ <li>[518108291] Critical CVE-2026-12011: Use after free WebMIDI. Reported by Google on 2026-05-30</li>
+ <li>[499182801] High CVE-2026-12012: Use after free etwork. Reported by Google on 2026-04-03</li>
+ <li>[514229805] High CVE-2026-12013: Use after free Media. Reported by Henock Habte, Independent Security Researcher on 2026-05-18</li>
+ <li>[514742747] High CVE-2026-12014: Use after free Cast. Reported by Google on 2026-05-19</li>
+ <li>[515463295] High CVE-2026-12015: Use after free utofill. Reported by Google on 2026-05-21</li>
+ <li>[516482138] High CVE-2026-12016: Insufficient validation of untrusted input DevTools. Reported by Google on 2026-05-25</li>
+ <li>[516797143] High CVE-2026-12017: Insufficient validation of untrusted input Extensions. Reported by Google on 2026-05-26</li>
+ <li>[516808201] High CVE-2026-12018: Inappropriate implementation Mojo. Reported by Google on 2026-05-26</li>
+ <li>[516872067] High CVE-2026-12019: Out of bounds write Codecs. Reported by Google on 2026-05-26</li>
+ <li>[516907083] High CVE-2026-12020: Use after free utofill. Reported by Google on 2026-05-27</li>
+ <li>[516929496] High CVE-2026-12022: Race Safe Browsing. Reported by Google on 2026-05-27</li>
+ <li>[517018374] High CVE-2026-12023: Use after free GPU. Reported by Google on 2026-05-27</li>
+ <li>[517086161] High CVE-2026-12024: Insufficient policy enforcement DevTools. Reported by Google on 2026-05-27</li>
+ <li>[517153191] High CVE-2026-12025: Insufficient validation of untrusted input etwork. Reported by Google on 2026-05-27</li>
+ <li>[517347084] High CVE-2026-12026: Out of bounds read Video. Reported by Google on 2026-05-28</li>
+ <li>[517517155] High CVE-2026-12027: Insufficient policy enforcement Headless. Reported by Google on 2026-05-28</li>
+ <li>[517555461] High CVE-2026-12028: Use after free GPU. Reported by Google on 2026-05-28</li>
+ <li>[518002958] High CVE-2026-12029: Use after free Video. Reported by Google on 2026-05-29</li>
+ <li>[518007423] High CVE-2026-12030: Heap buffer overflow GPU. Reported by Google on 2026-05-29</li>
+ <li>[518045638] High CVE-2026-12031: Inappropriate implementation Views. Reported by Google on 2026-05-30</li>
+ <li>[518128953] High CVE-2026-12032: Inappropriate implementation Passwords. Reported by Google on 2026-05-30</li>
+ <li>[519248779] High CVE-2026-12033: Out of bounds read VideoCapture. Reported by Google on 2026-06-02</li>
+ <li>[519258799] High CVE-2026-12034: Insufficient validation of untrusted input Linux Toolkit Theming. Reported by Google on 2026-06-02</li>
+ <li>[520210566] High CVE-2026-12035: Use after free Views. Reported by Google on 2026-06-05</li>
+ </ul>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2026-12007</cvename>
+ <cvename>CVE-2026-12008</cvename>
+ <cvename>CVE-2026-12009</cvename>
+ <cvename>CVE-2026-12010</cvename>
+ <cvename>CVE-2026-12011</cvename>
+ <cvename>CVE-2026-12012</cvename>
+ <cvename>CVE-2026-12013</cvename>
+ <cvename>CVE-2026-12014</cvename>
+ <cvename>CVE-2026-12015</cvename>
+ <cvename>CVE-2026-12016</cvename>
+ <cvename>CVE-2026-12017</cvename>
+ <cvename>CVE-2026-12018</cvename>
+ <cvename>CVE-2026-12019</cvename>
+ <cvename>CVE-2026-12020</cvename>
+ <cvename>CVE-2026-12022</cvename>
+ <cvename>CVE-2026-12023</cvename>
+ <cvename>CVE-2026-12024</cvename>
+ <cvename>CVE-2026-12025</cvename>
+ <cvename>CVE-2026-12026</cvename>
+ <cvename>CVE-2026-12027</cvename>
+ <cvename>CVE-2026-12028</cvename>
+ <cvename>CVE-2026-12029</cvename>
+ <cvename>CVE-2026-12030</cvename>
+ <cvename>CVE-2026-12031</cvename>
+ <cvename>CVE-2026-12032</cvename>
+ <cvename>CVE-2026-12033</cvename>
+ <cvename>CVE-2026-12034</cvename>
+ <cvename>CVE-2026-12035</cvename>
+ <url>https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html</url>
+ </references>
+ <dates>
+ <discovery>2026-06-11</discovery>
+ <entry>2026-06-15</entry>
+ </dates>
+ </vuln>
+
<vuln vid="76b09b16-638b-11f1-8e16-901b0e13f1a0">
<topic>libsmi -- Buffer overflow in the smiGetNode function in lib/smi</topic>
<affects>