-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 23 Sep 2025 16:50:58 -0400 Source: chromium Architecture: source Version: 140.0.7339.207-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: Debian Chromium Team Changed-By: Andres Salomon Changes: chromium (140.0.7339.207-1~deb13u1) trixie-security; urgency=high . * New upstream security release. - CVE-2025-10890: Side-channel information leakage in V8. Reported by Mate Marjanović (SharpEdged). - CVE-2025-10891: Integer overflow in V8. Reported by Google Big Sleep. - CVE-2025-10892: Integer overflow in V8. Reported by Google Big Sleep. Checksums-Sha1: b21d3185380ee92d8c309f7a24ea4a9112f22494 4027 chromium_140.0.7339.207-1~deb13u1.dsc 86bd2445b36de5d1d6e5b3cc47e471d248d832a8 993803584 chromium_140.0.7339.207.orig.tar.xz b212390c26ff92166e675df06fd907bcaa29b687 413916 chromium_140.0.7339.207-1~deb13u1.debian.tar.xz 53620ba0b69916fb8e67ae9cd4ef60cfdda3927b 26485 chromium_140.0.7339.207-1~deb13u1_source.buildinfo Checksums-Sha256: 53e7e3bf24fe72a4d88562a7161ea728d61bb434931712cbdd44b7f8d1f9e0d5 4027 chromium_140.0.7339.207-1~deb13u1.dsc 38b0d4dfb3a839f0cf6d7e05ddc55f3d73bcdf519e2211fa0d3d797824b548d0 993803584 chromium_140.0.7339.207.orig.tar.xz 7ddde75b9ab4632f797810aa13cf0aaf80a703c38aff44a24926ba0f9208b857 413916 chromium_140.0.7339.207-1~deb13u1.debian.tar.xz f352d56612e545a99ae54692d858095663f2fa4cadb804195c0e8f82c7a553a7 26485 chromium_140.0.7339.207-1~deb13u1_source.buildinfo Files: 58bf3ca99affd5fde6150573acb507bc 4027 web optional chromium_140.0.7339.207-1~deb13u1.dsc 2d18b4e91e7ad24cc5b42f7cc42a87f8 993803584 web optional chromium_140.0.7339.207.orig.tar.xz 4dbfb5435a3b8a8aab41e7dfb681d17b 413916 web optional chromium_140.0.7339.207-1~deb13u1.debian.tar.xz 64f76c36ef513a815b99e56e13d065ec 26485 web optional chromium_140.0.7339.207-1~deb13u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmjUFqIUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8Nudjculw/9FLK7SpPuybLWvGVNhRFXfPobPPS/ o16du6WN37GxiKQbogBqWVMVMnn4bZ7ByZIVWPA60UW2h88NTwu17BcK10xlissq GykNLiwT1CBtb8LxH/+Ji+sGezD9Tot/uD2k8uWK+bcjOwDXd5fD3ZYdVNWpzMe8 llsiQl1wYy0toj09qhkk6EcOGAKUEtdEhsmWUt0GcO0xgB/o/7o1JZJBFEmfEXCZ UdNFzdUELBPOl/XzakZ2Q8cZPAnkjrXmXag0+7GF0kq9SS3liM2YDvtmOfmzcaFZ A/LuqI9WkQvQevulgVsIeVEPmxZyI4NJa9t4KVUANKMLLnrEOsYOfoQGc3LG0CWB 9pfaZO957COvbBhe6x4AWGYFC78PMI8xGzcS2ZEtebT+stqxeVUDfnXqhMqDtp2d TAU+pec9GandH6w+FcycAMrtn/W2AbcyWD9bZM3Yv1DFrT0VWZJO4kqNmb7m6VGp 21+EpgTQv6kdPPzY8rKYP81Ekp7VZAa/r0iJYemHtL5Q5QNBv9U6mys/J+NEygpR Msg8rfrIXhVglv/IFPQD5QHa7DZQbNTO9+XaPmjTahowDBGqyz4aheNbj95P1HFC LI0b6pUk0zg1hqZ+t8hSBy6LmlZpBubHUBIRCwNaVjeBKAU1aPgaIWWQ9FiSfCDr cF9EvDmU7Ppk15w= =LlZE -----END PGP SIGNATURE-----