Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

chromedriver-151.0.7922.137-1.1 RPM for x86_64

From OpenSuSE Tumbleweed for x86_64

Name: chromedriver Distribution: openSUSE Tumbleweed
Version: 151.0.7922.137 Vendor: openSUSE
Release: 1.1 Build date: Wed Aug 12 09:07:08 2026
Group: Unspecified Build host: reproducible
Size: 57888830 Source RPM: chromium-151.0.7922.137-1.1.nosrc.rpm
Packager: https://bugs.opensuse.org
Url: https://www.chromium.org/
Summary: WebDriver for Google Chrome/Chromium
WebDriver is an open source tool for automated testing of webapps across many browsers. It provides capabilities for navigating to web pages, user input, JavaScript execution, and more. ChromeDriver is a standalone server which implements WebDriver's wire protocol for Chromium. It is being developed by members of the Chromium and WebDriver teams.

Provides

Requires

License

BSD-3-Clause

Changelog

* Wed Aug 12 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromiu 151.0.7922.137 (boo#1274759):
    * CVE-2026-19556: Use after free in V8
    * CVE-2026-19557: Use after free in TabStrip
    * CVE-2026-19558: Use after free in Extensions
    * CVE-2026-19559: Use after free in HTML
    * CVE-2026-19560: Use after free in Blink
* Fri Aug 07 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 151.0.7922.108 (boo#1274549):
    * CVE-2026-19137: Use after free in WebGL
    * CVE-2026-19149: Use after free in Aura
    * CVE-2026-19154: Use after free in Skia
    * CVE-2026-19157: Out of bounds write in ANGLE
    * CVE-2026-19170: Use after free in WebGL
    * CVE-2026-19172: Use after free in Views
    * CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks
    * CVE-2026-19168: Inappropriate implementation in V8
    * CVE-2026-19138: Heap buffer overflow in CrashReporting
    * CVE-2026-19139: Race in CredentialProvider
    * CVE-2026-19140: Use after free in GPU
    * CVE-2026-19141: Use after free in Resources
    * CVE-2026-19142: Use after free in Views
    * CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
    * CVE-2026-19144: Use after free in HTML
    * CVE-2026-19145: Use after free in Translate
    * CVE-2026-19146: Uninitialized Use in GPU
    * CVE-2026-19147: Use after free in Aura
    * CVE-2026-19148: Out of bounds write in GPU
    * CVE-2026-19150: Inappropriate implementation in V8
    * CVE-2026-19151: Use after free in V8
    * CVE-2026-19152: Inappropriate implementation in Navigation
    * CVE-2026-19153: Insufficient validation of untrusted input in Workers
    * CVE-2026-19155: Use after free in Payments
    * CVE-2026-19156: Heap buffer overflow in Base
    * CVE-2026-19158: Use after free in Views
    * CVE-2026-19159: Use after free in Views
    * CVE-2026-19160: Uninitialized Use in Skia
    * CVE-2026-19161: Uninitialized Use in Skia
    * CVE-2026-19162: Out of bounds write in V8
    * CVE-2026-19163: Use after free in Media
    * CVE-2026-19164: Insufficient validation of untrusted input in Codecs
    * CVE-2026-19165: Use after free in Extensions
    * CVE-2026-19166: Use after free in Web Authentication
    * CVE-2026-19167: Integer overflow in GPU
    * CVE-2026-19171: Use after free in Media
    * CVE-2026-19173: Out of bounds write in Skia
    * CVE-2026-19174: Integer overflow in V8
    * CVE-2026-19175: Use after free in Payments
    * CVE-2026-19176: Use after free in Skia
    * CVE-2026-19177: Insufficient validation of untrusted input in UI
* Tue Aug 04 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 151.0.7922.75:
    * stability fix
    * pull in SKIA updates
* Thu Jul 30 2026 Ruediger Oertel <ro@suse.com>
  - Chromium 151.0.7922.71 (boo#1272936):
    * CVE-2026-17650: Use after free in Compositing
    * CVE-2026-17651: Insufficient validation of untrusted input in Dawn
    * CVE-2026-17652: Use after free in Views
    * CVE-2026-17653: Use after free in Skia
    * CVE-2026-17654: Race in Updater
    * CVE-2026-17655: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-17656: Use after free in Ozone
    * CVE-2026-17657: Use after free in Navigation
    * CVE-2026-17658: Use after free in V8
    * CVE-2026-17659: Inappropriate implementation in SiteIsolation
    * CVE-2026-17660: Insufficient validation of untrusted input in Network
    * CVE-2026-17661: Use after free in Loader
    * CVE-2026-17662: Insufficient policy enforcement in Prefetch
    * CVE-2026-17663: Insufficient validation of untrusted input in GPU
    * CVE-2026-17664: Insufficient validation of untrusted input in Loader
    * CVE-2026-17665: Use after free in V8
    * CVE-2026-17666: Cryptographic Flaw in Enterprise
    * CVE-2026-17667: Uninitialized Use in ANGLE
    * CVE-2026-17668: Uninitialized Use in ANGLE
    * CVE-2026-17669: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17670: Use after free in Views
    * CVE-2026-17671: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-17672: Insufficient validation of untrusted input in Chromecast
    * CVE-2026-17673: Integer overflow in QUIC
    * CVE-2026-17674: Inappropriate implementation in HTML
    * CVE-2026-17675: Out of bounds write in ANGLE
    * CVE-2026-17676: Inappropriate implementation in ANGLE
    * CVE-2026-17677: Inappropriate implementation in ANGLE
    * CVE-2026-17678: Out of bounds read in ANGLE
    * CVE-2026-17679: Insufficient validation of untrusted input in Print Preview
    * CVE-2026-17680: Heap buffer overflow in Color
    * CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication
    * CVE-2026-17682: Integer overflow in ANGLE
    * CVE-2026-17683: Inappropriate implementation in ANGLE
    * CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-17685: Use after free in Autofill
    * CVE-2026-17686: Insufficient validation of untrusted input in Passwords
    * CVE-2026-17687: Type Confusion in ANGLE
    * CVE-2026-17688: Use after free in Input
    * CVE-2026-17689: Uninitialized Use in ANGLE
    * CVE-2026-17690: Insufficient validation of untrusted input in PDF
    * CVE-2026-17691: Out of bounds write in ANGLE
    * CVE-2026-17692: Use after free in DataTransfer
    * CVE-2026-17693: Inappropriate implementation in FileSystem
    * CVE-2026-17694: Use after free in DOM
    * CVE-2026-17695: Inappropriate implementation in ANGLE
    * CVE-2026-17696: Side-channel information leakage in Media
    * CVE-2026-17697: Type Confusion in ANGLE
    * CVE-2026-17698: Insufficient validation of untrusted input in UI
    * CVE-2026-17699: Use after free in Views
    * CVE-2026-17700: Insufficient validation of untrusted input in Actor
    * CVE-2026-17701: Out of bounds read in ANGLE
    * CVE-2026-17702: Inappropriate implementation in Skia
    * CVE-2026-17703: Policy bypass in Chrome for iOS
    * CVE-2026-17704: Use after free in ANGLE
    * CVE-2026-17705: Integer overflow in libxml
    * CVE-2026-17706: Insufficient validation of untrusted input in Media
    * CVE-2026-17707: Uninitialized Use in Media
    * CVE-2026-17708: Use after free in Audio
    * CVE-2026-17709: Race in Downloads
    * CVE-2026-17710: Inappropriate implementation in MHTML
    * CVE-2026-17711: Race in Downloads
    * CVE-2026-17712: Race in Skia
    * CVE-2026-17713: Insufficient validation of untrusted input in Accessibility
    * CVE-2026-17714: Uninitialized Use in ANGLE
    * CVE-2026-17715: Inappropriate implementation in Passwords
    * CVE-2026-17716: Use after free in Updater
    * CVE-2026-17717: Integer overflow in ANGLE
    * CVE-2026-17718: Use after free in ANGLE
    * CVE-2026-17719: Use after free in Input
    * CVE-2026-17720: Insufficient policy enforcement in Passwords
    * CVE-2026-17721: Out of bounds write in ANGLE
    * CVE-2026-17722: Object lifecycle issue in WebView
    * CVE-2026-17723: Use after free in Media
    * CVE-2026-17724: Race in Chrome for iOS
    * CVE-2026-17725: Type Confusion in V8
    * CVE-2026-17726: Integer overflow in WebGL
    * CVE-2026-17727: Out of bounds write in WebGL
    * CVE-2026-17728: Inappropriate implementation in Extensions
    * CVE-2026-17758: Heap buffer overflow in Dawn
    * CVE-2026-17732: Inappropriate implementation in SVG
    * CVE-2026-17729: Use after free in V8
    * CVE-2026-17730: Side-channel information leakage in Autofill
    * CVE-2026-17731: Inappropriate implementation in Autofill
    * CVE-2026-17733: Inappropriate implementation in QUIC
    * CVE-2026-17734: Inappropriate implementation in Autofill
    * CVE-2026-17735: Insufficient validation of untrusted input in BFCache
    * CVE-2026-17736: Insufficient validation of untrusted input in WebView
    * CVE-2026-17737: Use after free in Bluetooth
    * CVE-2026-17738: Insufficient validation of untrusted input in Payments
    * CVE-2026-17739: Insufficient policy enforcement in Extensions
    * CVE-2026-17740: Uninitialized Use in ANGLE
    * CVE-2026-17741: Insufficient validation of untrusted input in WebView
    * CVE-2026-17742: Insufficient policy enforcement in Payments
    * CVE-2026-17743: Insufficient policy enforcement in ControlledFrame
    * CVE-2026-17744: Inappropriate implementation in File Input
    * CVE-2026-17745: Out of bounds read in Skia
    * CVE-2026-17746: Use after free in GPU
    * CVE-2026-17747: Insufficient validation of untrusted input in Payments
    * CVE-2026-17748: Inappropriate implementation in Extensions
    * CVE-2026-17749: Insufficient validation of untrusted input in Extensions
    * CVE-2026-17750: Use after free in ANGLE
    * CVE-2026-17751: Inappropriate implementation in AdFilter
    * CVE-2026-17752: Use after free in Views
    * CVE-2026-17753: Inappropriate implementation in Autofill
    * CVE-2026-17754: Inappropriate implementation in Blink
    * CVE-2026-17755: Incorrect security UI in Extensions
    * CVE-2026-17756: Insufficient policy enforcement in Presentation
    * CVE-2026-17757: Uninitialized Use in Skia
    * CVE-2026-17759: Uninitialized Use in Codecs
    * CVE-2026-17760: Side-channel information leakage in NoStatePrefetch
    * CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-17762: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17763: Inappropriate implementation in GPU
    * CVE-2026-17764: Inappropriate implementation in FedCM
    * CVE-2026-17765: Inappropriate implementation in WebProtect
    * CVE-2026-17766: Insufficient validation of untrusted input in Clipboard
    * CVE-2026-17767: Insufficient validation of untrusted input in WebView
    * CVE-2026-17768: Insufficient validation of untrusted input in WebSockets
    * CVE-2026-17769: Insufficient validation of untrusted input in Cast
    * CVE-2026-17770: Out of bounds read in Media
    * CVE-2026-17771: Uninitialized Use in Skia
    * CVE-2026-17772: Out of bounds read in WebGL
    * CVE-2026-17773: Insufficient validation of untrusted input in Cast
    * CVE-2026-17774: Insufficient validation of untrusted input in Variations
    * CVE-2026-17775: Inappropriate implementation in PresentationAPI
    * CVE-2026-17776: Policy bypass in Receiver
    * CVE-2026-17777: Inappropriate implementation in Autofill
    * CVE-2026-17778: Use after free in Extensions
    * CVE-2026-17779: Inappropriate implementation in Site Isolation
    * CVE-2026-17780: Inappropriate implementation in Isolated Web Apps
    * CVE-2026-17781: Inappropriate implementation in Extensions
    * CVE-2026-17782: Incorrect security UI in Chrome for iOS
    * CVE-2026-17783: Inappropriate implementation in Loader
    * CVE-2026-17784: Use after free in Audio
    * CVE-2026-17785: Uninitialized Use in ANGLE
    * CVE-2026-17786: Insufficient validation of untrusted input in DevTools
    * CVE-2026-17787: Inappropriate implementation in DevTools
    * CVE-2026-17788: Inappropriate implementation in Blink
    * CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-17790: Uninitialized Use in ANGLE
    * CVE-2026-17791: Insufficient validation of untrusted input in Payments
    * CVE-2026-17792: Inappropriate implementation in Credential Management
    * CVE-2026-17793: Inappropriate implementation in Messages
    * CVE-2026-17794: Insufficient validation of untrusted input in Mobile
    * CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia
    * CVE-2026-17796: Side-channel information leakage in WebXR
    * CVE-2026-17797: Inappropriate implementation in CSS
    * CVE-2026-17798: Inappropriate implementation in Cast
    * CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing
    * CVE-2026-17800: Side-channel information leakage in MediaRecording
    * CVE-2026-17801: Out of bounds memory access in ANGLE
    * CVE-2026-17802: Side-channel information leakage in GPU
    * CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive
    * CVE-2026-17804: Use after free in Media
    * CVE-2026-17805: Insufficient policy enforcement in Glic
    * CVE-2026-17806: Insufficient validation of untrusted input in Extensions
    * CVE-2026-17807: Use after free in V8
    * CVE-2026-17808: Uninitialized Use in WebGL
    * CVE-2026-17809: Insufficient validation of untrusted input in Extensions
    * CVE-2026-17810: Uninitialized Use in Dawn
    * CVE-2026-17811: Use after free in ANGLE
    * CVE-2026-17812: Inappropriate implementation in DigitalCredentials
    * CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS
    * CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-17815: Insufficient policy enforcement in GuestView
    * CVE-2026-17816: Inappropriate implementation in Speech
    * CVE-2026-17817: Inappropriate implementation in ReportingAndNEL
    * CVE-2026-17818: Inappropriate implementation in Network
    * CVE-2026-17819: Inappropriate implementation in WebAppInstalls
    * CVE-2026-17820: Insufficient policy enforcement in Autofill
    * CVE-2026-17821: Insufficient policy enforcement in Extensions
    * CVE-2026-17822: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17823: Insufficient policy enforcement in WebXR
    * CVE-2026-17824: Insufficient policy enforcement in ServiceWorker
    * CVE-2026-17825: Insufficient policy enforcement in Passwords
    * CVE-2026-17826: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17827: Inappropriate implementation in CSS
    * CVE-2026-17828: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17829: Insufficient policy enforcement in Passwords
    * CVE-2026-17830: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17831: Insufficient validation of untrusted input in Passwords
    * CVE-2026-17832: Use after free in ANGLE
    * CVE-2026-17833: Inappropriate implementation in Passwords
    * CVE-2026-17834: Inappropriate implementation in Passwords
    * CVE-2026-17835: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17836: Use after free in V8
    * CVE-2026-17837: Insufficient validation of untrusted input in DevTools
    * CVE-2026-17838: Incorrect security UI in Chrome for iOS
    * CVE-2026-17839: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17840: Incorrect security UI in Passwords
    * CVE-2026-17841: Race in Chrome for iOS
    * CVE-2026-17842: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17843: Inappropriate implementation in CSS
    * CVE-2026-17844: Insufficient validation of untrusted input in Cast
    * CVE-2026-17845: Inappropriate implementation in CSS
    * CVE-2026-17846: Inappropriate implementation in Media
    * CVE-2026-17847: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-17848: Insufficient validation of untrusted input in Codecs
    * CVE-2026-17849: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17850: Inappropriate implementation in Permissions
    * CVE-2026-17851: Side-channel information leakage in Autofill
    * CVE-2026-17852: Inappropriate implementation in Media Router
    * CVE-2026-17853: Inappropriate implementation in DevTools
    * CVE-2026-17854: Insufficient policy enforcement in WebMCP
    * CVE-2026-17855: Race in DevTools
    * CVE-2026-17856: Inappropriate implementation in Network
    * CVE-2026-17857: Inappropriate implementation in Network
    * CVE-2026-17858: Uninitialized Use in WebNN
    * CVE-2026-17859: Side-channel information leakage in Favicons
    * CVE-2026-17860: Insufficient validation of untrusted input in Mobile
    * CVE-2026-17861: Insufficient validation of untrusted input in Updater
    * CVE-2026-17862: Use after free in Tracing
    * CVE-2026-17863: Inappropriate implementation in Browser
    * CVE-2026-17864: Inappropriate implementation in Updater
    * CVE-2026-17865: Inappropriate implementation in Crypto
    * CVE-2026-17866: Type Confusion in Tab
    * CVE-2026-17867: Insufficient validation of untrusted input in Dawn
    * CVE-2026-17868: Insufficient policy enforcement in USB
    * CVE-2026-17869: Out of bounds read in WebXR
    * CVE-2026-17870: Insufficient validation of untrusted input in Cast
    * CVE-2026-17871: Inappropriate implementation in Passwords
    * CVE-2026-17872: Cryptographic Flaw in WebAppInstalls
    * CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS
    * CVE-2026-17874: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17875: Use after free in PDFium
    * CVE-2026-17876: Inappropriate implementation in Payments
    * CVE-2026-17877: Inappropriate implementation in Chromoting
    * CVE-2026-17878: Inappropriate implementation in CSS
    * CVE-2026-17879: Inappropriate implementation in Autofill
    * CVE-2026-17880: Inappropriate implementation in Autofill
    * CVE-2026-17881: Use after free in WebXR
    * CVE-2026-17882: Policy bypass in Extensions
    * CVE-2026-17883: Inappropriate implementation in Headless
    * CVE-2026-17884: Object lifecycle issue in WebRTC
    * CVE-2026-17885: Inappropriate implementation in Paint
    * CVE-2026-17886: Use after free in Enterprise
    * CVE-2026-17887: Use after free in TabStrip
    * CVE-2026-17888: Insufficient validation of untrusted input in WebUI
    * CVE-2026-17889: Uninitialized Use in WebXR
    * CVE-2026-17890: Insufficient validation of untrusted input in DevTools
    * CVE-2026-17891: Use after free in ANGLE
    * CVE-2026-17892: Inappropriate implementation in WebXR
    * CVE-2026-17893: Insufficient validation of untrusted input in Updater
    * CVE-2026-17894: Use after free in Views
    * CVE-2026-17895: Inappropriate implementation in DataTransfer
    * CVE-2026-17896: Use after free in DevTools
    * CVE-2026-17897: Inappropriate implementation in ORB
    * CVE-2026-17898: Use after free in DevTools
    * CVE-2026-17899: Insufficient policy enforcement in DevTools
    * CVE-2026-17900: Inappropriate implementation in Enterprise
    * CVE-2026-17901: Inappropriate implementation in Sharing
    * CVE-2026-17902: Inappropriate implementation in Editing
    * CVE-2026-17903: Insufficient policy enforcement in Chromecast
    * CVE-2026-17904: Insufficient policy enforcement in NFC
    * CVE-2026-17905: Inappropriate implementation in SurfaceCapture
    * CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth
    * CVE-2026-17907: Side-channel information leakage in Network
    * CVE-2026-17908: Insufficient validation of untrusted input in Printing
    * CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps
    * CVE-2026-17910: Insufficient policy enforcement in NFC
    * CVE-2026-17911: Insufficient policy enforcement in SVG
    * CVE-2026-17912: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17913: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17914: Side-channel information leakage in Skia
    * CVE-2026-17915: Inappropriate implementation in WebView
    * CVE-2026-17916: Insufficient policy enforcement in Settings
    * CVE-2026-17917: Policy bypass in Chrome for iOS
    * CVE-2026-17918: Use after free in Sync
    * CVE-2026-17919: Insufficient policy enforcement in Enterprise
    * CVE-2026-17920: Use after free in V8
    * CVE-2026-17921: Insufficient validation of untrusted input in Navigation
    * CVE-2026-17922: Inappropriate implementation in Enterprise
    * CVE-2026-17923: Policy bypass in Enterprise
    * CVE-2026-17924: Use after free in DNS
    * CVE-2026-17925: Inappropriate implementation in Cast
    * CVE-2026-17926: Insufficient validation of untrusted input in DevTools
    * CVE-2026-17927: Insufficient policy enforcement in DevTools
    * CVE-2026-17928: Inappropriate implementation in DataTransfer
    * CVE-2026-17929: Insufficient validation of untrusted input in DevTools
    * CVE-2026-17930: Insufficient validation of untrusted input in Extensions
    * CVE-2026-17931: Inappropriate implementation in DevTools
    * CVE-2026-17932: Use after free in DataTransfer
    * CVE-2026-17933: Inappropriate implementation in DOMStorage
    * CVE-2026-17934: Insufficient validation of untrusted input in DevTools
    * CVE-2026-17935: Heap buffer overflow in Codecs
    * CVE-2026-17936: Inappropriate implementation in DevTools
    * CVE-2026-17937: Inappropriate implementation in DevTools
    * CVE-2026-17938: Inappropriate implementation in FullScreen
    * CVE-2026-17939: Inappropriate implementation in Passwords
    * CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture
    * CVE-2026-17941: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17942: Side-channel information leakage in SVG
    * CVE-2026-17943: Inappropriate implementation in Parser
    * CVE-2026-17944: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17945: Inappropriate implementation in Navigation
    * CVE-2026-17946: Uninitialized Use in Dawn
    * CVE-2026-17947: Use after free in WebSockets
    * CVE-2026-17948: Type Confusion in V8
    * CVE-2026-17949: Uninitialized Use in GPU
    * CVE-2026-17950: Policy bypass in Safebrowsing
    * CVE-2026-17951: Heap buffer overflow in WebRTC
    * CVE-2026-17952: Inappropriate implementation in V8
    * CVE-2026-17953: Insufficient policy enforcement in WebView
    * CVE-2026-17954: Policy bypass in MHTML
    * CVE-2026-17955: Insufficient validation of untrusted input in Payments
    * CVE-2026-17956: Inappropriate implementation in Scheduling
    * CVE-2026-17957: Inappropriate implementation in CORS
    * CVE-2026-17958: Inappropriate implementation in Views
    * CVE-2026-17959: Inappropriate implementation in Network
    * CVE-2026-17960: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17961: Inappropriate implementation in Session
    * CVE-2026-17962: Inappropriate implementation in Blink
    * CVE-2026-17963: Inappropriate implementation in SVG
    * CVE-2026-17964: Incorrect security UI in UI
    * CVE-2026-17965: Incorrect security UI in Chrome for iOS
    * CVE-2026-17966: Inappropriate implementation in Views
    * CVE-2026-17967: Use after free in Chrome for iOS
    * CVE-2026-17968: Uninitialized Use in WebXR
    * CVE-2026-17969: Inappropriate implementation in Passwords
    * CVE-2026-17970: Insufficient validation of untrusted input in Passwords
    * CVE-2026-17971: Inappropriate implementation in Frame
    * CVE-2026-17972: Inappropriate implementation in Chrome for iOS
    * CVE-2026-17973: Inappropriate implementation in Views
    * CVE-2026-17974: Insufficient policy enforcement in DevTools
    * CVE-2026-17975: Inappropriate implementation in IME
    * CVE-2026-17976: Policy bypass in Extensions
    * CVE-2026-17977: Policy bypass in CSS
    * CVE-2026-17978: Side-channel information leakage in WebCodecs
    * CVE-2026-17979: Race in V8
    * CVE-2026-17980: Inappropriate implementation in UI
    * CVE-2026-17981: Inappropriate implementation in Blink
    * CVE-2026-17982: Insufficient validation of untrusted input in Cast
    * CVE-2026-17983: Incorrect security UI in Global Media Controls
    * CVE-2026-17984: Inappropriate implementation in Browser
    * CVE-2026-17985: Insufficient policy enforcement in Speech
    * CVE-2026-17986: Insufficient policy enforcement in Bluetooth
    * CVE-2026-17987: Insufficient validation of untrusted input in Notifications
    * CVE-2026-17988: Insufficient validation of untrusted input in Navigation
    * CVE-2026-17989: Type Confusion in V8
    * CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn
    * CVE-2026-17991: Insufficient validation of untrusted input in AI
    * CVE-2026-17992: Uninitialized Use in Skia
    * CVE-2026-17993: Race in Updater
    * CVE-2026-17994: Inappropriate implementation in Media
    * CVE-2026-17995: Out of bounds read in Dawn
    * CVE-2026-17996: Inappropriate implementation in Browser
    * CVE-2026-17997: Inappropriate implementation in Passwords
    * CVE-2026-17998: Incorrect security UI in Extensions
    * CVE-2026-17999: Incorrect security UI in PictureInPicture
    * CVE-2026-18000: Insufficient policy enforcement in USB
    * CVE-2026-18001: Inappropriate implementation in WebGL
    * CVE-2026-18002: Insufficient validation of untrusted input in Google Lens
    * CVE-2026-18003: Inappropriate implementation in Chrome for iOS
    * CVE-2026-18004: Insufficient policy enforcement in Speech
    * CVE-2026-18005: Inappropriate implementation in WebXR
    * CVE-2026-18006: Inappropriate implementation in Google Lens
    * CVE-2026-18007: Inappropriate implementation in Input
    * CVE-2026-18008: Inappropriate implementation in Settings
    * CVE-2026-18009: Insufficient validation of untrusted input in Passwords
    * CVE-2026-18010: Inappropriate implementation in Passwords
    * CVE-2026-18011: Inappropriate implementation in Chrome for iOS
    * CVE-2026-18012: Use after free in PDFium
    * CVE-2026-18013: Inappropriate implementation in Chrome for iOS
    * CVE-2026-18014: Insufficient validation of untrusted input in DevTools
    * CVE-2026-18015: Inappropriate implementation in Tint
    * CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS
    * CVE-2026-18017: Use after free in Dawn
    * CVE-2026-18018: Inappropriate implementation in Updater
    * CVE-2026-18019: Side-channel information leakage in Media
* Fri Jul 24 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 151.0.7922.47 (beta released 2026-07-22)
  - modified patches:
    * ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch
    * ppc-fedora-0002-regenerate-xnn-buildgn.patch
    * ppc-fedora-0001-sandbox-Enable-seccomp_bpf-for-ppc64.patch
    * ppc-fedora-skia-vsx-instructions.patch
    * chromium-150-toolchain.patch
    * chromium-146-ignore-for-ubsan.patch
    * disable-ai.patch
  - added patches:
    * ppc-dawn-add-ppc64.patch
    * chromium-151-metrics-metadata-histograms.patch
    * chromium-151-value_or.patch
    * chromium-150-raw-ref-map-find.patch
    * chromium-151-privatefriends.patch
    * chromium-151-constexpr.patch
    * chromium-150-i18n-builder-enum.patch
  - dropped patches:
    * chromium-117-string-convert.patch
    * chromium-150-sysroot.patch
    * disable-ai.patch
    * ppc-fedora-fix-partition-alloc-compile.patch
    * chromium-150-icubridge_item_length.patch
    * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch
  - create links for go binary in dawn tree
  - drop disable-ai.conf, seems to break more than it solves
    (https://bugzilla.redhat.com/show_bug.cgi?id=2501811)
    (additionally the "your browser is being managed" message)
* Fri Jul 24 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 150.0.7871.186 (boo#1272460):
    * CVE-2026-16807: Out of bounds write in Codecs
    * CVE-2026-16806: Use after free in WebMCP
    * CVE-2026-16805: Use after free in Blink
    * CVE-2026-16804: Use after free in Input
* Wed Jul 22 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 150.0.7871.181 (boo#1272156):
    * CVE-2026-16420: Type Confusion in WebAudio
    * CVE-2026-16421: Inappropriate implementation in WebAudio
    * CVE-2026-16413: Out of bounds write in ANGLE
    * CVE-2026-16414: Insufficient validation of untrusted input in Chromecast
    * CVE-2026-16415: Insufficient validation of untrusted input in Extensions
    * CVE-2026-16416: Integer overflow in Chromecast
    * CVE-2026-16417: Uninitialized Use in Skia
    * CVE-2026-16418: Stack buffer overflow in V8
    * CVE-2026-16419: Out of bounds read and write in ANGLE
    * CVE-2026-16422: Insufficient validation of untrusted input in Certificate
    * CVE-2026-16423: Use after free in UI
    * CVE-2026-16424: Use after free in GPU
* Fri Jul 17 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 150.0.7871.128 (boo#1271656):
    * CVE-2026-15899: Use after free in CameraCapture
    * CVE-2026-15900: Use after free in GPU
    * CVE-2026-15901: Use after free in Network
    * CVE-2026-15902: Use after free in Cast
    * CVE-2026-15903: Out of bounds read and write in V8
    * CVE-2026-15904: Use after free in Ozone
    * CVE-2026-15905: Use after free in Aura
* Tue Jul 14 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 150.0.7871.124 (boo#1271415):
    * CVE-2026-15764: Use after free in Ozone
    * CVE-2026-15765: Use after free in Ozone
    * CVE-2026-15766: Uninitialized Use in Skia
    * CVE-2026-15767: Heap buffer overflow in libyuv
    * CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas
    * CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming
    * CVE-2026-15770: Uninitialized Use in V8
    * CVE-2026-15771: Insufficient validation of untrusted input in Media
    * CVE-2026-15772: Use after free in GPU
    * CVE-2026-15773: Use after free in Core
    * CVE-2026-15774: Use after free in Skia
    * CVE-2026-15775: Insufficient policy enforcement in V8
    * CVE-2026-15776: Type Confusion in V8
    * CVE-2026-15777: Use after free in UI
    * CVE-2026-15778: Insufficient validation of untrusted input in Navigation
* Thu Jul 09 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 150.0.7871.114 (boo#1271093):
    * CVE-2026-15112: Use after free in Ozone
    * CVE-2026-15129: Use after free in Views
    * CVE-2026-15132: Uninitialized Use in V8
    * CVE-2026-15133: Use after free in InterestGroups
    * CVE-2026-15108: Integer overflow in Extensions API
    * CVE-2026-15109: Uninitialized Use in ANGLE
    * CVE-2026-15110: Use after free in Extensions
    * CVE-2026-15111: Use after free in Views
    * CVE-2026-15113: Use after free in Autofill
    * CVE-2026-15114: Out of bounds read and write in Codecs
    * CVE-2026-15115: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-15116: Use after free in Actor
    * CVE-2026-15117: Use after free in Payments
    * CVE-2026-15118: Use after free in Input
    * CVE-2026-15119: Inappropriate implementation in GetUserMedia
    * CVE-2026-15120: Use after free in Core
    * CVE-2026-15121: Use after free in WebRTC
    * CVE-2026-15122: Insufficient validation of untrusted input in Codecs
    * CVE-2026-15123: Insufficient data validation in DOM
    * CVE-2026-15124: Insufficient policy enforcement in Passwords
    * CVE-2026-15125: Inappropriate implementation in Forms
    * CVE-2026-15126: Use after free in Forms
    * CVE-2026-15127: Inappropriate implementation in WebGL
    * CVE-2026-15128: Inappropriate implementation in Forms
    * CVE-2026-15130: Insufficient policy enforcement in Navigation
    * CVE-2026-15107: Use after free in IndexedDB
    * CVE-2026-15131: Insufficient data validation in Navigation
* Tue Jul 07 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 150.0.7871.100:
    * stability improvements, no further information available
* Thu Jul 02 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - promote Chromium 150 (150.0.7871.46) to stable (boo#1270051)
    * CVE-2026-13774: Use after free in Extensions
    * CVE-2026-13775: Use after free in GPU
    * CVE-2026-14398: Use after free in ANGLE
    * CVE-2026-13776: Type Confusion in Dawn
    * CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb
    * CVE-2026-13778: Use after free in WebUSB
    * CVE-2026-13779: Use after free in Chromoting
    * CVE-2026-13780: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-13781: Insufficient validation of untrusted input in Skia
    * CVE-2026-14417: Use after free in Dawn
    * CVE-2026-13782: Use after free in Browser
    * CVE-2026-13783: Use after free in Views
    * CVE-2026-13784: Use after free in Views
    * CVE-2026-14419: Use after free in Skia
    * CVE-2026-13785: Use after free in Bluetooth
    * CVE-2026-14420: Out of bounds read and write in Dawn
    * CVE-2026-13786: Use after free in Ozone
    * CVE-2026-14427: Heap buffer overflow in Skia
    * CVE-2026-13787: Use after free in Chromoting
    * CVE-2026-13788: Use after free in Fullscreen
    * CVE-2026-14382: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-13790: Side-channel information leakage in Scroll
    * CVE-2026-14385: Heap buffer overflow in ANGLE
    * CVE-2026-13791: Insufficient validation of untrusted input in Downloads
    * CVE-2026-13792: Use after free in Touchbar
    * CVE-2026-13793: Insufficient policy enforcement in SVG
    * CVE-2026-14392: Out of bounds write in Tint
    * CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-14422: Out of bounds read and write in Tint
    * CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS
    * CVE-2026-14426: Use after free in V8
    * CVE-2026-13796: Integer overflow in Chromecast
    * CVE-2026-13797: Insufficient validation of untrusted input in Chromecast
    * CVE-2026-14386: Out of bounds read in ANGLE
    * CVE-2026-13798: Heap buffer overflow in Chromecast
    * CVE-2026-13799: Use after free in QUIC
    * CVE-2026-13800: Inappropriate implementation in Updater
    * CVE-2026-13801: Integer overflow in Chromecast
    * CVE-2026-13802: Use after free in Views
    * CVE-2026-13803: Type Confusion in Chrome Tabs
    * CVE-2026-13804: Use after free in Chromecast
    * CVE-2026-13805: Use after free in GFX
    * CVE-2026-14390: Use after free in ANGLE
    * CVE-2026-13806: Insufficient validation of untrusted input in Accessibility
    * CVE-2026-13807: Use after free in Import
    * CVE-2026-13808: Insufficient data validation in Chrome for iOS
    * CVE-2026-13809: Side-channel information leakage in Safe Browsing
    * CVE-2026-13810: Inappropriate implementation in Input
    * CVE-2026-13811: Use after free in IME
    * CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-13814: Use after free in Views
    * CVE-2026-13815: Use after free in Blink
    * CVE-2026-13816: Insufficient validation of untrusted input in File Input
    * CVE-2026-14396: Out of bounds read in ANGLE
    * CVE-2026-13817: Insufficient validation of untrusted input in Glic
    * CVE-2026-13818: Inappropriate implementation in Passwords
    * CVE-2026-13819: Out of bounds read in ANGLE
    * CVE-2026-13820: Out of bounds read in Skia
    * CVE-2026-14400: Out of bounds write in ANGLE
    * CVE-2026-14401: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-14402: Uninitialized Use in ANGLE
    * CVE-2026-13821: Use after free in Canvas
    * CVE-2026-13822: Inappropriate implementation in Extensions
    * CVE-2026-13823: Use after free in Glic
    * CVE-2026-13824: Insufficient validation of untrusted input in Extensions
    * CVE-2026-13825: Uninitialized Use in Dawn
    * CVE-2026-13826: Inappropriate implementation in Autofill
    * CVE-2026-13827: Use after free in Updater
    * CVE-2026-13828: Inappropriate implementation in Enterprise
    * CVE-2026-13829: Insufficient validation of untrusted input in Settings
    * CVE-2026-13830: Use after free in Chromoting
    * CVE-2026-13831: Use after free in GPU
    * CVE-2026-13832: Use after free in Headless
    * CVE-2026-14411: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-13833: Uninitialized Use in ANGLE
    * CVE-2026-14412: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-14413: Uninitialized Use in ANGLE
    * CVE-2026-13834: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-13835: Inappropriate implementation in XML
    * CVE-2026-13836: Inappropriate implementation in CSS
    * CVE-2026-13837: Inappropriate implementation in CSS
    * CVE-2026-13838: Inappropriate implementation in CSS
    * CVE-2026-13839: Inappropriate implementation in CSS
    * CVE-2026-13840: Insufficient policy enforcement in Canvas
    * CVE-2026-13841: Integer overflow in Skia
    * CVE-2026-13842: Incorrect security UI in Chrome for iOS
    * CVE-2026-14418: Uninitialized Use in ANGLE
    * CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-13844: Use after free in Updater
    * CVE-2026-13845: Use after free in DOM
    * CVE-2026-13846: Use after free in USB
    * CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-13848: Use after free in Forms
    * CVE-2026-13849: Insufficient validation of untrusted input in Chromoting
    * CVE-2026-14423: Type Confusion in Tint
    * CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-14424: Use after free in Dawn
    * CVE-2026-14425: Use after free in ANGLE
    * CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-14428: Insufficient validation of untrusted input in Dawn
    * CVE-2026-14429: Insufficient validation of untrusted input in Skia
    * CVE-2026-14430: Integer overflow in V8
    * CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-13853: Use after free in Journeys
    * CVE-2026-13854: Use after free in Ozone
    * CVE-2026-14431: Type Confusion in V8
    * CVE-2026-13855: Use after free in Ozone
    * CVE-2026-13856: Insufficient validation of untrusted input in Speech
    * CVE-2026-13857: Inappropriate implementation in Geometry
    * CVE-2026-13858: Out of bounds read in FFmpeg
    * CVE-2026-13859: Inappropriate implementation in ANGLE
    * CVE-2026-14391: Integer overflow in ANGLE
    * CVE-2026-13860: Incorrect security UI in Autofill
    * CVE-2026-14408: Uninitialized Use in Dawn
    * CVE-2026-14381: Incorrect security UI in WebAppInstalls
    * CVE-2026-14383: Inappropriate implementation in V8
    * CVE-2026-13861: Use after free in Core
    * CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys)
    * CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs
    * CVE-2026-13864: Insufficient policy enforcement in WebHID
    * CVE-2026-13865: Insufficient validation of untrusted input in Enterprise
    * CVE-2026-13866: Insufficient validation of untrusted input in Input
    * CVE-2026-13867: Inappropriate implementation in Geolocation
    * CVE-2026-13868: Inappropriate implementation in Network
    * CVE-2026-14384: Out of bounds read in ANGLE
    * CVE-2026-13869: Use after free in Device
    * CVE-2026-13870: Use after free in WebView
    * CVE-2026-13871: Insufficient data validation in GuestView
    * CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-13873: Out of bounds memory access in Layout
    * CVE-2026-13874: Inappropriate implementation in DataTransfer
    * CVE-2026-13875: Insufficient validation of untrusted input in GPU
    * CVE-2026-13876: Inappropriate implementation in Network
    * CVE-2026-13877: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-13878: Use after free in Bluetooth
    * CVE-2026-13879: Use after free in Bluetooth
    * CVE-2026-13880: Use after free in USB
    * CVE-2026-13881: Insufficient data validation in WebAppInstalls
    * CVE-2026-13882: Inappropriate implementation in USB
    * CVE-2026-13883: Type Confusion in ANGLE
    * CVE-2026-13884: Heap buffer overflow in Chromecast
    * CVE-2026-14387: Integer overflow in Skia
    * CVE-2026-13885: Use after free in Skia
    * CVE-2026-13886: Policy bypass in Isolated Web Apps
    * CVE-2026-14388: Out of bounds read in ANGLE
    * CVE-2026-14389: Integer overflow in Skia
    * CVE-2026-13887: Insufficient policy enforcement in NFC
    * CVE-2026-13888: Use after free in Extensions
    * CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication
    * CVE-2026-13890: Out of bounds read in Chromecast
    * CVE-2026-13891: Insufficient validation of untrusted input in Extensions
    * CVE-2026-13892: Inappropriate implementation in Chrome for iOS
    * CVE-2026-13893: Insufficient validation of untrusted input in WebUI
    * CVE-2026-13894: Insufficient policy enforcement in Network
    * CVE-2026-13895: Inappropriate implementation in Autofill
    * CVE-2026-13896: Insufficient policy enforcement in Glic
    * CVE-2026-13897: Insufficient policy enforcement in Chromecast
    * CVE-2026-13898: Use after free in Cast Receiver
    * CVE-2026-13899: Use after free in HTML
    * CVE-2026-13900: Insufficient validation of untrusted input in Chromecast
    * CVE-2026-13901: Insufficient validation of untrusted input in Serial
    * CVE-2026-13902: Inappropriate implementation in Chrome for iOS
    * CVE-2026-13903: Insufficient policy enforcement in Bluetooth
    * CVE-2026-13904: Incorrect security UI in Safe Browsing
    * CVE-2026-13905: Incorrect security UI in Chrome for iOS
    * CVE-2026-13906: Out of bounds read in Codecs
    * CVE-2026-13907: Inappropriate implementation in iOSWeb
    * CVE-2026-13908: Insufficient validation of untrusted input in Omnibox
    * CVE-2026-13909: Insufficient policy enforcement in DevTools
    * CVE-2026-13910: Insufficient policy enforcement in WebXR
    * CVE-2026-13911: Insufficient data validation in Spellcheck
    * CVE-2026-13912: Incorrect security UI in Safe Browsing
    * CVE-2026-13913: Insufficient policy enforcement in Autofill
    * CVE-2026-13914: Inappropriate implementation in Passwords
    * CVE-2026-13915: Use after free in Chrome for iOS
    * CVE-2026-13916: Inappropriate implementation in Chrome for iOS
    * CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-13918: Use after free in Chrome for iOS
    * CVE-2026-13919: Insufficient data validation in Extensions
    * CVE-2026-14393: Use after free in V8
    * CVE-2026-13920: Insufficient validation of untrusted input in Media
    * CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials
    * CVE-2026-13922: Side-channel information leakage in Paint
    * CVE-2026-13923: Uninitialized Use in GPU
    * CVE-2026-14397: Out of bounds write in ANGLE
    * CVE-2026-13924: Insufficient validation of untrusted input in WebView
    * CVE-2026-13925: Inappropriate implementation in Downloads
    * CVE-2026-13926: Insufficient validation of untrusted input in Network
    * CVE-2026-13927: Insufficient validation of untrusted input in UI
    * CVE-2026-13928: Insufficient validation of untrusted input in Enterprise
    * CVE-2026-13929: Insufficient validation of untrusted input in DevTools
    * CVE-2026-13930: Insufficient policy enforcement in Actor
    * CVE-2026-13931: Inappropriate implementation in Media
    * CVE-2026-13932: Inappropriate implementation in Sharing
    * CVE-2026-13933: Insufficient policy enforcement in Passwords
    * CVE-2026-13934: Insufficient validation of untrusted input in Dawn
    * CVE-2026-14399: Uninitialized Use in Dawn
    * CVE-2026-13935: Side-channel information leakage in ComputePressure
    * CVE-2026-13936: Inappropriate implementation in Passwords
    * CVE-2026-13937: Insufficient policy enforcement in Passwords
    * CVE-2026-13938: Integer overflow in Fonts
    * CVE-2026-13939: Insufficient validation of untrusted input in WebShare
    * CVE-2026-13940: Uninitialized Use in Cast
    * CVE-2026-13941: Inappropriate implementation in SiteSettings
    * CVE-2026-13942: Insufficient validation of untrusted input in Video Capture
    * CVE-2026-13943: Uninitialized Use in CSS
    * CVE-2026-13944: Inappropriate implementation in DataTransfer
    * CVE-2026-13945: Insufficient policy enforcement in Extensions
    * CVE-2026-13946: Inappropriate implementation in ScriptInjections
    * CVE-2026-13947: Uninitialized Use in XR
    * CVE-2026-13948: Insufficient policy enforcement in Extensions
    * CVE-2026-13949: Insufficient policy enforcement in Payments
    * CVE-2026-14404: Inappropriate implementation in PDFium
    * CVE-2026-13950: Uninitialized Use in GPU
    * CVE-2026-13951: Policy bypass in USB
    * CVE-2026-13952: Inappropriate implementation in PerformanceAPIs
    * CVE-2026-14406: Out of bounds read in V8
    * CVE-2026-13953: Inappropriate implementation in SplitView
    * CVE-2026-13954: Insufficient policy enforcement in XML
    * CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs
    * CVE-2026-13956: Incorrect security UI in PageInfo
    * CVE-2026-13957: Incorrect security UI in Extensions
    * CVE-2026-13958: Uninitialized Use in Codecs
    * CVE-2026-14407: Inappropriate implementation in V8
    * CVE-2026-13959: Insufficient validation of untrusted input in Blink
    * CVE-2026-13960: Inappropriate implementation in Passwords
    * CVE-2026-13961: Insufficient validation of untrusted input in DevTools
    * CVE-2026-13962: Insufficient data validation in PDF
    * CVE-2026-13963: Inappropriate implementation in DevTools
    * CVE-2026-13964: Insufficient policy enforcement in WebView
    * CVE-2026-13965: Use after free in Oilpan
    * CVE-2026-13966: Inappropriate implementation in History
    * CVE-2026-13967: Type Confusion in V8
    * CVE-2026-13968: Insufficient validation of untrusted input in DevTools
    * CVE-2026-13969: Uninitialized Use in UI
    * CVE-2026-13970: Uninitialized Use in Media
    * CVE-2026-13971: Uninitialized Use in Skia
    * CVE-2026-13972: Inappropriate implementation in Paint
    * CVE-2026-13973: Inappropriate implementation in UI
    * CVE-2026-13974: Integer overflow in Safe Browsing
    * CVE-2026-13975: Out of bounds read in ANGLE
    * CVE-2026-13976: Heap buffer overflow in Storage
    * CVE-2026-13977: Inappropriate implementation in HTMLParser
    * CVE-2026-13978: Insufficient policy enforcement in PageInfo
    * CVE-2026-14414: Insufficient validation of untrusted input in Skia
    * CVE-2026-13979: Inappropriate implementation in Paint
    * CVE-2026-13980: Incorrect security UI in Chrome for iOS
    * CVE-2026-13981: Inappropriate implementation in Chrome for iOS
    * CVE-2026-13982: Incorrect security UI in Passwords
    * CVE-2026-13983: Incorrect security UI in Chrome for iOS
    * CVE-2026-13984: Incorrect security UI in TabStrip
    * CVE-2026-13985: Inappropriate implementation in MediaCapture
    * CVE-2026-13986: Inappropriate implementation in Media UI
    * CVE-2026-13987: Incorrect security UI in Mobile
    * CVE-2026-13988: Inappropriate implementation in Paint
    * CVE-2026-13989: Insufficient policy enforcement in PageInfo
    * CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer
    * CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-13992: Inappropriate implementation in UI
    * CVE-2026-13993: Incorrect security UI in WebAppInstalls
    * CVE-2026-13994: Inappropriate implementation in Credential Management
    * CVE-2026-13995: Insufficient validation of untrusted input in Autofill
    * CVE-2026-13996: Incorrect security UI in Permissions
    * CVE-2026-13997: Incorrect security UI in Extensions
    * CVE-2026-13998: Incorrect security UI in File Input
    * CVE-2026-13999: Inappropriate implementation in Extensions
    * CVE-2026-14000: Inappropriate implementation in XML
    * CVE-2026-14001: Inappropriate implementation in Network
    * CVE-2026-14002: Inappropriate implementation in Geolocation
    * CVE-2026-14003: Insufficient policy enforcement in Extensions
    * CVE-2026-14004: Inappropriate implementation in CSS
    * CVE-2026-14005: Use after free in Omnibox
    * CVE-2026-14006: Use after free in Navigation
    * CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy
    * CVE-2026-14008: Uninitialized Use in WebXR
    * CVE-2026-14009: Insufficient data validation in Passwords
    * CVE-2026-14010: Uninitialized Use in Codecs
    * CVE-2026-14011: Out of bounds read in SurfaceCapture
    * CVE-2026-14421: Uninitialized Use in Dawn
    * CVE-2026-14012: Side-channel information leakage in CSS
    * CVE-2026-14013: Inappropriate implementation in SVG
    * CVE-2026-14014: Inappropriate implementation in Paint
    * CVE-2026-14015: Inappropriate implementation in WebRTC
    * CVE-2026-14016: Insufficient policy enforcement in SVG
    * CVE-2026-14017: Inappropriate implementation in Navigation
    * CVE-2026-14018: Use after free in Updater
    * CVE-2026-14019: Inappropriate implementation in Passwords
    * CVE-2026-14020: Insufficient validation of untrusted input in WebXR
    * CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI
    * CVE-2026-14022: Insufficient validation of untrusted input in Network
    * CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI
    * CVE-2026-14024: Use after free in Ozone
    * CVE-2026-14432: Use after free in V8
    * CVE-2026-14025: Use after free in Views
    * CVE-2026-14026: Incorrect security UI in SplitView
    * CVE-2026-14027: Use after free in SignIn
    * CVE-2026-14028: Incorrect security UI in Chrome for iOS
    * CVE-2026-14030: Incorrect security UI in SplitView
    * CVE-2026-14031: Incorrect security UI in File Input
    * CVE-2026-14032: Use after free in Bluetooth
    * CVE-2026-14033: Insufficient policy enforcement in Media
    * CVE-2026-14034: Inappropriate implementation in WebXR
    * CVE-2026-14035: Insufficient policy enforcement in Bluetooth
    * CVE-2026-14036: Insufficient policy enforcement in Bluetooth
    * CVE-2026-14037: Insufficient policy enforcement in GPU
    * CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page
    * CVE-2026-14039: Insufficient policy enforcement in GetUserMedia
    * CVE-2026-14040: Use after free in BrowserTag
    * CVE-2026-14041: Insufficient policy enforcement in Serial
    * CVE-2026-14042: Inappropriate implementation in Isolated Web Apps
    * CVE-2026-14043: Use after free in GetUserMedia
    * CVE-2026-14044: Use after free in ANGLE
    * CVE-2026-14045: Insufficient validation of untrusted input in Network
    * CVE-2026-14046: Inappropriate implementation in CustomTabs
    * CVE-2026-14047: Insufficient policy enforcement in Extensions
    * CVE-2026-14048: Use after free in Chromecast
    * CVE-2026-14049: Inappropriate implementation in GPU
    * CVE-2026-14050: Insufficient policy enforcement in Passwords
    * CVE-2026-14051: Uninitialized Use in GamepadAPI
    * CVE-2026-14052: Insufficient policy enforcement in FileSystem
    * CVE-2026-14053: Insufficient policy enforcement in Extensions
    * CVE-2026-14054: Insufficient policy enforcement in Network
    * CVE-2026-14055: Insufficient validation of untrusted input in Device Trust
    * CVE-2026-14056: Insufficient validation of untrusted input in Media
    * CVE-2026-14057: Insufficient policy enforcement in FedCM
    * CVE-2026-14058: Policy bypass in Parser
    * CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets
    * CVE-2026-14060: Insufficient validation of untrusted input in Chromoting
    * CVE-2026-14061: Inappropriate implementation in Dawn
    * CVE-2026-14062: Inappropriate implementation in Views
    * CVE-2026-14063: Out of bounds memory access in Chromecast
    * CVE-2026-14064: Use after free in PageInfo
    * CVE-2026-14065: Insufficient validation of untrusted input in PageInfo
    * CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-14067: Use after free in Chrome for iOS
    * CVE-2026-14068: Inappropriate implementation in Omnibox
    * CVE-2026-14069: Integer overflow in WebNN
    * CVE-2026-14070: Uninitialized Use in WebNN
    * CVE-2026-14071: Side-channel information leakage in WebAudio
    * CVE-2026-14072: Incorrect security UI in SplitView
    * CVE-2026-14073: Insufficient policy enforcement in WebXR
    * CVE-2026-14394: Use after free in V8
    * CVE-2026-14395: Out of bounds write in V8
    * CVE-2026-14074: Side-channel information leakage in WebAuthentication
    * CVE-2026-14075: Policy bypass in Chrome for iOS
    * CVE-2026-14076: Policy bypass in Network
    * CVE-2026-14077: Incorrect security UI in Select
    * CVE-2026-14078: Policy bypass in WebRTC
    * CVE-2026-14079: Policy bypass in Network
    * CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher
    * CVE-2026-14081: Insufficient policy enforcement in DevTools
    * CVE-2026-14082: Race in Storage
    * CVE-2026-14083: Insufficient validation of untrusted input in HTML
    * CVE-2026-14084: Insufficient validation of untrusted input in Chromoting
    * CVE-2026-14085: Side-channel information leakage in CSS
    * CVE-2026-14086: Insufficient policy enforcement in HID
    * CVE-2026-14087: Insufficient validation of untrusted input in WebNN
    * CVE-2026-14088: Uninitialized Use in Canvas
    * CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker
    * CVE-2026-14090: Out of bounds read in CameraCapture
    * CVE-2026-14091: Use after free in DevTools
    * CVE-2026-14092: Insufficient policy enforcement in Privacy
    * CVE-2026-14093: Use after free in Cast
    * CVE-2026-14094: Use after free in Installer
    * CVE-2026-14095: Insufficient validation of untrusted input in Browser
    * CVE-2026-14403: Use after free in V8
    * CVE-2026-14096: Object lifecycle issue in Input
    * CVE-2026-14097: Inappropriate implementation in WebAppInstalls
    * CVE-2026-14098: Inappropriate implementation in CSS
    * CVE-2026-14405: Uninitialized Use in V8
    * CVE-2026-14099: Use after free in Chrome for iOS
    * CVE-2026-14100: Insufficient data validation in NetworkCache
    * CVE-2026-14101: Insufficient policy enforcement in Sandbox
    * CVE-2026-14102: Use after free in Passwords
    * CVE-2026-14103: Use after free in SSL
    * CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-14105: Insufficient policy enforcement in Speech
    * CVE-2026-14106: Insufficient validation of untrusted input in Text
    * CVE-2026-14107: Use after free in Scheduling
    * CVE-2026-14108: Use after free in PDFium
    * CVE-2026-14109: Insufficient policy enforcement in Mojo
    * CVE-2026-14110: Inappropriate implementation in DarkMode
    * CVE-2026-14111: Use after free in WebProtect
    * CVE-2026-14112: Inappropriate implementation in Enterprise
    * CVE-2026-14113: Use after free in Updater
    * CVE-2026-14114: Inappropriate implementation in WebAppInstalls
    * CVE-2026-14115: Insufficient validation of untrusted input in Cast
    * CVE-2026-14116: Insufficient validation of untrusted input in DevTools
    * CVE-2026-14117: Insufficient validation of untrusted input in DevTools
    * CVE-2026-14118: Insufficient data validation in DevTools
    * CVE-2026-14119: Type Confusion in Bluetooth
    * CVE-2026-14120: Inappropriate implementation in DevTools
    * CVE-2026-14121: Use after free in Chromoting
    * CVE-2026-14409: Inappropriate implementation in V8
    * CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-14410: Inappropriate implementation in Skia
    * CVE-2026-14123: Incorrect security UI in Chrome for iOS
    * CVE-2026-14124: Inappropriate implementation in CredentialProvider
    * CVE-2026-14125: Uninitialized Use in ANGLE
    * CVE-2026-14126: Incorrect security UI in UI
    * CVE-2026-14127: Inappropriate implementation in Printing
    * CVE-2026-14128: Insufficient data validation in Chrome for iOS
    * CVE-2026-14129: Incorrect security UI in PreviewTab
    * CVE-2026-14130: Incorrect security UI in Omnibox
    * CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-14132: Inappropriate implementation in WebXR
    * CVE-2026-14133: Race in History Embeddings
    * CVE-2026-14134: Inappropriate implementation in Autofill
    * CVE-2026-14135: Insufficient validation of untrusted input in Network
    * CVE-2026-14136: Incorrect security UI in Chrome for iOS
    * CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-14138: Inappropriate implementation in WebAppInstalls
    * CVE-2026-14139: Inappropriate implementation in TabStrip
    * CVE-2026-14140: Insufficient validation of untrusted input in Input
    * CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture
    * CVE-2026-14142: Inappropriate implementation in Extensions
    * CVE-2026-14143: Incorrect security UI in Passwords
    * CVE-2026-14144: Incorrect security UI in Views
    * CVE-2026-14145: Inappropriate implementation in CSS
    * CVE-2026-14146: Inappropriate implementation in CSS
    * CVE-2026-14147: Inappropriate implementation in CSS
    * CVE-2026-14415: Inappropriate implementation in V8
    * CVE-2026-14148: Type Confusion in CSS
    * CVE-2026-14149: Use after free in Audio
    * CVE-2026-14416: Out of bounds read in Dawn
    * CVE-2026-14150: Insufficient validation of untrusted input in Speech
    * CVE-2026-14151: Inappropriate implementation in AI
    * CVE-2026-14152: Out of bounds write in ANGLE
    * CVE-2026-14153: Inappropriate implementation in Glic
    * CVE-2026-14154: Inappropriate implementation in DevTools
    * CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI
    * CVE-2026-14156: Policy bypass in StorageAccessAPI
  - dropped patches:
    * ppc-fedora-fix-rust-linking.patch
* Thu Jul 02 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 150.0.7871.46 (beta released 2026-06-24)
  - modified patches:
    * chromium-102-regex_pattern-array.patch
    * chromium-125-compiler.patch
    * chromium-144-revert-libxml-2.13.patch
    * ppc-fedora-fix-breakpad-compile.patch
    * ppc-fedora-dawn-fix-ppc64le-detection.patch
    * ppc-fedora-0002-regenerate-xnn-buildgn.patch
    * chromium-146-value_or.patch
  - added patches:
    * chromium-150-toolchain.patch
    * chromium-150-sysroot.patch
    * chromium-150-ffmpeg_no_agtm.patch
    * chromium-150-icubridge_item_length.patch
  - keeplibs:
    added:
    third_party/llvm-libc
    third_party/perfetto/protos/third_party/android
    moved:
    third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/third_party/mitt
    third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/third_party/parsel-js
    third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/third_party/rxjs
    third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/third_party/urlpattern-polyfill
  - bump BR for rust-bindgen to 0.72
    (0.71 ends up with reserved keyword "gen" in boringssl)
* Fri Jun 26 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 149.0.7827.200 (boo#1269061):
    * CVE-2026-13281: Integer overflow in Mojo
    * CVE-2026-13282: Use after free in Payments
    * CVE-2026-13283: Use after free in AdFilter
* Tue Jun 23 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 149.0.7827.196:
    * stability and performance improvements
* Wed Jun 17 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Use version suffix for llvm/clang commands
  - added patches:
    * chromium-149-strip-path.patch
* Wed Jun 17 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 149.0.7827.155 (boo#1268373):
    * CVE-2026-12437: Use after free in WebShare
    * CVE-2026-12438: Inappropriate implementation in WebView
    * CVE-2026-12439: Use after free in Digital Credentials
    * CVE-2026-12440: Use after free in DigitalCredentials
    * CVE-2026-12441: Use after free in File Input
    * CVE-2026-12442: Use after free in Passwords
    * CVE-2026-12443: Use after free in Web Authentication
    * CVE-2026-12444: Out of bounds read in Chromoting
    * CVE-2026-12445: Use after free in Extensions
    * CVE-2026-12446: Insufficient data validation in Passwords
    * CVE-2026-12447: Heap buffer overflow in WebRTC
    * CVE-2026-12448: Inappropriate implementation in WebView
    * CVE-2026-12449: Use after free in Chromoting
    * CVE-2026-12450: Inappropriate implementation in Media
    * CVE-2026-12451: Use after free in DigitalCredentials
    * CVE-2026-12452: Use after free in Downloads
    * CVE-2026-12453: Insufficient validation of untrusted input in Input
    * CVE-2026-12454: Race in Safe Browsing
    * CVE-2026-12455: Use after free in Tab Strip
    * CVE-2026-12456: Insufficient validation of untrusted input in Extensions
    * CVE-2026-12457: Insufficient data validation in Extensions
    * CVE-2026-12458: Incorrect security UI in Passwords
    * CVE-2026-12459: Inappropriate implementation in Serial
    * CVE-2026-12460: Insufficient policy enforcement in File System Access
    * CVE-2026-12461: Out of bounds read in WebRTC
    * CVE-2026-12462: Use after free in Media
    * CVE-2026-12463: Inappropriate implementation in Views
    * CVE-2026-12464: Use after free in Browser
    * CVE-2026-12465: Insufficient validation of untrusted input in Metrics
    * CVE-2026-12466: Heap buffer overflow in WebRTC
    * CVE-2026-12467: Use after free in Extensions
    * CVE-2026-12468: Inappropriate implementation in Updater
    * CVE-2026-12469: Uninitialized Use in GPU
* Sat Jun 13 2026 Ruediger Oertel <ro@suse.com>
  - added patches:
    * disable-ai.patch (re-add since now ported to 149)
  - added configs:
    * disable-ai.json
    (both parts taken from fedora package)
* Fri Jun 12 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 149.0.7827.114 (boo#1268158):
    * CVE-2026-12007: Use after free  Core
    * CVE-2026-12008: Use after free  DigitalCredentials
    * CVE-2026-12009: Insufficient validation of untrusted input  Accessibility
    * CVE-2026-12010: Heap buffer overflow  GPU
    * CVE-2026-12011: Use after free  WebMIDI
    * CVE-2026-12012: Use after free  Network
    * CVE-2026-12013: Use after free  Media
    * CVE-2026-12014: Use after free  Cast
    * CVE-2026-12015: Use after free  Autofill
    * CVE-2026-12016: Insufficient validation of untrusted input  DevTools
    * CVE-2026-12017: Insufficient validation of untrusted input  Extensions
    * CVE-2026-12018: Inappropriate implementation  Mojo
    * CVE-2026-12019: Out of bounds write  Codecs
    * CVE-2026-12020: Use after free  Autofill
    * CVE-2026-12022: Race  Safe Browsing
    * CVE-2026-12023: Use after free  GPU
    * CVE-2026-12024: Insufficient policy enforcement  DevTools
    * CVE-2026-12025: Insufficient validation of untrusted input  Network
    * CVE-2026-12026: Out of bounds read  Video
    * CVE-2026-12027: Insufficient policy enforcement  Headless
    * CVE-2026-12028: Use after free  GPU
    * CVE-2026-12029: Use after free  Video
    * CVE-2026-12030: Heap buffer overflow  GPU
    * CVE-2026-12031: Inappropriate implementation  Views
    * CVE-2026-12032: Inappropriate implementation  Passwords
    * CVE-2026-12033: Out of bounds read  VideoCapture
    * CVE-2026-12034: Insufficient validation of untrusted input  Linux Toolkit Theming
    * CVE-2026-12035: Use after free  Views
* Tue Jun 09 2026 Andreas Stieger <Andreas.Stieger@gmx.de>
  - Chromium 149.0.7827.102 (boo#1267911):
    * CVE-2026-11628: Use after free in Ozone
    * CVE-2026-11629: Use after free in Ozone
    * CVE-2026-11630: Use after free in File Input
    * CVE-2026-11631: Use after free in Aura
    * CVE-2026-11632: Use after free in TabStrip
    * CVE-2026-11633: Use after free in Bluetooth
    * CVE-2026-11634: Use after free in Gamepad
    * CVE-2026-11635: Use after free in Bluetooth
    * CVE-2026-11636: Use after free in Autofill
    * CVE-2026-11637: Use after free in Views
    * CVE-2026-11638: Use after free in Printing
    * CVE-2026-11639: Use after free in Compositing
    * CVE-2026-11640: Integer overflow in libyuv
    * CVE-2026-11641: Use after free in Bluetooth
    * CVE-2026-11642: Use after free in Web Apps
    * CVE-2026-11643: Use after free in Proxy
    * CVE-2026-11644: Use after free in Views
    * CVE-2026-11645: Out of bounds memory access in V8
    * CVE-2026-11646: Use after free in ViewTransitions
    * CVE-2026-11647: Use after free in Printing
    * CVE-2026-11648: Use after free in FullScreen
    * CVE-2026-11649: Use after free in V8
    * CVE-2026-11650: Use after free in V8
    * CVE-2026-11651: Use after free in Network
    * CVE-2026-11652: Use after free in Extensions
    * CVE-2026-11653: Insufficient validation of untrusted input in Extensions
    * CVE-2026-11654: Use after free in CameraCapture
    * CVE-2026-11655: Integer overflow in Media
    * CVE-2026-11656: Use after free in ServiceWorker
    * CVE-2026-11657: Use after free in Payments
    * CVE-2026-11658: Insufficient validation of untrusted input in Extensions
    * CVE-2026-11659: Insufficient validation of untrusted input in UI
    * CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page
    * CVE-2026-11661: Use after free in Views
    * CVE-2026-11662: Type Confusion in Bindings
    * CVE-2026-11663: Use after free in Skia
    * CVE-2026-11664: Use after free in Payments
    * CVE-2026-11665: Out of bounds read in Dawn
    * CVE-2026-11666: Insufficient validation of untrusted input in Input
    * CVE-2026-11667: Out of bounds read in WebRTC
    * CVE-2026-11668: Uninitialized Use in Codecs
    * CVE-2026-11669: Integer overflow in Media
    * CVE-2026-11670: Use after free in PDF
    * CVE-2026-11671: Use after free in Navigation
    * CVE-2026-11672: Out of bounds write in GPU
    * CVE-2026-11673: Use after free in InterestGroups
    * CVE-2026-11674: Use after free in Guest View
    * CVE-2026-11675: Insufficient validation of untrusted input in Skia
    * CVE-2026-11676: Insufficient validation of untrusted input in Dawn
    * CVE-2026-11677: Race in Network
    * CVE-2026-11678: Integer overflow in libyuv
    * CVE-2026-11679: Use after free in Codecs
    * CVE-2026-11680: Use after free in Media
    * CVE-2026-11681: Use after free in Ozone
    * CVE-2026-11682: Insufficient validation of untrusted input in Views
    * CVE-2026-11683: Use after free in WebCodecs
    * CVE-2026-11684: Insufficient policy enforcement in Network
    * CVE-2026-11685: Insufficient data validation in MediaCapture
    * CVE-2026-11686: Insufficient validation of untrusted input in Dawn
    * CVE-2026-11687: Use after free in Dawn
    * CVE-2026-11688: Object lifecycle issue in SVG
    * CVE-2026-11689: Insufficient validation of untrusted input in Passwords
    * CVE-2026-11690: Out of bounds read and write in Media
    * CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page
    * CVE-2026-11692: Use after free in Read Anything
    * CVE-2026-11693: Inappropriate implementation in Plugins
    * CVE-2026-11694: Use after free in ServiceWorker
    * CVE-2026-11695: Inappropriate implementation in Passwords
    * CVE-2026-11696: Uninitialized Use in Video
    * CVE-2026-11697: Insufficient validation of untrusted input in UI
    * CVE-2026-11698: Use after free in Bluetooth
    * CVE-2026-11699: Use after free in Bluetooth
    * CVE-2026-11700: Use after free in Tracing
    * CVE-2026-11701: Insufficient validation of untrusted input in Guest View
* Mon Jun 01 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 149 (149.0.7827.53) stable (boo#1267706):
    * CVE-2026-10881: Out of bounds read and write in ANGLE
    * CVE-2026-10882: Use after free in Network
    * CVE-2026-10883: Out of bounds write in ANGLE
    * CVE-2026-10884: Use after free in Chromecast
    * CVE-2026-10885: Use after free in Chrome for iOS
    * CVE-2026-10886: Use after free in FileSystem
    * CVE-2026-10887: Use after free in Chromoting
    * CVE-2026-10888: Use after free in Cast Streaming
    * CVE-2026-10889: Out of bounds read in ANGLE
    * CVE-2026-10890: Use after free in Cast
    * CVE-2026-10891: Use after free in GFX
    * CVE-2026-10892: Out of bounds write in GPU
    * CVE-2026-10893: Use after free in Chromoting
    * CVE-2026-10894: Use after free in Printing
    * CVE-2026-10895: Use after free in Ozone
    * CVE-2026-10896: Use after free in Chrome for iOS
    * CVE-2026-10897: Out of bounds write in GPU
    * CVE-2026-10898: Stack buffer overflow in GPU
    * CVE-2026-10899: Use after free in Ozone
    * CVE-2026-10900: Use after free in Passwords
    * CVE-2026-10901: Use after free in Passwords
    * CVE-2026-10902: Use after free in Ozone
    * CVE-2026-10903: Use after free in WebRTC
    * CVE-2026-10904: Inappropriate implementation in V8
    * CVE-2026-10905: Use after free in Network
    * CVE-2026-10906: Use after free in WebAuthentication
    * CVE-2026-10907: Out of bounds write in ANGLE
    * CVE-2026-10908: Use after free in FullScreen
    * CVE-2026-10909: Use after free in Dawn
    * CVE-2026-10910: Type Confusion in V8
    * CVE-2026-10911: Insufficient validation of untrusted input in Media
    * CVE-2026-10912: Insufficient validation of untrusted input in Extensions
    * CVE-2026-10913: Use after free in ANGLE
    * CVE-2026-10914: Use after free in ANGLE
    * CVE-2026-10915: Use after free in Core
    * CVE-2026-10916: Insufficient validation of untrusted input in DevTools
    * CVE-2026-10917: Insufficient validation of untrusted input in Media
    * CVE-2026-10918: Use after free in Viz
    * CVE-2026-10919: Use after free in ANGLE
    * CVE-2026-10920: Insufficient validation of untrusted input in WebShare
    * CVE-2026-10921: Integer overflow in Dawn
    * CVE-2026-10922: Insufficient validation of untrusted input in DevTools
    * CVE-2026-10923: Use after free in WebAppInstalls
    * CVE-2026-10924: Integer overflow in Chromecast
    * CVE-2026-10925: Out of bounds write in Skia
    * CVE-2026-10926: Use after free in Cast
    * CVE-2026-10927: Out of bounds read in Dawn
    * CVE-2026-10928: Script injection in Headless
    * CVE-2026-10929: Heap buffer overflow in ANGLE
    * CVE-2026-10930: Out of bounds read in ANGLE
    * CVE-2026-10931: Use after free in FileSystem
    * CVE-2026-10932: Use after free in UI
    * CVE-2026-10933: Use after free in Audio
    * CVE-2026-10934: Use after free in Autofill
    * CVE-2026-10935: Inappropriate implementation in V8
    * CVE-2026-10936: Type Confusion in V8
    * CVE-2026-10937: Inappropriate implementation in Passwords
    * CVE-2026-10938: Insufficient validation of untrusted input in Input
    * CVE-2026-10939: Use after free in WebRTC
    * CVE-2026-10940: Race in Codecs
    * CVE-2026-10941: Out of bounds memory access in Skia
    * CVE-2026-10942: Insufficient validation of untrusted input in UI
    * CVE-2026-10943: Use after free in WebRTC
    * CVE-2026-10944: Insufficient policy enforcement in Autofill
    * CVE-2026-10945: Use after free in PDF
    * CVE-2026-10946: Heap buffer overflow in Media
    * CVE-2026-10947: Use after free in WebRTC
    * CVE-2026-10948: Use after free in WebRTC
    * CVE-2026-10949: Heap buffer overflow in Video
    * CVE-2026-10950: Insufficient policy enforcement in Autofill
    * CVE-2026-10951: Use after free in Autofill
    * CVE-2026-10952: Use after free in Chrome for iOS
    * CVE-2026-10953: Use after free in Core
    * CVE-2026-10954: Use after free in Actor
    * CVE-2026-10955: Type Confusion in ANGLE
    * CVE-2026-10956: Use after free in MimeHandlerView
    * CVE-2026-10957: Use after free in Glic
    * CVE-2026-10958: Use after free in Chrome for iOS
    * CVE-2026-10959: Use after free in Input
    * CVE-2026-10960: Uninitialized Use in Codecs
    * CVE-2026-10961: Use after free in Chrome for iOS
    * CVE-2026-10962: Type Confusion in Media
    * CVE-2026-10963: Integer overflow in V8
    * CVE-2026-10964: Integer overflow in V8
    * CVE-2026-10965: Integer overflow in DevTools
    * CVE-2026-10966: Insufficient validation of untrusted input in Codecs
    * CVE-2026-10967: Use after free in SurfaceCapture
    * CVE-2026-10968: Insufficient validation of untrusted input in Dawn
    * CVE-2026-10969: Insufficient validation of untrusted input in Extensions
    * CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups
    * CVE-2026-10971: Insufficient validation of untrusted input in Printing
    * CVE-2026-10972: Use after free in Ozone
    * CVE-2026-10973: Uninitialized Use in Dawn
    * CVE-2026-10974: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-10975: Use after free in WebRTC
    * CVE-2026-10976: Uninitialized Use in Dawn
    * CVE-2026-10977: Uninitialized Use in Skia
    * CVE-2026-10978: Use after free in Chromoting
    * CVE-2026-10979: Out of bounds read in ANGLE
    * CVE-2026-10980: Insufficient validation of untrusted input in DevTools
    * CVE-2026-10981: Insufficient validation of untrusted input in Codecs
    * CVE-2026-10982: Use after free in WebXR
    * CVE-2026-10983: Insufficient validation of untrusted input in Dawn
    * CVE-2026-10984: Inappropriate implementation in Accessibility
    * CVE-2026-10985: Out of bounds read in Skia
    * CVE-2026-10986: Integer overflow in Media
    * CVE-2026-10987: Integer overflow in V8
    * CVE-2026-10988: Use after free in Views
    * CVE-2026-10989: Inappropriate implementation in V8
    * CVE-2026-10990: Use after free in Glic
    * CVE-2026-10991: Use after free in V8
    * CVE-2026-10992: Insufficient data validation in Animation
    * CVE-2026-10993: Heap buffer overflow in Skia
    * CVE-2026-10994: Uninitialized Use in ANGLE
    * CVE-2026-10995: Heap buffer overflow in TabStrip
    * CVE-2026-10996: Inappropriate implementation in Workers
    * CVE-2026-10997: Insufficient policy enforcement in Extensions
    * CVE-2026-10998: Out of bounds read in Media
    * CVE-2026-10999: Out of bounds memory access in ANGLE
    * CVE-2026-11000: Use after free in Fonts
    * CVE-2026-11001: Incorrect security UI in Payments
    * CVE-2026-11002: Use after free in Autofill
    * CVE-2026-11003: Use after free in WebRTC
    * CVE-2026-11004: Out of bounds read in ANGLE
    * CVE-2026-11005: Out of bounds read in ANGLE
    * CVE-2026-11006: Out of bounds read in Dawn
    * CVE-2026-11007: Insufficient validation of untrusted input in WebView
    * CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-11009: Use after free in USB
    * CVE-2026-11010: Use after free in WebShare
    * CVE-2026-11011: Insufficient policy enforcement in Password Manager
    * CVE-2026-11012: Use after free in Serial
    * CVE-2026-11013: Insufficient validation of untrusted input in Network
    * CVE-2026-11014: Insufficient policy enforcement in Extensions
    * CVE-2026-11015: Out of bounds read in WebGPU
    * CVE-2026-11016: Insufficient validation of untrusted input in Network
    * CVE-2026-11017: Inappropriate implementation in Link Preview
    * CVE-2026-11018: Insufficient policy enforcement in Actor
    * CVE-2026-11019: Inappropriate implementation in Payments
    * CVE-2026-11020: Inappropriate implementation in Extensions
    * CVE-2026-11021: Insufficient validation of untrusted input in GPU
    * CVE-2026-11022: Insufficient validation of untrusted input in DevTools
    * CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-11024: Stack buffer overflow in Skia
    * CVE-2026-11025: Insufficient policy enforcement in Navigation
    * CVE-2026-11026: Insufficient policy enforcement in Extensions
    * CVE-2026-11027: Insufficient validation of untrusted input in Glic
    * CVE-2026-11028: Use after free in Media
    * CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop
    * CVE-2026-11030: Use after free in Network
    * CVE-2026-11031: Insufficient validation of untrusted input in Password Manager
    * CVE-2026-11032: Insufficient data validation in Password Manager
    * CVE-2026-11033: Uninitialized Use in WebML
    * CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync
    * CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs
    * CVE-2026-11036: Inappropriate implementation in DOM
    * CVE-2026-11037: Out of bounds write in Codecs
    * CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity
    * CVE-2026-11039: Uninitialized Use in Skia
    * CVE-2026-11040: Use after free in ANGLE
    * CVE-2026-11041: Insufficient validation of untrusted input in Media
    * CVE-2026-11042: Use after free in Views
    * CVE-2026-11043: Out of bounds write in ANGLE
    * CVE-2026-11044: Integer overflow in ANGLE
    * CVE-2026-11045: Insufficient validation of untrusted input in GPU
    * CVE-2026-11046: Insufficient validation of untrusted input in Media
    * CVE-2026-11047: Insufficient validation of untrusted input in Base
    * CVE-2026-11048: Inappropriate implementation in Extensions
    * CVE-2026-11049: Use after free in Password Manager
    * CVE-2026-11050: Use after free in V8
    * CVE-2026-11051: Out of bounds read in ANGLE
    * CVE-2026-11052: Type Confusion in GPU
    * CVE-2026-11053: VULNERABILITY in WebRTC
    * CVE-2026-11054: Use after free in WebRTC
    * CVE-2026-11055: Use after free in ANGLE
    * CVE-2026-11056: Insufficient validation of untrusted input in SiteIsolation
    * CVE-2026-11057: Uninitialized Use in Skia
    * CVE-2026-11058: Integer overflow in CredentialProvider
    * CVE-2026-11059: Use after free in Blink
    * CVE-2026-11060: Use after free in Media
    * CVE-2026-11061: Out of bounds read in ANGLE
    * CVE-2026-11062: Insufficient policy enforcement in Extensions
    * CVE-2026-11063: Insufficient validation of untrusted input in WebNN
    * CVE-2026-11064: Uninitialized Use in GPU
    * CVE-2026-11065: Use after free in ANGLE
    * CVE-2026-11066: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-11067: Uninitialized Use in Dawn
    * CVE-2026-11068: Use after free in WebSockets
    * CVE-2026-11069: Insufficient validation of untrusted input in Cast
    * CVE-2026-11070: Insufficient validation of untrusted input in Chromoting
    * CVE-2026-11071: Use after free in Base
    * CVE-2026-11072: Use after free in WebView
    * CVE-2026-11073: Use after free in WebGL
    * CVE-2026-11074: Use after free in WebRTC
    * CVE-2026-11075: Out of bounds read in V8
    * CVE-2026-11076: Type Confusion in CSS
    * CVE-2026-11077: Out of bounds read in Dawn
    * CVE-2026-11078: Insufficient validation of untrusted input in FileSystem
    * CVE-2026-11079: Insufficient validation of untrusted input in Codecs
    * CVE-2026-11080: Use after free in WebView
    * CVE-2026-11081: Policy bypass in Canvas
    * CVE-2026-11082: Use after free in GPU
    * CVE-2026-11083: Inappropriate implementation in Password Manager
    * CVE-2026-11084: Inappropriate implementation in Password Manager
    * CVE-2026-11085: Integer overflow in GPU
    * CVE-2026-11086: Insufficient validation of untrusted input in Dawn
    * CVE-2026-11087: Uninitialized Use in ANGLE
    * CVE-2026-11088: Integer overflow in ANGLE
    * CVE-2026-11089: Uninitialized Use in Media
    * CVE-2026-11090: Uninitialized Use in ANGLE
    * CVE-2026-11091: Inappropriate implementation in Dawn
    * CVE-2026-11092: Insufficient policy enforcement in DevTools
    * CVE-2026-11093: Insufficient validation of untrusted input in Printing
    * CVE-2026-11094: Use after free in Codecs
    * CVE-2026-11095: Insufficient validation of untrusted input in Codecs
    * CVE-2026-11096: Out of bounds read in WebRTC
    * CVE-2026-11097: Inappropriate implementation in WebView
    * CVE-2026-11098: Insufficient validation of untrusted input in GPU
    * CVE-2026-11099: Vulnerability in Skia
    * CVE-2026-11100: Use after free in File Input
    * CVE-2026-11101: Uninitialized Use in Dawn
    * CVE-2026-11102: Inappropriate implementation in Isolated Web Apps
    * CVE-2026-11103: Inappropriate implementation in Installer
    * CVE-2026-11104: Uninitialized Use in ANGLE
    * CVE-2026-11105: Insufficient validation of untrusted input in WebUI
    * CVE-2026-11106: Inappropriate implementation in Media
    * CVE-2026-11107: Inappropriate implementation in Downloads
    * CVE-2026-11108: Inappropriate implementation in NFC
    * CVE-2026-11109: Uninitialized Use in ANGLE
    * CVE-2026-11110: Uninitialized Use in ANGLE
    * CVE-2026-11111: Out of bounds read in ANGLE
    * CVE-2026-11112: Insufficient validation of untrusted input in Chromoting
    * CVE-2026-11113: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-11114: Use after free in Device Trust
    * CVE-2026-11115: Use after free in Updater
    * CVE-2026-11116: Use after free in Chromoting
    * CVE-2026-11117: Use after free in Views
    * CVE-2026-11118: Use after free in WebRTC
    * CVE-2026-11119: Insufficient validation of untrusted input in GPU
    * CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting
    * CVE-2026-11121: Insufficient validation of untrusted input in Skia
    * CVE-2026-11122: Inappropriate implementation in Keyboard
    * CVE-2026-11123: Uninitialized Use in ANGLE
    * CVE-2026-11124: Heap buffer overflow in Skia
    * CVE-2026-11125: Use after free in Compositing
    * CVE-2026-11126: Insufficient validation of untrusted input in DevTools
    * CVE-2026-11127: Inappropriate implementation in WebAPKs
    * CVE-2026-11128: Insufficient validation of untrusted input in Web Share
    * CVE-2026-11129: Inappropriate implementation in Extensions
    * CVE-2026-11130: Use after free in Media
    * CVE-2026-11131: Use after free in Autofill
    * CVE-2026-11132: Policy bypass in Paint
    * CVE-2026-11133: Insufficient policy enforcement in Paint
    * CVE-2026-11134: Insufficient data validation in Media
    * CVE-2026-11135: Insufficient policy enforcement in Autofill
    * CVE-2026-11136: Use after free in Canvas
    * CVE-2026-11137: Uninitialized Use in ANGLE
    * CVE-2026-11138: Uninitialized Use in ANGLE
    * CVE-2026-11139: Policy bypass in Paint
    * CVE-2026-11140: Insufficient validation of untrusted input in Chromecast
    * CVE-2026-11141: Uninitialized Use in Audio
    * CVE-2026-11142: Policy bypass in Paint
    * CVE-2026-11143: Heap buffer overflow in Extensions
    * CVE-2026-11144: Use after free in Media
    * CVE-2026-11145: Race in Geolocation
    * CVE-2026-11146: Insufficient validation of untrusted input in Chromoting
    * CVE-2026-11147: Use after free in WebML
    * CVE-2026-11148: Inappropriate implementation in Payments
    * CVE-2026-11149: Insufficient validation of untrusted input in Extensions
    * CVE-2026-11150: Inappropriate implementation in XML
    * CVE-2026-11151: Insufficient validation of untrusted input in Password Manager
    * CVE-2026-11152: Object lifecycle issue in Dawn
    * CVE-2026-11153: Side-channel information leakage in Forms
    * CVE-2026-11154: Use after free in Dawn
    * CVE-2026-11155: Insufficient policy enforcement in CSS
    * CVE-2026-11156: Inappropriate implementation in CSS
    * CVE-2026-11157: Script injection in Accessibility
    * CVE-2026-11158: Insufficient validation of untrusted input in Downloads
    * CVE-2026-11159: Uninitialized Use in Skia
    * CVE-2026-11160: Out of bounds read in Input
    * CVE-2026-11161: Insufficient data validation in DataTransfer
    * CVE-2026-11162: Insufficient policy enforcement in CSS
    * CVE-2026-11163: Use after free in Messages
    * CVE-2026-11164: Use after free in Blink
    * CVE-2026-11165: Use after free in WebMIDI
    * CVE-2026-11166: Inappropriate implementation in SVG
    * CVE-2026-11167: Inappropriate implementation in WebView
    * CVE-2026-11168: Insufficient policy enforcement in Extensions
    * CVE-2026-11169: Inappropriate implementation in XML
    * CVE-2026-11170: Inappropriate implementation in Chromoting
    * CVE-2026-11171: Integer overflow in Blink
    * CVE-2026-11172: Incorrect security UI in Contact Picker
    * CVE-2026-11173: Out of bounds write in V8
    * CVE-2026-11174: Insufficient policy enforcement in Site Isolation
    * CVE-2026-11175: Incorrect security UI in Messages
    * CVE-2026-11176: Inappropriate implementation in Media
    * CVE-2026-11177: Use after free in Omnibox
    * CVE-2026-11178: Policy bypass in WebView
    * CVE-2026-11179: Inappropriate implementation in ORB
    * CVE-2026-11180: Policy bypass in SVG
    * CVE-2026-11181: Inappropriate implementation in Media Session
    * CVE-2026-11182: Inappropriate implementation in SVG
    * CVE-2026-11183: Out of bounds read in GWP-ASan
    * CVE-2026-11184: Insufficient policy enforcement in Actor
    * CVE-2026-11185: Use after free in V8
    * CVE-2026-11186: Inappropriate implementation in CSS
    * CVE-2026-11187: Insufficient policy enforcement in Glic
    * CVE-2026-11188: Use after free in USB
    * CVE-2026-11189: Insufficient validation of untrusted input in DevTools
    * CVE-2026-11190: Insufficient policy enforcement in Extensions
    * CVE-2026-11191: Out of bounds memory access in ANGLE
    * CVE-2026-11192: Insufficient validation of untrusted input in Password Manager
    * CVE-2026-11193: Insufficient policy enforcement in Password Manager
    * CVE-2026-11194: Inappropriate implementation in Network
    * CVE-2026-11195: Inappropriate implementation in MHTML
    * CVE-2026-11196: Type Confusion in XML
    * CVE-2026-11197: Insufficient policy enforcement in Workers
    * CVE-2026-11198: Insufficient validation of untrusted input in Codecs
    * CVE-2026-11199: Insufficient validation of untrusted input in WebRTC
    * CVE-2026-11200: Inappropriate implementation in WebRTC
    * CVE-2026-11201: Use after free in ServiceWorker
    * CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-11203: Policy bypass in GPU
    * CVE-2026-11204: Inappropriate implementation in Signin
    * CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS
    * CVE-2026-11206: Policy bypass in ServiceWorker
    * CVE-2026-11207: Insufficient validation of untrusted input in Autofill
    * CVE-2026-11208: Use after free in Codecs
    * CVE-2026-11209: Insufficient policy enforcement in Passwords
    * CVE-2026-11210: Insufficient policy enforcement in Safe Browsing
    * CVE-2026-11211: Integer overflow in V8
    * CVE-2026-11212: Insufficient policy enforcement in DevTools
    * CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode
    * CVE-2026-11214: Inappropriate implementation in Chrome for iOS
    * CVE-2026-11215: Inappropriate implementation in Cronet
    * CVE-2026-11216: Incorrect security UI in File Input
    * CVE-2026-11217: Insufficient policy enforcement in Fenced Frames
    * CVE-2026-11218: Inappropriate implementation in PlatformIntegration
    * CVE-2026-11219: Insufficient data validation in Navigation
    * CVE-2026-11220: Insufficient validation of untrusted input in Navigation
    * CVE-2026-11221: Insufficient validation of untrusted input in PointerLock
    * CVE-2026-11222: Incorrect security UI in Tab Strip
    * CVE-2026-11223: Insufficient validation of untrusted input in Network
    * CVE-2026-11224: Use after free in Chromoting
    * CVE-2026-11225: Incorrect security UI in WebUI
    * CVE-2026-11226: Insufficient policy enforcement in PreviewTab
    * CVE-2026-11227: Incorrect security UI in Tab Hover Cards
    * CVE-2026-11228: Incorrect security UI in File Input
    * CVE-2026-11229: Insufficient policy enforcement in Enterprise
    * CVE-2026-11230: Use after free in Extensions
    * CVE-2026-11231: Inappropriate implementation in Safe Browsing
    * CVE-2026-11232: Inappropriate implementation in TabGroups
    * CVE-2026-11233: Insufficient validation of untrusted input in FoldableAPIs
    * CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs
    * CVE-2026-11235: Insufficient validation of untrusted input in Compositing
    * CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth
    * CVE-2026-11237: Insufficient validation of untrusted input in Media
    * CVE-2026-11238: Inappropriate implementation in DevTools
    * CVE-2026-11239: Insufficient validation of untrusted input in Extensions
    * CVE-2026-11240: Insufficient validation of untrusted input in Loader
    * CVE-2026-11241: Insufficient validation of untrusted input in Cast
    * CVE-2026-11242: Insufficient validation of untrusted input in Plugins
    * CVE-2026-11243: Incorrect security UI in Downloads
    * CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication
    * CVE-2026-11245: Inappropriate implementation in Payments
    * CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB
    * CVE-2026-11247: Insufficient policy enforcement in CustomTabs
    * CVE-2026-11248: Policy bypass in Google Lens
    * CVE-2026-11249: Use after free in Network
    * CVE-2026-11250: Inappropriate implementation in DevTools
    * CVE-2026-11251: Insufficient validation of untrusted input in Password Manager
    * CVE-2026-11252: Policy bypass in Content Settings
    * CVE-2026-11253: Race in Permissions
    * CVE-2026-11254: Inappropriate implementation in Permissions
    * CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API
    * CVE-2026-11256: Out of bounds read in GPU
    * CVE-2026-11257: Inappropriate implementation in Browser
    * CVE-2026-11258: Inappropriate implementation in File System Access
    * CVE-2026-11259: Insufficient validation of untrusted input in Cast
    * CVE-2026-11260: Policy bypass in Permissions
    * CVE-2026-11261: Insufficient validation of untrusted input in PDF
    * CVE-2026-11262: Use after free in TabStrip
    * CVE-2026-11263: Insufficient policy enforcement in WebAuthentication
    * CVE-2026-11264: Policy bypass in Content Security Policy
    * CVE-2026-11265: Insufficient data validation in Autofill
    * CVE-2026-11266: Policy bypass in SafeBrowsing
    * CVE-2026-11267: Insufficient policy enforcement in Extensions
    * CVE-2026-11268: Uninitialized Use in ANGLE
    * CVE-2026-11269: Inappropriate implementation in Extensions
    * CVE-2026-11270: Inappropriate implementation in UI
    * CVE-2026-11271: Incorrect security UI in Passwords
    * CVE-2026-11272: Insufficient validation of untrusted input in Reading List
    * CVE-2026-11273: Insufficient validation of untrusted input in Omnibox
    * CVE-2026-11274: Inappropriate implementation in DOM Distiller
    * CVE-2026-11275: Insufficient policy enforcement in Page Info
    * CVE-2026-11276: Inappropriate implementation in Cast
    * CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS
    * CVE-2026-11278: Inappropriate implementation in CustomTabs
    * CVE-2026-11279: Out of bounds read in DevTools
    * CVE-2026-11280: Insufficient validation of untrusted input in Signin
    * CVE-2026-11281: Integer overflow in Chromoting
    * CVE-2026-11282: Policy bypass in Sandbox
    * CVE-2026-11283: Policy bypass in Shortcuts
    * CVE-2026-11284: Side-channel information leakage in PerformanceAPIs
    * CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS
    * CVE-2026-11286: Insufficient validation of untrusted input in Wallet
    * CVE-2026-11287: Insufficient validation of untrusted input in Navigation
    * CVE-2026-11288: Policy bypass in CSS
    * CVE-2026-11289: Side-channel information leakage in Paint
    * CVE-2026-11290: Integer overflow in WebView
    * CVE-2026-11291: Policy bypass in Android Autofill
    * CVE-2026-11292: Policy bypass in Blink
    * CVE-2026-11293: Use after free in Input
    * CVE-2026-11294: Inappropriate implementation in Passwords
    * CVE-2026-11295: Inappropriate implementation in WebView
    * CVE-2026-11296: Inappropriate implementation in ImageCapture
    * CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode
    * CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS
    * CVE-2026-11299: Out of bounds read in Fonts
    * CVE-2026-11300: Inappropriate implementation in Permissions
    * CVE-2026-11301: Out of bounds read in LiveCaption
    * CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS
    * CVE-2026-11303: Use after free in PDFium
    * CVE-2026-11304: Use after free in PDFium
    * CVE-2026-11305: Use after free in PDFium
    * CVE-2026-11306: Use after free in PDFium
    * CVE-2026-11307: Use after free in PDFium
    * CVE-2026-11308: Inappropriate implementation in Extensions
    * CVE-2026-11309: Insufficient policy enforcement in History
* Fri May 29 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 149.0.7827.53
  - added patches:
    * chromium-149-profile_no_const.patch
      try to complete deconstifying the use of Profile*
      started in upstream 2ac4e0f090a26f86e9ffa4bc6c22743911b9be35
    * ppc-fedora-0003-third_party-libvpx-Add-ppc64-vsx-files.patch
    * ppc-libvpx-add-missing-prototype.patch
  - removed patches:
    * chromium-141-glibc-2.42-SYS_SECCOMP.patch
    * fix_building_widevinecdm_with_chromium.patch
    * disable-ai.patch: known rebase conflicts on 149
  - modified patches:
    * chromium-125-compiler.patch (context)
    * chromium-143-revert_rust_is_multiple_of.patch (drop one hunk)
    * chromium-146-value_or.patch (drop one hunk, add one hunk)
    * ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch
      (regenerated)
    * ppc-fedora-0002-regenerate-xnn-buildgn.patch (regenerated)
    * chromium-146-ignore-for-ubsan.patch (redone)
    * chromium-148-no_dep_on_intree_rustc_binary.patch
    * ppc-fedora-0001-Implement-support-for-ppc64-on-Linux.patch
    * ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch
    * ppc-fedora-0001-Add-pregenerated-config-for-libaom-on-ppc64.patch
      (regenerated, disable code to regenerate at build for now)
  - changed patch ranges, global patches up to 449,
    ppc patches from 450-599 now
  - keeplibs:
    added: third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/esm/third_party/urlpattern-polyfill
  - bump BR for gn to 0.20260429 for expand_directory
  - fixes reading mode (boo#1265854)
* Wed May 27 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 148.0.7778.215 (boo#1266471):
    * CVE-2026-9872: Out of bounds write in GPU
    * CVE-2026-9873: Use after free in Network
    * CVE-2026-9874: Use after free in Dawn
    * CVE-2026-9875: Out of bounds read in WebGL
    * CVE-2026-9876: Use after free in WebGL
    * CVE-2026-9877: Use after free in ANGLE
    * CVE-2026-9878: Use after free in ANGLE
    * CVE-2026-9879: Out of bounds write in ANGLE
    * CVE-2026-9880: Insufficient validation of untrusted input in WebGL
    * CVE-2026-9881: Use after free in Bluetooth
    * CVE-2026-9882: Integer overflow in ANGLE
    * CVE-2026-9883: Use after free in Base
    * CVE-2026-9884: Use after free in Browser
    * CVE-2026-9885: Insufficient validation of untrusted input in UI
    * CVE-2026-9886: Use after free in Base
    * CVE-2026-9887: Use after free in Proxy
    * CVE-2026-9888: Use after free in WebView
    * CVE-2026-9889: Out of bounds read and write in Dawn
    * CVE-2026-9890: Use after free in XR
    * CVE-2026-9891: Use after free in Extensions
    * CVE-2026-9892: Inappropriate implementation in Skia
    * CVE-2026-9893: Use after free in Skia
    * CVE-2026-9894: Use after free in GPU
    * CVE-2026-9895: Out of bounds read in GPU
    * CVE-2026-9896: Out of bounds write in V8
    * CVE-2026-9897: Use after free in DOM
    * CVE-2026-9898: Insufficient validation of untrusted input in GPU
    * CVE-2026-9899: Use after free in ANGLE
    * CVE-2026-9900: Out of bounds write in ANGLE
    * CVE-2026-9901: Use after free in ANGLE
    * CVE-2026-9902: Use after free in Accessibility
    * CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation
    * CVE-2026-9904: Use after free in ANGLE
    * CVE-2026-9905: Use after free in Accessibility
    * CVE-2026-9906: Out of bounds write in GPU
    * CVE-2026-9907: Out of bounds read in Dawn
    * CVE-2026-9908: Out of bounds read in ANGLE
    * CVE-2026-9909: Integer overflow in Skia
    * CVE-2026-9910: Out of bounds memory access in ANGLE
    * CVE-2026-9911: Integer overflow in ANGLE
    * CVE-2026-9912: Inappropriate implementation in GPU
    * CVE-2026-9913: Inappropriate implementation in ANGLE
    * CVE-2026-9914: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-9915: Heap buffer overflow in ANGLE
    * CVE-2026-9916: Out of bounds write in ANGLE
    * CVE-2026-9917: Uninitialized Use in WebGL
    * CVE-2026-9918: Inappropriate implementation in Tint
    * CVE-2026-9919: Out of bounds read in WebGL
    * CVE-2026-9920: Uninitialized Use in GPU
    * CVE-2026-9921: Uninitialized Use in WebGL
    * CVE-2026-9922: Use after free in GPU
    * CVE-2026-9923: Use after free in Skia
    * CVE-2026-9924: Heap buffer overflow in ANGLE
    * CVE-2026-9925: Use after free in ANGLE
    * CVE-2026-9926: Heap buffer overflow in ANGLE
    * CVE-2026-9927: Use after free in ANGLE
    * CVE-2026-9928: Out of bounds read in ANGLE
    * CVE-2026-9929: Inappropriate implementation in WebGL
    * CVE-2026-9930: Out of bounds write in Dawn
    * CVE-2026-9931: Use after free in GPU
    * CVE-2026-9932: Use after free in ANGLE
    * CVE-2026-9933: Use after free in Input
    * CVE-2026-9934: Use after free in Aura
    * CVE-2026-9935: Uninitialized Use in ANGLE
    * CVE-2026-9936: Use after free in GFX
    * CVE-2026-9937: Use after free in UI
    * CVE-2026-9938: Inappropriate implementation in V8
    * CVE-2026-9939: Heap buffer overflow in WebCodecs
    * CVE-2026-9940: Heap buffer overflow in ANGLE
    * CVE-2026-9941: Use after free in ANGLE
    * CVE-2026-9942: Uninitialized Use in ANGLE
    * CVE-2026-9943: Out of bounds read in WebGL
    * CVE-2026-9944: Uninitialized Use in ANGLE
    * CVE-2026-9945: Use after free in Media
    * CVE-2026-9946: Use after free in ANGLE
    * CVE-2026-9947: Use after free in XML
    * CVE-2026-9948: Use after free in Views
    * CVE-2026-9949: Use after free in Core
    * CVE-2026-9950: Insufficient validation of untrusted input in iOS
    * CVE-2026-9951: Use after free in UI
    * CVE-2026-9952: Use after free in WebAudio
    * CVE-2026-9953: Out of bounds read in ANGLE
    * CVE-2026-9954: Use after free in TabStrip
    * CVE-2026-9955: Inappropriate implementation in iOS
    * CVE-2026-9956: Use after free in iOS
    * CVE-2026-9957: Use after free in PDF
    * CVE-2026-9958: Use after free in PDFium
    * CVE-2026-9959: Race in WebRTC
    * CVE-2026-9960: Integer overflow in PDFium
    * CVE-2026-9961: Use after free in SurfaceCapture
    * CVE-2026-9962: Use after free in WebRTC
    * CVE-2026-9963: Uninitialized Use in iOS
    * CVE-2026-9964: Use after free in Bluetooth
    * CVE-2026-9965: Out of bounds write in ANGLE
    * CVE-2026-9966: Integer overflow in XML
    * CVE-2026-9967: Out of bounds write in GPU
    * CVE-2026-9968: Integer overflow in V8
    * CVE-2026-9969: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-9970: Use after free in WebGL
    * CVE-2026-9971: Inappropriate implementation in iOS
    * CVE-2026-9972: Uninitialized Use in Gamepad
    * CVE-2026-9973: Out of bounds write in V8
    * CVE-2026-9974: Out of bounds write in GPU
    * CVE-2026-9975: Out of bounds read and write in ANGLE
    * CVE-2026-9976: Inappropriate implementation in USB
    * CVE-2026-9977: Insufficient validation of untrusted input in WebShare
    * CVE-2026-9978: Use after free in Glic
    * CVE-2026-9979: Insufficient validation of untrusted input in Input
    * CVE-2026-9980: Insufficient validation of untrusted input in Printing
    * CVE-2026-9981: Inappropriate implementation in Skia
    * CVE-2026-9982: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-9983: Type Confusion in Skia
    * CVE-2026-9984: Use after free in UI
    * CVE-2026-9985: Insufficient validation of untrusted input in Media
    * CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide
    * CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls
    * CVE-2026-9988: Use after free in WebRTC
    * CVE-2026-9989: Inappropriate implementation in Media
    * CVE-2026-9990: Use after free in WebAppInstalls
    * CVE-2026-9991: Inappropriate implementation in Media
    * CVE-2026-9992: Use after free in Network
    * CVE-2026-9993: Use after free in Views
    * CVE-2026-9994: Use after free in Core
    * CVE-2026-9995: Use after free in WebXR
    * CVE-2026-9996: Out of bounds read in WebRTC
    * CVE-2026-9997: Use after free in Input
    * CVE-2026-9998: Integer overflow in Skia
    * CVE-2026-9999: Inappropriate implementation in ANGLE
    * CVE-2026-10000: Use after free in Passwords
    * CVE-2026-10001: Use after free in PerformanceManager
    * CVE-2026-10002: Use after free in PDFium
    * CVE-2026-10003: Use after free in Views
    * CVE-2026-10004: Insufficient validation of untrusted input in Passwords
    * CVE-2026-10005: Use after free in WebAppInstalls
    * CVE-2026-10006: Race in WebAudio
    * CVE-2026-10007: Use after free in SVG
    * CVE-2026-10008: Uninitialized Use in GPU
    * CVE-2026-10009: Integer overflow in Skia
    * CVE-2026-10010: Inappropriate implementation in Input
    * CVE-2026-10011: Inappropriate implementation in Skia
    * CVE-2026-10012: Use after free in Skia
    * CVE-2026-10013: Use after free in WebCodecs
    * CVE-2026-10014: Use after free in WebMIDI
    * CVE-2026-10015: Integer overflow in WTF
    * CVE-2026-10016: Use after free in DOM
    * CVE-2026-10017: Out of bounds read in Headless
    * CVE-2026-10018: Integer overflow in ANGLE
    * CVE-2026-10019: Integer overflow in ANGLE
    * CVE-2026-10020: Insufficient validation of untrusted input in Skia
    * CVE-2026-10021: Insufficient validation of untrusted input in USB
    * CVE-2026-10022: Type Confusion in V8
* Tue May 19 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 148.0.7778.178 (boo#1265848)
    * CVE-2026-9111: Use after free in WebRTC
    * CVE-2026-9110: Inappropriate implementation in UI
    * CVE-2026-9112: Use after free in GPU
    * CVE-2026-9113: Out of bounds read in GPU
    * CVE-2026-9114: Use after free in QUIC
    * CVE-2026-9115: Insufficient policy enforcement in Service Worker
    * CVE-2026-9116: Insufficient policy enforcement in ServiceWorker
    * CVE-2026-9117: Type Confusion in GFX
    * CVE-2026-9118: Use after free in XR
    * CVE-2026-9119: Heap buffer overflow in WebRTC
    * CVE-2026-9120: Use after free in WebRTC
    * CVE-2026-9126: Use after free in DOM
    * CVE-2026-9121: Out of bounds read in GPU
    * CVE-2026-9122: Out of bounds read in GPU
    * CVE-2026-9123: Heap buffer overflow in Chromecast
    * CVE-2026-9124: Insufficient validation of untrusted input in Input
* Mon May 18 2026 Ruediger Oertel <ro@suse.com>
  - add system-wide chromium.conf as in fedora package
    enable several features by default and disable ai features
    allow to override via setting CHROMIUM_USER_FLAGS
* Tue May 12 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 148.0.7778.167 (boo#1265159)
    * CVE-2026-8509: Heap buffer overflow in WebML
    * CVE-2026-8510: Integer overflow in Skia
    * CVE-2026-8511: Use after free in UI
    * CVE-2026-8512: Use after free in FileSystem
    * CVE-2026-8513: Use after free in Input
    * CVE-2026-8514: Use after free in Aura
    * CVE-2026-8515: Use after free in HID
    * CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer
    * CVE-2026-8517: Object lifecycle issue in WebShare
    * CVE-2026-8518: Use after free in Blink
    * CVE-2026-8519: Integer overflow in ANGLE
    * CVE-2026-8520: Race in Payments
    * CVE-2026-8521: Use after free in Tab Groups
    * CVE-2026-8522: Use after free in Downloads
    * CVE-2026-8523: Use after free in Mojo
    * CVE-2026-8558: Out of bounds write in Fonts
    * CVE-2026-8524: Out of bounds write in WebAudio
    * CVE-2026-8525: Heap buffer overflow in ANGLE
    * CVE-2026-8526: Out of bounds write in WebRTC
    * CVE-2026-8527: Insufficient validation of untrusted input in Downloads
    * CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation
    * CVE-2026-8529: Heap buffer overflow in Codecs
    * CVE-2026-8530: Use after free in Network
    * CVE-2026-8531: Heap buffer overflow in WebML
    * CVE-2026-8532: Integer overflow in XML
    * CVE-2026-8533: Use after free in Accessibility
    * CVE-2026-8534: Integer overflow in GPU
    * CVE-2026-8535: Out of bounds read in Media
    * CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode
    * CVE-2026-8537: Insufficient policy enforcement in ViewTransitions
    * CVE-2026-8538: Insufficient validation of untrusted input in GPU
    * CVE-2026-8539: Script injection in SanitizerAPI
    * CVE-2026-8540: Type Confusion in V8
    * CVE-2026-8541: Out of bounds read in UI
    * CVE-2026-8542: Use after free in Core
    * CVE-2026-8543: Out of bounds read in FileSystem
    * CVE-2026-8544: Use after free in Media
    * CVE-2026-8545: Object corruption in Compositing
    * CVE-2026-8546: Out of bounds read in GPU
    * CVE-2026-8547: Insufficient policy enforcement in Passwords
    * CVE-2026-8548: Out of bounds write in Media
    * CVE-2026-8549: Use after free in Media
    * CVE-2026-8550: Use after free in Google Lens
    * CVE-2026-8551: Use after free in Downloads
    * CVE-2026-8552: Heap buffer overflow in GPU
    * CVE-2026-8553: Use after free in GPU
    * CVE-2026-8554: Type Confusion in ANGLE
    * CVE-2026-8555: Use after free in GTK
    * CVE-2026-8556: Inappropriate implementation in ANGLE
    * CVE-2026-8557: Use after free in Accessibility
    * CVE-2026-8559: Integer overflow in Internationalization
    * CVE-2026-8560: Heap buffer overflow in SwiftShader
    * CVE-2026-8561: Incorrect security UI in Fullscreen
    * CVE-2026-8562: Side-channel information leakage in Navigation
    * CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox
    * CVE-2026-8564: Incorrect security UI in Downloads
    * CVE-2026-8565: Inappropriate implementation in Downloads
    * CVE-2026-8566: Insufficient policy enforcement in Payments
    * CVE-2026-8567: Integer overflow in ANGLE
    * CVE-2026-8568: Insufficient policy enforcement in AI
    * CVE-2026-8569: Out of bounds write in Codecs
    * CVE-2026-8570: Type Confusion in V8
    * CVE-2026-8571: Insufficient policy enforcement in GPU
    * CVE-2026-8572: Insufficient policy enforcement in Network
    * CVE-2026-8573: Integer overflow in Codecs
    * CVE-2026-8574: Use after free in Core
    * CVE-2026-8575: Use after free in UI
    * CVE-2026-8576: Inappropriate implementation in CORS
    * CVE-2026-8577: Integer overflow in Fonts
    * CVE-2026-8578: Out of bounds read in GPU
    * CVE-2026-8579: Insufficient validation of untrusted input in Skia
    * CVE-2026-8580: Use after free in Mojo
    * CVE-2026-8581: Use after free in GPU
    * CVE-2026-8582: Object lifecycle issue in Dawn
    * CVE-2026-8583: Insufficient policy enforcement in WebXR
    * CVE-2026-8584: Inappropriate implementation in Views
    * CVE-2026-8585: Inappropriate implementation in Media
    * CVE-2026-8586: Inappropriate implementation in Chromoting
    * CVE-2026-8587: Use after free in Extensions
* Mon May 11 2026 Ruediger Oertel <ro@suse.com>
  - added patches:
    * disable-ai.patch
      (do not attempt to download AI code behind the users back)
  - changed patch ranges, global patches up to 449,
    ppc patches from 450-599 now
* Wed May 06 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175)
    * CVE-2026-7896: Integer overflow in Blink
    * CVE-2026-7897: Use after free in Mobile
    * CVE-2026-7898: Use after free in Chromoting
    * CVE-2026-7899: Out of bounds read and write in V8
    * CVE-2026-7900: Heap buffer overflow in ANGLE
    * CVE-2026-7901: Use after free in ANGLE
    * CVE-2026-7902: Out of bounds memory access in V8
    * CVE-2026-7903: Integer overflow in ANGLE
    * CVE-2026-7904: Out of bounds read in Fonts
    * CVE-2026-7905: Insufficient validation of untrusted input in Media
    * CVE-2026-7906: Use after free in SVG
    * CVE-2026-7907: Use after free in DOM
    * CVE-2026-7908: Use after free in Fullscreen
    * CVE-2026-7909: Inappropriate implementation in ServiceWorker
    * CVE-2026-7910: Use after free in Views
    * CVE-2026-7911: Use after free in Aura
    * CVE-2026-7912: Integer overflow in GPU
    * CVE-2026-7913: Insufficient policy enforcement in DevTools
    * CVE-2026-7914: Type Confusion in Accessibility
    * CVE-2026-7915: Insufficient data validation in DevTools
    * CVE-2026-7916: Insufficient data validation in InterestGroups
    * CVE-2026-7917: Use after free in Fullscreen
    * CVE-2026-7918: Use after free in GPU
    * CVE-2026-7919: Use after free in Aura
    * CVE-2026-7920: Use after free in Skia
    * CVE-2026-7921: Use after free in Passwords
    * CVE-2026-7922: Use after free in ServiceWorker
    * CVE-2026-7923: Out of bounds write in Skia
    * CVE-2026-7924: Uninitialized Use in Dawn
    * CVE-2026-7925: Use after free in Chromoting
    * CVE-2026-7926: Use after free in PresentationAPI
    * CVE-2026-7927: Type Confusion in Runtime
    * CVE-2026-7928: Use after free in WebRTC
    * CVE-2026-7929: Use after free in MediaRecording
    * CVE-2026-7930: Insufficient validation of untrusted input in Cookies
    * CVE-2026-7931: Insufficient validation of untrusted input in iOS
    * CVE-2026-7932: Insufficient policy enforcement in Downloads
    * CVE-2026-7933: Out of bounds read in WebCodecs
    * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker
    * CVE-2026-7935: Inappropriate implementation in Speech
    * CVE-2026-7936: Object lifecycle issue in V8
    * CVE-2026-7937: Insufficient policy enforcement in DevTools
    * CVE-2026-7938: Use after free in CSS
    * CVE-2026-7939: Inappropriate implementation in SanitizerAPI
    * CVE-2026-7940: Use after free in V8
    * CVE-2026-7941: Insufficient validation of untrusted input in Mobile
    * CVE-2026-7942: Integer overflow in ANGLE
    * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache
    * CVE-2026-7945: Insufficient validation of untrusted input in COOP
    * CVE-2026-7946: Insufficient policy enforcement in WebUI
    * CVE-2026-7947: Insufficient validation of untrusted input in Network
    * CVE-2026-7948: Race in Chromoting
    * CVE-2026-7949: Out of bounds read in Skia
    * CVE-2026-7950: Out of bounds read and write in GFX
    * CVE-2026-7951: Out of bounds write in WebRTC
    * CVE-2026-7952: Insufficient policy enforcement in Extensions
    * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox
    * CVE-2026-7954: Race in Shared Storage
    * CVE-2026-7955: Uninitialized Use in GPU
    * CVE-2026-7956: Use after free in Navigation
    * CVE-2026-7957: Out of bounds write in Media
    * CVE-2026-7958: Inappropriate implementation in ServiceWorker
    * CVE-2026-7959: Inappropriate implementation in Navigation
    * CVE-2026-7960: Race in Speech
    * CVE-2026-7961: Insufficient validation of untrusted input in Permissions
    * CVE-2026-7962: Insufficient policy enforcement in DirectSockets
    * CVE-2026-7963: Inappropriate implementation in ServiceWorker
    * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem
    * CVE-2026-7965: Insufficient validation of untrusted input in DevTools
    * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation
    * CVE-2026-7967: Insufficient validation of untrusted input in Navigation
    * CVE-2026-7968: Insufficient validation of untrusted input in CORS
    * CVE-2026-7969: Integer overflow in Network
    * CVE-2026-7970: Use after free in TopChrome
    * CVE-2026-7971: Inappropriate implementation in ORB
    * CVE-2026-7972: Uninitialized Use in GPU
    * CVE-2026-7973: Integer overflow in Dawn
    * CVE-2026-7974: Use after free in Blink
    * CVE-2026-7975: Use after free in DevTools
    * CVE-2026-7976: Use after free in Views
    * CVE-2026-7977: Inappropriate implementation in Canvas
    * CVE-2026-7978: Inappropriate implementation in Companion
    * CVE-2026-7979: Inappropriate implementation in Media
    * CVE-2026-7980: Use after free in WebAudio
    * CVE-2026-7981: Out of bounds read in Codecs
    * CVE-2026-7982: Uninitialized Use in WebCodecs
    * CVE-2026-7983: Out of bounds read in Dawn
    * CVE-2026-7984: Use after free in ReadingMode
    * CVE-2026-7985: Use after free in GPU
    * CVE-2026-7986: Insufficient policy enforcement in Autofill
    * CVE-2026-7987: Use after free in WebRTC
    * CVE-2026-7988: Type Confusion in WebRTC
    * CVE-2026-7989: Insufficient data validation in DataTransfer
    * CVE-2026-7990: Insufficient validation of untrusted input in Updater
    * CVE-2026-7991: Use after free in UI
    * CVE-2026-7992: Insufficient validation of untrusted input in UI
    * CVE-2026-7993: Insufficient validation of untrusted input in Payments
    * CVE-2026-7994: Inappropriate implementation in Chromoting
    * CVE-2026-7995: Out of bounds read in AdFilter
    * CVE-2026-7996: Insufficient validation of untrusted input in SSL
    * CVE-2026-7997: Insufficient validation of untrusted input in Updater
    * CVE-2026-7998: Insufficient validation of untrusted input in Dialog
    * CVE-2026-7999: Inappropriate implementation in V8
    * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver
    * CVE-2026-8001: Use after free in Printing
    * CVE-2026-8002: Use after free in Audio
    * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups
    * CVE-2026-8004: Insufficient policy enforcement in DevTools
    * CVE-2026-8005: Insufficient validation of untrusted input in Cast
    * CVE-2026-8006: Insufficient policy enforcement in DevTools
    * CVE-2026-8007: Insufficient validation of untrusted input in Cast
    * CVE-2026-8008: Inappropriate implementation in DevTools
    * CVE-2026-8009: Inappropriate implementation in Cast
    * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation
    * CVE-2026-8011: Insufficient policy enforcement in Search
    * CVE-2026-8012: Inappropriate implementation in MHTML
    * CVE-2026-8013: Insufficient validation of untrusted input in FedCM
    * CVE-2026-8014: Inappropriate implementation in Preload
    * CVE-2026-8015: Inappropriate implementation in Media
    * CVE-2026-8016: Use after free in WebRTC
    * CVE-2026-8017: Side-channel information leakage in Media
    * CVE-2026-8018: Insufficient policy enforcement in DevTools
    * CVE-2026-8019: Insufficient policy enforcement in WebApp
    * CVE-2026-8020: Uninitialized Use in GPU
    * CVE-2026-8021: Script injection in UI
    * CVE-2026-8022: Inappropriate implementation in MHTML
  - Fix build failure in seccomp_bpf sandbox
    previously chromium-fix-sandbox-with-glibc-2.43.patch
    add chromium-148-sandbox-glibc-2.43.patch
  - bump version in buildrequires for gn (0.20260331)
    (needs variable inputs added in March 2026)
  - added patches:
    * chromium-148-revert_std_ranges_iota.patch
      (revert for llvm < 20,
      error: no member named 'iota' in namespace 'std::ranges')
    * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch
      (from upstream, add missing implementation for ppc)
    * chromium-148-no_dep_on_intree_rustc_binary.patch
      (do not depend on intree binary of rustc)
  - added patches:
    * chromium-148-only_address_sanitizer.patch
    (prevent undefined symbol __sanitizer_set_death_callback)
    * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch
    (revert upstream change)
    * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch
      (obsolete, upstream)
  - removed patches:
    * chromium-147-ffmpeg_includes.patch (upstream)
    * chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch (upstream)
  - modified patches:
    * ppc-fedora-fix-different-data-layouts.patch
    * ppc-fedora-skia-vsx-instructions.patch
    * ppc-fedora-0002-regenerate-xnn-buildgn.patch
    * chromium-146-ignore-for-ubsan.patch
    * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch
      adjust context for changes made in 7120cf7
    * chromium-146-value_or.patch (one more place in v8)
    * chromium-147-blink_renderer_need_ffmpeg.patch (new hunk added)
  - keeplibs:
    added: third_party/gperf
    (needed by blink/renderer/core/css/parser/at_rule_descriptors.cc)
    change: third_party/harfbuzz-ng to third_party/harfbuzz
    drop: third_party/libaom/source/libaom/third_party/SVT-AV1
  - force link to system gperf binary instead of hardcoded x86
    in tree copy
* Tue Apr 28 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 147.0.7727.137 (boo#1263158)
    * CVE-2026-7363: Use after free in Canvas
    * CVE-2026-7361: Use after free in iOS
    * CVE-2026-7344: Use after free in Accessibility
    * CVE-2026-7343: Use after free in Views
    * CVE-2026-7333: Use after free in GPU
    * CVE-2026-7360: Insufficient validation of untrusted input in Compositing
    * CVE-2026-7359: Use after free in ANGLE
    * CVE-2026-7358: Use after free in Animation
    * CVE-2026-7334: Use after free in Views
    * CVE-2026-7357: Use after free in GPU
    * CVE-2026-7356: Use after free in Navigation
    * CVE-2026-7354: Out of bounds read and write in Angle
    * CVE-2026-7353: Heap buffer overflow in Skia
    * CVE-2026-7352: Use after free in Media
    * CVE-2026-7351: Race in MHTML
    * CVE-2026-7350: Use after free in WebMIDI
    * CVE-2026-7349: Use after free in Cast
    * CVE-2026-7348: Use after free in Codecs
    * CVE-2026-7335: Use after free in media
    * CVE-2026-7336: Use after free in WebRTC
    * CVE-2026-7337: Type Confusion in V8
    * CVE-2026-7347: Use after free in Chromoting
    * CVE-2026-7346: Inappropriate implementation in Tint
    * CVE-2026-7345: Insufficient validation of untrusted input in Feedback
    * CVE-2026-7338: Use after free in Cast
    * CVE-2026-7342: Use after free in WebView
    * CVE-2026-7341: Use after free in WebRTC
    * CVE-2026-7339: Heap buffer overflow in WebRTC
    * CVE-2026-7340: Integer overflow in ANGLE
    * CVE-2026-7355: Use after free in Media
* Wed Apr 22 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 147.0.7727.116 (boo#1262586)
    * CVE-2026-6919: Use after free in DevTools
    * CVE-2026-6920: Out of bounds read in GPU
    * CVE-2026-6921: Race in GPU
    * Various fixes from internal audits, fuzzing and other
      initiatives
* Wed Apr 15 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 147.0.7727.101 (boo#1262174)
    * CVE-2026-6296: Heap buffer overflow in ANGLE
    * CVE-2026-6297: Use after free in Proxy
    * CVE-2026-6298: Heap buffer overflow in Skia
    * CVE-2026-6299: Use after free in Prerender
    * CVE-2026-6358: Use after free in XR
    * CVE-2026-6359: Use after free in Video
    * CVE-2026-6300: Use after free in CSS
    * CVE-2026-6301: Type Confusion in Turbofan
    * CVE-2026-6302: Use after free in Video
    * CVE-2026-6303: Use after free in Codecs
    * CVE-2026-6304: Use after free in Graphite
    * CVE-2026-6305: Heap buffer overflow in PDFium
    * CVE-2026-6306: Heap buffer overflow in PDFium
    * CVE-2026-6307: Type Confusion in Turbofan
    * CVE-2026-6308: Out of bounds read in Media
    * CVE-2026-6309: Use after free in Viz
    * CVE-2026-6360: Use after free in FileSystem
    * CVE-2026-6310: Use after free in Dawn
    * CVE-2026-6311: Uninitialized Use in Accessibility
    * CVE-2026-6312: Insufficient policy enforcement in Passwords
    * CVE-2026-6313: Insufficient policy enforcement in CORS
    * CVE-2026-6314: Out of bounds write in GPU
    * CVE-2026-6315: Use after free in Permissions
    * CVE-2026-6316: Use after free in Forms
    * CVE-2026-6361: Heap buffer overflow in PDFium
    * CVE-2026-6362: Use after free in Codecs
    * CVE-2026-6317: Use after free in Cast
    * CVE-2026-6363: Type Confusion in V8
    * CVE-2026-6318: Use after free in Codecs
    * CVE-2026-6319: Use after free in Payments
    * CVE-2026-6364: Out of bounds read in Skia
  - try sloppiness=gcno_cwd in local ccache config
* Wed Apr 08 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 147.0.7727.55 (boo#1261758):
    * CVE-2026-5858: Heap buffer overflow in WebML
    * CVE-2026-5859: Integer overflow in WebML
    * CVE-2026-5860: Use after free in WebRTC
    * CVE-2026-5861: Use after free in V8
    * CVE-2026-5862: Inappropriate implementation in V8
    * CVE-2026-5863: Inappropriate implementation in V8
    * CVE-2026-5864: Heap buffer overflow in WebAudio
    * CVE-2026-5865: Type Confusion in V8
    * CVE-2026-5866: Use after free in Media
    * CVE-2026-5867: Heap buffer overflow in WebML
    * CVE-2026-5868: Heap buffer overflow in ANGLE
    * CVE-2026-5869: Heap buffer overflow in WebML
    * CVE-2026-5870: Integer overflow in Skia
    * CVE-2026-5871: Type Confusion in V8
    * CVE-2026-5872: Use after free in Blink
    * CVE-2026-5873: Out of bounds read and write in V8
    * CVE-2026-5874: Use after free in PrivateAI
    * CVE-2026-5875: Policy bypass in Blink
    * CVE-2026-5876: Side-channel information leakage in Navigation
    * CVE-2026-5877: Use after free in Navigation
    * CVE-2026-5878: Incorrect security UI in Blink
    * CVE-2026-5879: Insufficient validation of untrusted input in ANGLE
    * CVE-2026-5880: Incorrect security UI in browser UI
    * CVE-2026-5881: Policy bypass in LocalNetworkAccess
    * CVE-2026-5882: Incorrect security UI in Fullscreen
    * CVE-2026-5883: Use after free in Media
    * CVE-2026-5884: Insufficient validation of untrusted input in Media
    * CVE-2026-5885: Insufficient validation of untrusted input in WebML
    * CVE-2026-5886: Out of bounds read in WebAudio
    * CVE-2026-5887: Insufficient validation of untrusted input in Downloads
    * CVE-2026-5888: Uninitialized Use in WebCodecs
    * CVE-2026-5889: Cryptographic Flaw in PDFium
    * CVE-2026-5890: Race in WebCodecs
    * CVE-2026-5891: Insufficient policy enforcement in browser UI
    * CVE-2026-5892: Insufficient policy enforcement in PWAs
    * CVE-2026-5893: Race in V8
    * CVE-2026-5894: Inappropriate implementation in PDF
    * CVE-2026-5895: Incorrect security UI in Omnibox
    * CVE-2026-5896: Policy bypass in Audio
    * CVE-2026-5897: Incorrect security UI in Downloads
    * CVE-2026-5898: Incorrect security UI in Omnibox
    * CVE-2026-5899: Incorrect security UI in History Navigation
    * CVE-2026-5900: Policy bypass in Downloads
    * CVE-2026-5901: Policy bypass in DevTools
    * CVE-2026-5902: Race in Media
    * CVE-2026-5903: Policy bypass in IFrameSandbox
    * CVE-2026-5904: Use after free in V8
    * CVE-2026-5905: Incorrect security UI in Permissions
    * CVE-2026-5906: Incorrect security UI in Omnibox
    * CVE-2026-5907: Insufficient data validation in Media
    * CVE-2026-5908: Integer overflow in Media
    * CVE-2026-5909: Integer overflow in Media
    * CVE-2026-5910: Integer overflow in Media
    * CVE-2026-5911: Policy bypass in ServiceWorkers
    * CVE-2026-5912: Integer overflow in WebRTC
    * CVE-2026-5913: Out of bounds read in Blink
    * CVE-2026-5914: Type Confusion in CSS
    * CVE-2026-5915: Insufficient validation of untrusted input in WebML
    * CVE-2026-5918: Inappropriate implementation in Navigation
    * CVE-2026-5919: Insufficient validation of untrusted input in WebSockets
    * enforce a num,ber of new Local Area Network (LAN) restrictions
    * New Web Printing API
    * vertical tabs support (trial)
  - new in 147 (for developers):
    * Element-scoped view transitions exposes startViewTransition on arbitrary HTML elements.
    * CSS contrast-color() helps meet accessibility requirements
    * The CSS border-shape property lets you create non-rectangular borders
* Thu Apr 02 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 147.0.7727.49 (early stable released 2026-04-01)
  - added patches:
    * chromium-147-comment_safe_assert.patch
      (ignore requirement for local libc++ for now, system copy
      has to be good enough)
    * chromium-147-ffmpeg_includes.patch
    * chromium-bafd7d217b9e26edf3be8d20b1ff56bcea4b16ee.patch
      (revert spanification for llvm-19 for now)
    * chromium-147-blink_renderer_need_ffmpeg.patch
      (only seen with using system ffmpeg)
  - modified patches:
    * chromium-24264eefbfd3464161764f31a2752c5327719452.patch
    * ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch
    * ppc-fedora-0002-regenerate-xnn-buildgn.patch
    * ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch
  - removed patches:
    * chromium-145-use_unrar.patch
* Thu Apr 02 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - ccache experiement: show stats
* Tue Mar 31 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 146.0.7680.177 (boo#1261249)
    * CVE-2026-5273: Use after free in CSS
    * CVE-2026-5272: Heap buffer overflow in GPU
    * CVE-2026-5274: Integer overflow in Codecs
    * CVE-2026-5275: Heap buffer overflow in ANGLE
    * CVE-2026-5276: Insufficient policy enforcement in WebUSB
    * CVE-2026-5277: Integer overflow in ANGLE
    * CVE-2026-5278: Use after free in Web MIDI
    * CVE-2026-5279: Object corruption in V8
    * CVE-2026-5280: Use after free in WebCodecs
    * CVE-2026-5281: Use after free in Dawn
    * CVE-2026-5282: Out of bounds read in WebCodecs
    * CVE-2026-5283: Inappropriate implementation in ANGLE
    * CVE-2026-5284: Use after free in Dawn
    * CVE-2026-5285: Use after free in WebGL
    * CVE-2026-5286: Use after free in Dawn
    * CVE-2026-5287: Use after free in PDF
    * CVE-2026-5288: Use after free in WebView
    * CVE-2026-5289: Use after free in Navigation
    * CVE-2026-5290: Use after free in Compositing
    * CVE-2026-5291: Inappropriate implementation in WebGL
    * CVE-2026-5292: Out of bounds read in WebCodecs
  - drop chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch
    (included)
* Mon Mar 23 2026 Ruediger Oertel <ro@suse.com>
  - Chromium 146.0.7680.164 (boo#1260376)
    * CVE-2026-4673: Heap buffer overflow in WebAudio
    * CVE-2026-4674: Out of bounds read in CSS
    * CVE-2026-4675: Heap buffer overflow in WebGL
    * CVE-2026-4676: Use after free in Dawn
    * CVE-2026-4677: Out of bounds read in WebAudio
    * CVE-2026-4678: Use after free in WebGPU
    * CVE-2026-4679: Integer overflow in Fonts
    * CVE-2026-4680: Use after free in FedCM
  - added patches:
    * chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch
      (upstream compile fix for blink on non-x86,non-arm)
* Wed Mar 18 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 146.0.7680.153 (boo#1259964):
    * CVE-2026-4439: Out of bounds memory access in WebGL
    * CVE-2026-4440: Out of bounds read and write in WebGL
    * CVE-2026-4441: Use after free in Base
    * CVE-2026-4442: Heap buffer overflow in CSS
    * CVE-2026-4443: Heap buffer overflow in WebAudio
    * CVE-2026-4444: Stack buffer overflow in WebRTC
    * CVE-2026-4445: Use after free in WebRTC
    * CVE-2026-4446: Use after free in WebRTC
    * CVE-2026-4447: Inappropriate implementation in V8
    * CVE-2026-4448: Heap buffer overflow in ANGLE
    * CVE-2026-4449: Use after free in Blink
    * CVE-2026-4450: Out of bounds write in V8
    * CVE-2026-4451: Insufficient validation of untrusted input in Navigation
    * CVE-2026-4452: Integer overflow in ANGLE
    * CVE-2026-4453: Integer overflow in Dawn
    * CVE-2026-4454: Use after free in Network
    * CVE-2026-4455: Heap buffer overflow in PDFium
    * CVE-2026-4456: Use after free in Digital Credentials API
    * CVE-2026-4457: Type Confusion in V8
    * CVE-2026-4458: Use after free in Extensions
    * CVE-2026-4459: Out of bounds read and write in WebAudio
    * CVE-2026-4460: Out of bounds read in Skia
    * CVE-2026-4461: Inappropriate implementation in V8
    * CVE-2026-4462: Out of bounds read in Blink
    * CVE-2026-4463: Heap buffer overflow in WebRTC
    * CVE-2026-4464: Integer overflow in ANGLE
* Mon Mar 16 2026 Ruediger Oertel <ro@suse.com>
  - fix INSTALL.sh (upstream changed CHANNEL to channel in wrapper)
* Sat Mar 14 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 146.0.7680.80:
    * CVE-2026-3909: Out of bounds write in Skia (boo#1259659)
* Fri Mar 13 2026 Ruediger Oertel <ro@suse.com>
  - Chromium 146.0.7680.75:
    * CVE-2026-3910: Inappropriate implementation in V8 (boo#1259648)
* Fri Mar 13 2026 Ruediger Oertel <ro@suse.com>
  - fix ffmpeg build on ppc64le
  - modified patches:
    * ppc-debian-0003-third_party-ffmpeg-Add-ppc64-generated-config.patch
* Thu Mar 12 2026 Ruediger Oertel <ro@suse.com>
  - modified patches:
    * chromium-146-value_or.patch (from debian)
  - removed patches:
    * chromium-144-revert_gfx_value_or.patch (contained above)
* Thu Mar 12 2026 Ruediger Oertel <ro@suse.com>
  - Chromium 146.0.7680.71 (released 2026-03-11) (boo#1259530)
    * CVE-2026-3913: Heap buffer overflow in WebML
    * CVE-2026-3914: Integer overflow in WebML
    * CVE-2026-3915: Heap buffer overflow in WebML
    * CVE-2026-3916: Out of bounds read in Web Speech
    * CVE-2026-3917: Use after free in Agents
    * CVE-2026-3918: Use after free in WebMCP
    * CVE-2026-3919: Use after free in Extensions
    * CVE-2026-3920: Out of bounds memory access in WebML
    * CVE-2026-3921: Use after free in TextEncoding
    * CVE-2026-3922: Use after free in MediaStream
    * CVE-2026-3923: Use after free in WebMIDI
    * CVE-2026-3924: Use after free in WindowDialog
    * CVE-2026-3925: Incorrect security UI in LookalikeChecks
    * CVE-2026-3926: Out of bounds read in V8
    * CVE-2026-3927: Incorrect security UI in PictureInPicture
    * CVE-2026-3928: Insufficient policy enforcement in Extensions
    * CVE-2026-3929: Side-channel information leakage in ResourceTiming
    * CVE-2026-3930: Unsafe navigation in Navigation
    * CVE-2026-3931: Heap buffer overflow in Skia
    * CVE-2026-3932: Insufficient policy enforcement in PDF
    * CVE-2026-3934: Insufficient policy enforcement in ChromeDriver
    * CVE-2026-3935: Incorrect security UI in WebAppInstalls
    * CVE-2026-3936: Use after free in WebView
    * CVE-2026-3937: Incorrect security UI in Downloads
    * CVE-2026-3938: Insufficient policy enforcement in Clipboard
    * CVE-2026-3939: Insufficient policy enforcement in PDF
    * CVE-2026-3940: Insufficient policy enforcement in DevTools
    * CVE-2026-3941: Insufficient policy enforcement in DevTools
    * CVE-2026-3942: Incorrect security UI in PictureInPicture
  - added patches:
    * chromium-146-mojo_chmod_mode.patch
      (fix typo/pythonism in c code)
    * chromium-146-value_or.patch
      (error: no matching member function for call to 'value_or')
    * chromium-146-has_no_clone.patch
    * chromium-146-clang-19-crash.patch (from debian)
    * chromium-146-keyfactory.patch (from debian)
    * chromium-146-static-assert.patch (from debian)
    * chromium-146-ignore-for-ubsan.patch (from debian)
    * chromium-146-bytemuck.patch (from debian)
  - modified patches:
    * chromium-125-compiler.patch
    * chromium-133-bring_back_and_disable_allowlist.patch
    * chromium-134-type-mismatch-error.patch
    * chromium-145-use_unrar.patch
    * force-rust-nightly.patch
    * rollup.patch
    * ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch
    * ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch
    * ppc-fedora-0001-Implement-support-for-ppc64-on-Linux.patch
    * ppc-fedora-fix-study-crash.patch
  - removed patches:
    * chromium-4f46f03a6c6d4c6efc1ad5d0d78030d02326f967.patch
  - keeplibs:
    drop third_party/skia/third_party/vulkan (gone)
    add  third_party/catapult/third_party/typ
    (needed by base/tracing/protos/chrome_track_event_resources_grit)
* Wed Mar 04 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 145.0.7632.159 (boo#1259213)
    * CVE-2026-3536: Integer overflow in ANGLE
    * CVE-2026-3537: Object lifecycle issue in PowerVR
    * CVE-2026-3538: Integer overflow in Skia
    * CVE-2026-3539: Object lifecycle issue in DevTools
    * CVE-2026-3540: Inappropriate implementation in WebAudio
    * CVE-2026-3541: Inappropriate implementation in CSS
    * CVE-2026-3542: Inappropriate implementation in WebAssembly
    * CVE-2026-3543: Inappropriate implementation in V8
    * CVE-2026-3544: Heap buffer overflow in WebCodecs
    * CVE-2026-3545: Insufficient data validation in Navigation
* Tue Feb 24 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 145.0.7632.116 (boo#1258733):
    * CVE-2026-3061: Out of bounds read in Media
    * CVE-2026-3062: Out of bounds read and write in Tint
    * CVE-2025-3063: Inappropriate implementation in DevTools
* Wed Feb 18 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 145.0.7632.109 (boo#1258438):
    * CVE-2026-2648: Heap buffer overflow in PDFium
    * CVE-2026-2649: Integer overflow in V8
    * CVE-2026-2650: Heap buffer overflow in Media
* Tue Feb 17 2026 Ruediger Oertel <ro@suse.com>
  - more fixes for desktop file, some variables were lowercased,
    further adaptions in INSTALL script (boo#1258199)
  - modified patches:
    * chromium-141-glibc-2.42-SYS_SECCOMP.patch
      (trigger only with glibc-2.43)
* Mon Feb 16 2026 Ruediger Oertel <ro@suse.com>
  - also copy rollup into third_party/node/node_modules
  - stay on llvm-10 for swiftshader but bring a similar patch
    * added patches:
      0001-swiftshader-fix-build-llvm10.patch
    * removed patches:
      chromium-143-swiftshader-llvm-16.0.patch
* Mon Feb 16 2026 Ruediger Oertel <ro@suse.com>
  - drop use of rollup binaries and use rollup-3.x which does not
    use prebuilt binaries (that fail at least on older ppc64le)
    follow the approach of the debian packaging
    * added patches:
      rollup.patch
* Mon Feb 16 2026 Ruediger Oertel <ro@suse.com>
  - update/resync ppc64le patches from fedora:
    * modified patches:
      ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch
      ppc-fedora-0001-Add-ppc64-target-to-libaom.patch
      ppc-fedora-0001-Add-pregenerated-config-for-libaom-on-ppc64.patch
      ppc-fedora-0001-Enable-ppc64-pointer-compression.patch
      ppc-fedora-0001-Force-baseline-POWER8-AltiVec-VSX-CPU-features-when-.patch
      ppc-fedora-0001-Implement-support-for-PPC64-on-Linux.patch
      ppc-fedora-0001-Implement-support-for-ppc64-on-Linux.patch
      ppc-fedora-0001-add-xnn-ppc64el-support.patch
      ppc-fedora-0001-sandbox-Enable-seccomp_bpf-for-ppc64.patch
      ppc-fedora-0001-swiftshader-fix-build.patch
      ppc-fedora-0001-third_party-angle-Include-missing-header-cstddef-in-.patch
      ppc-fedora-0001-third_party-libvpx-Properly-generate-gni-on-ppc64.patch
      ppc-fedora-0001-third_party-pffft-Include-altivec.h-on-ppc64-with-SI.patch
      ppc-fedora-0002-Add-PPC64-generated-files-for-boringssl.patch
      ppc-fedora-0002-Add-ppc64-trap-instructions.patch
      ppc-fedora-0002-regenerate-xnn-buildgn.patch
      ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch
      ppc-fedora-0002-third_party-lss-kernel-structs.patch
      ppc-fedora-0003-third_party-libvpx-Add-ppc64-generated-config.patch
      ppc-fedora-0004-third_party-crashpad-port-curl-transport-ppc64.patch
      ppc-fedora-0004-third_party-libvpx-work-around-ambiguous-vsx.patch
      ppc-fedora-HACK-debian-clang-disable-base-musttail.patch
      ppc-fedora-HACK-third_party-libvpx-use-generic-gnu.patch
      ppc-fedora-Rtc_base-system-arch.h-PPC.patch
      ppc-fedora-add-ppc64-architecture-string.patch
      ppc-fedora-add-ppc64-architecture-to-extensions.diff
      ppc-fedora-add-ppc64-pthread-stack-size.patch
      ppc-fedora-dawn-fix-ppc64le-detection.patch
      ppc-fedora-fix-breakpad-compile.patch
      ppc-fedora-fix-different-data-layouts.patch
      ppc-fedora-fix-partition-alloc-compile.patch
      ppc-fedora-fix-rust-linking.patch
      ppc-fedora-fix-study-crash.patch
      ppc-fedora-fix-unknown-warning-option-messages.diff
      ppc-fedora-skia-vsx-instructions.patch
    * removed patches:
      ppc-fedora-0001-linux-seccomp-bpf-ppc64-glibc-workaround-in-SIGSYS-h.patch
      ppc-fedora-0001-services-service_manager-sandbox-linux-Fix-TCGETS-de.patch
      ppc-fedora-0001-sandbox-linux-bpf_dsl-Update-syscall-ranges-for-ppc6.patch
      ppc-fedora-0001-sandbox-linux-Implement-partial-support-for-ppc64-sy.patch
      ppc-fedora-0001-sandbox-linux-Update-IsSyscallAllowed-in-broker_proc.patch
      ppc-fedora-0001-sandbox-linux-Update-syscall-helpers-lists-for-ppc64.patch
      ppc-fedora-0002-sandbox-linux-bpf_dsl-Modify-seccomp_macros-to-add-s.patch
      ppc-fedora-0003-sandbox-linux-system_headers-Update-linux-seccomp-he.patch
      ppc-fedora-0004-sandbox-linux-system_headers-Update-linux-signal-hea.patch
      ppc-fedora-0005-sandbox-linux-seccomp-bpf-Add-ppc64-syscall-stub.patch
      ppc-fedora-0005-sandbox-linux-update-unit-test-for-ppc64.patch
      ppc-fedora-0006-sandbox-linux-disable-timedwait-time64-ppc64.patch
      ppc-fedora-0007-sandbox-linux-add-ppc64-stat.patch
      ppc-fedora-Sandbox-linux-services-credentials.cc-PPC.patch
      ppc-fedora-0008-sandbox-fix-ppc64le-glibc234.patch
      ppc-fedora-0002-Include-cstddef-to-fix-build.patch
      ppc-fedora-0001-third-party-hwy-wrong-include.patch
      ppc-fedora-fix-ppc64-linux-syscalls-headers.patch
      ppc-fedora-use-sysconf-page-size-on-ppc64.patch
    * added patches:
      ppc-fedora-HACK-debian-clang-disable-pa-musttail.patch
      ppc-fedora-fix-rustc.patch
      ppc-fedora-fix-page-allocator-overflow.patch
      chromium-143-swiftshader-llvm-16.0.patch
      chromium-145-swiftshader-missing-include.patch
* Mon Feb 16 2026 Ruediger Oertel <ro@suse.com>
  - fix INSTALL.sh again to replace the tags in desktop file,
    appdata and manpage (boo#1258199)
* Fri Feb 13 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 145.0.7632.75:
    * CVE-2026-2441: Use after free in CSS (boo#1258185)
* Fri Feb 13 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 145.0.7632.67:
    * Revert a change in url_fixer that may have caused crashes
* Wed Feb 04 2026 Ruediger Oertel <ro@suse.com>
  - Chromium 145.0.7632.45 (boo#1258116)
    * jpeg-xl support has been readded
    * CVE-2026-2313: Use after free in CSS
    * CVE-2026-2314: Heap buffer overflow in Codecs
    * CVE-2026-2315: Inappropriate implementation in WebGPU
    * CVE-2026-2316: Insufficient policy enforcement in Frames
    * CVE-2026-2317: Inappropriate implementation in Animation
    * CVE-2026-2318: Inappropriate implementation in PictureInPicture
    * CVE-2026-2319: Race in DevTools
    * CVE-2026-2320: Inappropriate implementation in File input
    * CVE-2026-2321: Use after free in Ozone
    * CVE-2026-2322: Inappropriate implementation in File input
    * CVE-2026-2323: Inappropriate implementation in Downloads
  - modified patches:
    * chromium-127-rust-clanglib.patch (context)
    * chromium-144-revert-libxml-2.13.patch (context)
    * ppc-fedora-0001-Force-baseline-POWER8-AltiVec-VSX-CPU-features-when-.patch
      (context)
    * ppc-debian-0003-third_party-ffmpeg-Add-ppc64-generated-config.patch
      (drop ref to ppc/lossless_audiodsp_altivec.o, dropped upstream)
    * chromium-141-no_cxx_modules.patch
    * ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch (context)
    * ppc-fedora-0002-regenerate-xnn-buildgn.patch (regenerated)
    * system-libdrm.patch (context)
    * ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch
  - added patches:
    * chromium-145-blink_missing_include.patch
    * chromium-145-use_unrar.patch
      (properly respect disabling unrar in recent code changes)
    * ppc-fedora-0009-sandbox-ignore-byte-span-error.patch
    * chromium-4f46f03a6c6d4c6efc1ad5d0d78030d02326f967.patch
      (revert spanification for jpeg_parser ending in compile error)
    * chromium-24264eefbfd3464161764f31a2752c5327719452.patch
      (also to revert jpeg_encoder spanification for older llvm)
  - bump BR for gn to 0.20251217
    * need the string_hash function for rust gni
  - add rollup binaries for arm64 and powerpc64le, missing upstream
    using tarballs from npm.skia.org
* Wed Feb 04 2026 Ruediger Oertel <ro@suse.com>
  - Chromium 144.0.7559.132 (boo#1257650)
    * CVE-2026-1861: Heap buffer overflow in libvpx in Google Chrome
      prior to 144.0.7559.132 allowed a remote attacker to potentially
      exploit heap corruption via a crafted HTML page.
    * CVE-2026-1862: Type Confusion in V8 in Google Chrome prior to
      144.0.7559.132 allowed a remote attacker to potentially exploit
      heap corruption via a crafted HTML page.
  - removed patches:
    * chromium-134-revert-rust-adler2.patch
    * chromium-144-rust-adler2.patch
      (obsolete, automatic if rust_nightly is set properly)
  - added patches:
    * force-rust-nightly.patch
  - try rust1.93 for tumbleweed, 1.92 for older
  - gn flags:
    add toolchain_supports_rust_thin_lto=false to be able to build
    with a llvm older than the one vendored in rust
  - use llvm21 for tumbleweed
  - drop qt5 parts from spec, not used
* Thu Jan 29 2026 Ruediger Oertel <ro@suse.com>
  - use nodejs-common and use the version from /usr/bin/node
  - but use nodejs22 for code15 (while nodejs-common still
    points to nodejs14 there)
* Wed Jan 28 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 144.0.7559.109 (boo#1257404)
    * CVE-2026-1504: Inappropriate implementation in Background Fetch API
* Wed Jan 21 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 144.0.7559.96 (boo#1257011)
    * CVE-2026-1220: Race in V8
* Tue Jan 20 2026 ro@suse.de
  - update INSTALL.sh to handle the addded tags in the
    desktop file (boo#1256938)
* Wed Jan 14 2026 Ruediger Oertel <ro@suse.de>
  - Chromium 144.0.7559.59 (boo#1256614)
    * CVE-2026-0899: Out of bounds memory access in V8
    * CVE-2026-0900: Inappropriate implementation in V8
    * CVE-2026-0901: Inappropriate implementation in Blink
    * CVE-2026-0902: Inappropriate implementation in V8
    * CVE-2026-0903: Insufficient validation of untrusted input in Downloads
    * CVE-2026-0904: Incorrect security UI in Digital Credentials
    * CVE-2026-0905: Insufficient policy enforcement in Network
    * CVE-2026-0906: Incorrect security UI
    * CVE-2026-0907: Incorrect security UI in Split View
    * CVE-2026-0908: Use after free in ANGLE
  - added patches:
    * chromium-144-rust-adler2.patch
      (with system rust-1.86, we still have adler2)
    * chromium-144-revert_gfx_value_or.patch
      (looks like third_party/skia is outdated)
    * chromium-144-revert-libxml-2.13.patch
      (conditionally applied if libxml < 2.13)
  - modified patches:
    * chromium-125-compiler.patch
    * chromium-127-bindgen.patch
    * chromium-127-rust-clanglib.patch
      (rust nightly features are now guarded, drop hunk)
    * gcc-enable-lto.patch
    * ppc-fedora-0001-sandbox-linux-Update-syscall-helpers-lists-for-ppc64.patch
    * ppc-fedora-0002-regenerate-xnn-buildgn.patch
      (regenerated)
  - dropped patches:
    * ppc-fedora-fix-clang-selection.patch (upstream)
    * chromium-140-keep-__rust_no_alloc_shim_is_unstable.patch
    * chromium-142-rust-revert_should_panic.patch
  - keeplibs:
    added third_party/perfetto/protos/third_party/pprof (pulled in)
  - gn buildflags:
    * drop duplicate "use_sysroot=false"
    * add "chrome_pgo_phase=0" as in debian and fedora
  - use noopenh264 where available
* Tue Jan 06 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 143.0.7499.192 (boo#1256067):
    * CVE-2026-0628: Insufficient policy enforcement in WebView tag
* Fri Dec 19 2025 ro@suse.de
  - Chromium 143.0.7499.169 (stable released 2025-12-18)
    * no cve listed yet
* Wed Dec 17 2025 Ruediger Oertel <ro@suse.de>
  - Chromium 143.0.7499.146 (boo#1255115):
    * CVE-2025-14765: Use after free in WebGPU
    * CVE-2025-14766: Out of bounds read and write in V8
* Wed Dec 10 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 143.0.7499.109 (boo#1254776):
    * CVE-2025-14372: Use after free in Password Manager
    * CVE-2025-14373: Inappropriate implementation in Toolbar
    * CVE-2025-14174: Out of bounds memory access in ANGLE
  - added patch gtk-414-2.patch
    (also revert upstream cdc2a57272589f9522689500838e889b88b3f9d4
    for older gtk versions)
* Tue Dec 02 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 143.0.7499.40 (boo#1254429):
    * CVE-2025-13630: Type Confusion in V8
    * CVE-2025-13631: Inappropriate implementation in Google Updater
    * CVE-2025-13632: Inappropriate implementation in DevTools
    * CVE-2025-13633: Use after free in Digital Credentials
    * CVE-2025-13634: Inappropriate implementation in Downloads
    * CVE-2025-13720: Bad cast in Loader
    * CVE-2025-13721: Race in v8
    * CVE-2025-13635: Inappropriate implementation in Downloads
    * CVE-2025-13636: Inappropriate implementation in Split View
    * CVE-2025-13637: Inappropriate implementation in Downloads
    * CVE-2025-13638: Use after free in Media Stream
    * CVE-2025-13639: Inappropriate implementation in WebRTC
    * CVE-2025-13640: Inappropriate implementation in Passwords
  - added patches:
    chromium-143-libpng-unbundle.patch
    (workaround broken libpng unbundle)
    chromium-143-cookie_string_view.patch
    (use string_view also for the const_iterator after type change)
    chromium-143-revert_rust_is_multiple_of.patch
    (revert added calls to is_multiple_of rejected as unstable feature)
  - modified patches:
    gcc-enable-lto.patch (updated context)
    chromium-127-constexpr.patch (file moved)
    chromium-140-keep-__rust_no_alloc_shim_is_unstable.patch (add unsafe)
    ppc-fedora-fix-clang-selection.patch (updated context)
    ppc-fedora-0002-regenerate-xnn-buildgn.patch (reduced to stub,
    will need updating)
  - dropped patches:
    chromium-142-iwyu-field-form-data.patch (upstream)
  - bump buildrequires for rust-bindgen to 0.71 minimum as we need
    the unsafe_extern_blocks
  - updated ppc-fedora-0002-regenerate-xnn-buildgn.patch
* Sun Nov 23 2025 Stanislav Brabec <sbrabec@suse.com>
  - Remove unused BuildRequires: update-desktop-files.
* Mon Nov 17 2025 ro@suse.de
  - Chromium 142.0.7444.175 (boo#1253698):
    * CVE-2025-13223: Type Confusion in V8
    * CVE-2025-13224: Type Confusion in V8
* Tue Nov 11 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 142.0.7444.162 (boo#1253267):
    * CVE-2025-13042: Inappropriate implementation in V8
* Thu Nov 06 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 142.0.7444.134 (boo#1253089):
    * CVE-2025-12725: Out of bounds write in WebGPU
    * CVE-2025-12726: Inappropriate implementation in Views
    * CVE-2025-12727: Inappropriate implementation in V8
    * CVE-2025-12728: Inappropriate implementation in Omnibox
    * CVE-2025-12729: Inappropriate implementation in Omnibox
* Wed Oct 29 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 142.0.7444.59, the stable channel promotion of 142
    Security fixes (boo#1252881):
    * CVE-2025-12428: Type Confusion in V8
    * CVE-2025-12429: Inappropriate implementation in V8
    * CVE-2025-12430: Object lifecycle issue in Media
    * CVE-2025-12431: Inappropriate implementation in Extensions
    * CVE-2025-12432: Race in V8
    * CVE-2025-12433: Inappropriate implementation in V8
    * CVE-2025-12434: Race in Storage
    * CVE-2025-12435: Incorrect security UI in Omnibox
    * CVE-2025-12436: Policy bypass in Extensions
    * CVE-2025-12437: Use after free in PageInfo
    * CVE-2025-12438: Use after free in Ozone
    * CVE-2025-12439: Inappropriate implementation in App-Bound Encryption
    * CVE-2025-12440: Inappropriate implementation in Autofill
    * CVE-2025-12441: Out of bounds read in V8
    * CVE-2025-12443: Out of bounds read in WebXR
    * CVE-2025-12444: Incorrect security UI in Fullscreen UI
    * CVE-2025-12445: Policy bypass in Extensions
    * CVE-2025-12446: Incorrect security UI in SplitView
    * CVE-2025-12447: Incorrect security UI in Omnibox
  - drop chromium-142-dawn_commit_hash.patch, the generation of the
    header was included in the tarball genration
* Mon Oct 27 2025 ro@suse.de
  - Chromium 142.0.7444.52
  - added patches:
    chromium-142-rust-revert_should_panic.patch
    re-add __rust_alloc_error_handler_should_panic
    to fix unresolved symbol
    chromium-142-dawn_commit_hash.patch:
    create gpu/webgpu/dawn_commit_hash.h which should be in tarball
    chromium-142-rust_no_sanitize.patch:
    revert rust change no_sanitize to sanitize=off
    chromium-142-iwyu-field-form-data.patch
  - drop chromium-139-pdfium-openjpeg-CVE-2025-54874.patch
  - update ppc patches
    modified patches:
    ppc-fedora-0001-sandbox-linux-Implement-partial-support-for-ppc64-sy.patch#
    ppc-fedora-0001-third-party-hwy-wrong-include.patch
    ppc-fedora-0002-regenerate-xnn-buildgn.patch
    ppc-fedora-add-ppc64-architecture-to-extensions.diff
    removed patches:
    ppc-fedora-fix-ppc64-rust_png-build-error.patch (obsolete)
* Tue Oct 21 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 141.0.7390.122:
    * CVE-2025-12036: Inappropriate implementation in V8 (boo#1252402)
* Wed Oct 15 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 141.0.7390.107:
    * CVE-2025-11756: Use after free in Safe Browsing (boo#1252013)
* Thu Oct 09 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 141.0.7390.76:
    * Do not send URLs as AIM input. This is to resolve a privacy
      concern, around passing urls to AI Mode.
* Thu Oct 09 2025 Dirk Müller <dmueller@suse.com>
  - exclude the main tarball from the src.rpm to reduce size
    (it is anyway fully referenced, so no supply chain concern)
* Wed Oct 08 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 141.0.7390.65 (boo#1251334):
    * CVE-2025-11458: Heap buffer overflow in Sync
    * CVE-2025-11460: Use after free in Storage
    * CVE-2025-11211: Out of bounds read in WebCodecs
* Wed Oct 01 2025 ro@suse.de
  - Chromium 141.0.7390.54
    (stable released 2025-09-30) (boo#1250780)
    * CVE-2025-11205: Heap buffer overflow in WebGPU
    * CVE-2025-11206: Heap buffer overflow in Video
    * CVE-2025-11207: Side-channel information leakage in Storage
    * CVE-2025-11208: Inappropriate implementation in Media
    * CVE-2025-11209: Inappropriate implementation in Omnibox
    * CVE-2025-11210: Side-channel information leakage in Tab
    * CVE-2025-11211: Out of bounds read in Media
    * CVE-2025-11212: Inappropriate implementation in Media
    * CVE-2025-11213: Inappropriate implementation in Omnibox
    * CVE-2025-11215: Off by one error in V8
    * CVE-2025-11216: Inappropriate implementation in Storage
    * CVE-2025-11219: Use after free in V8
    * Various fixes from internal audits, fuzzing and other initiatives
  - added patches:
    chromium-141-csss_style_sheet.patch (from fedora)
    chromium-141-use_libcxx_modules.patch (from fedora)
    chromium-141-no_cxx_modules.patch
    (one more fallout from clang modules)
  - modified patches: (context)
    ppc-fedora-0001-sandbox-linux-Update-syscall-helpers-lists-for-ppc64.patch
    ppc-fedora-Sandbox-linux-services-credentials.cc-PPC.patch
    ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch
    ppc-fedora-add-ppc64-architecture-to-extensions.diff
    ppc-debian-0003-third_party-ffmpeg-Add-ppc64-generated-config.patch
    (updated from debian)
    chromium-121-rust-clang_lib.patch (redone)
  - keeplibs:
    added third_party/federated_compute (pulled in)
    added third_party/oak (needed by federated_compute)
* Wed Sep 24 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 141.0.7390.37
    (beta released 2025-09-24)
  - modified patches:
    chromium-125-compiler.patch
    chromium-133-bring_back_and_disable_allowlist.patch
    chromium-140-keep-__rust_no_alloc_shim_is_unstable.patch
  - dropped patches:
    ppc-fedora-fix-rustc.patch (obsolete)
    chromium-135-add_map_droppable.patch
* Wed Sep 24 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 140.0.7339.207 (boo#1250472)
    * CVE-2025-10890: Side-channel information leakage in V8
    * CVE-2025-10891: Integer overflow in V8
    * CVE-2025-10892: Integer overflow in V8
* Mon Sep 22 2025 ro@suse.de
  - use the same llvm version on recent distros,
    build currently fails with lvm21
* Wed Sep 17 2025 ro@suse.de
  - Chromium 140.0.7339.185 (stable released 2025-09-17) boo#1249999
    * CVE-2025-10585: Type Confusion in V8
    * CVE-2025-10500: Use after free in Dawn
    * CVE-2025-10501: Use after free in WebRTC
    * CVE-2025-10502: Heap buffer overflow in ANGLE
* Wed Sep 10 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 140.0.7339.127 (boo#1249388)
    * CVE-2025-10200: Use after free in Serviceworker
    * CVE-2025-10201: Inappropriate implementation in Mojo
* Tue Sep 02 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 140.0.7339.80 (boo#1249093):
    * new permission prompt for local network access
    * CVE-2025-9864: Use after free in V8
    * CVE-2025-9865: Inappropriate implementation in Toolbar
    * CVE-2025-9866: Inappropriate implementation in Extensions
    * CVE-2025-9867: Inappropriate implementation in Downloads
    * Various fixes from internal audits, fuzzing and other initiatives
* Tue Sep 02 2025 ro@suse.de
  - modified patches:
    ppc-fedora-0002-regenerate-xnn-buildgn.patch
    (updated from debian)
* Thu Aug 28 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 140.0.7339.41
    (early stable released 2025-08-27)
  - modified patches:
    chromium-125-compiler.patch
    chromium-libusb_interrupt_event_handler.patch
    gcc-enable-lto.patch
    ppc-fedora-fix-unknown-warning-option-messages.diff
    ppc-fedora-0001-sandbox-linux-Update-syscall-helpers-lists-for-ppc64.patch
    ppc-fedora-add-ppc64-architecture-to-extensions.diff
    chromium-102-regex_pattern-array.patch
    gtk-414.patch
    ppc-fedora-fix-study-crash.patch
    ppc-fedora-0002-regenerate-xnn-buildgn.patch (stub, needs to be redone)
    ppc-fedora-0001-Add-pregenerated-config-for-libaom-on-ppc64.patch
  - added patches:
    chromium-140-keep-__rust_no_alloc_shim_is_unstable.patch
    (revert of upstream patch
    8393b61ba876c8e1614275c97767f9b06b889f48)
    chromium-140-old-flac.patch (applied for flac < 1.5.0)
  - change rust_version to 1.86
  - keeplibs:
    removed buildtools/third_party/eu-strip (gone upstream)
    removed wasm_tts_engine (gone upstream)
  - bump gn BuildReq to 0.20250619
  - do not use system_harfbuzz for 16+ for now, unbundle is broken
* Wed Aug 27 2025 ro@suse.de
  - Chromium 139.0.7258.154 (boo#1248769)
    * CVE-2025-9478: Use after free in ANGLE
* Tue Aug 19 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 139.0.7258.138 (boo#1248315):
    * CVE-2025-9132: Out of bounds write in V8
* Wed Aug 13 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 139.0.7258.127 (boo#1247981):
    * CVE-2025-8879: Heap buffer overflow in libaom
    * CVE-2025-8880: Race in V8
    * CVE-2025-8901: Out of bounds write in ANGLE
    * CVE-2025-8881: Inappropriate implementation in File Picker
    * CVE-2025-8882: Use after free in Aura
    * Various fixes from internal audits, fuzzing and other initiatives
* Thu Aug 07 2025 ro@suse.de
  - really install libffmpeg.so if using the bundled one
    and block the extra dependency
* Wed Aug 06 2025 ro@suse.de
  - add patch:
    chromium-139-pdfium-openjpeg-CVE-2025-54874.patch
    (CVE-2025-54874 bsc#1247661) fix missing error check in openjpeg
* Wed Aug 06 2025 ro@suse.de
  - re-add updated patch:
    ppc-fedora-0002-regenerate-xnn-buildgn.patch
    from https://src.fedoraproject.org/rpms/chromium/blob/
      rawhide/f/0002-regenerate-xnn-buildgn.patch
* Tue Aug 05 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 139.0.7258.66 (boo#1247664):
    * CVE-2025-8576: Use after free in Extensions
    * CVE-2025-8577: Inappropriate implementation in Picture In Picture
    * CVE-2025-8578: Use after free in Cast
    * CVE-2025-8579: Inappropriate implementation in Gemini Live in Chrome
    * CVE-2025-8580: Inappropriate implementation in Filesystems
    * CVE-2025-8581: Inappropriate implementation in Extensions
    * CVE-2025-8582: Insufficient validation of untrusted input in DOM
    * CVE-2025-8583: Inappropriate implementation in Permissions
    - modified patches:
    gcc-enable-lto.patch
    ppc-fedora-0001-sandbox-linux-Update-syscall-helpers-lists-for-ppc64.patch
    ppc-fedora-skia-vsx-instructions.patch
    ppc-fedora-fix-partition-alloc-compile.patch
    ppc-fedora-0001-add-xnn-ppc64el-support.patch
    - dropped patches:
    chromium-warning-suppression-mappings.patch (using cmdline switch)
    chromium-93-ffmpeg-4.4.patch
    - dropped the ffmpeg revert patches that were only applied for 15:
    chromium-125-ffmpeg-5.x-reordered_opaque.patch
    Cr122-ffmpeg-new-channel-layout.patch
    ffmpeg-new-channel-layout.patch
    chromium-106-ffmpeg-duration.patch
    chromium-93-ffmpeg-4.4-rest.patch
    chromium-138-revert_ffmpeg_FF_AV.patch
    - added patches:
    ppc-debian-0003-third_party-ffmpeg-Add-ppc64-generated-config.patch
    - keeplibs:
    removed chrome/third_party/mozilla_security_manager
    removed third_party/mesa
    added third_party/ml_dtypes (needed in tflite/xla)
    added third_party/readability (needed in tools/grit/grit)
    added third_party/ffmpeg (gave up on reverting all recent
      commits in the code using ffmpeg, need at least ffmpeg-7)
  - remove disabled ppc-fedora-0002-regenerate-xnn-buildgn.patch
    to please factory-auto
* Wed Jul 30 2025 ro@suse.de
  - Chromium 138.0.7204.183 (boo#1247365):
    * CVE-2025-8292: Use after free in Media Stream
  - try to switch to smaller linux tarball from
    https://github.com/chromium-linux-tarballs)
  - disable chromium-91-java-only-allowed-in-android-builds.patch
    (not part of reduced tarball)
* Tue Jul 29 2025 ro@suse.de
  - set official_build to true (like other distributions)
    "official builds have less debugging and go faster..."
  - added patches:
    chromium-139-deterministic.patch
    (undefine __DATE__,__TIME__ like without official-build set
    to keep the build reproducible)
* Thu Jul 24 2025 ro@suse.de
  - modified patches:
    ppc-fedora-0001-sandbox-linux-Update-syscall-helpers-lists-for-ppc64.patch
    (update context to apply)
* Tue Jul 22 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 138.0.7204.168 (boo#1246902):
    * CVE-2025-8010: Type Confusion in V8
    * CVE-2025-8011: Type Confusion in V8
    * Various fixes from internal audits, fuzzing and other
      initiatives
* Tue Jul 15 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 138.0.7204.157 (boo#1246558):
    * CVE-2025-7656: Integer overflow in V8
    * CVE-2025-6558: Incorrect validation of untrusted input in ANGLE
      and GPU
    * CVE-2025-7657: Use after free in WebRTC
* Wed Jul 09 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 138.0.7204.100:
    * tweaks to the Google services settings page
* Tue Jul 01 2025 ro@suse.de
  - update from debian:
    ppc-fedora-skia-vsx-instructions.patch
  - dropped patches:
    ppc-skia-revert-1.patch
    ppc-skia-revert-2.patch
    ppc-skia-revert-3.patch
* Tue Jul 01 2025 ro@suse.de
  - Chromium 138.0.7204.96
    (stable released 2025-06-30) (boo#1245544)
    * CVE-2025-6554: Type Confusion in V8
* Wed Jun 25 2025 ro@suse.de
  - Chromium 138.0.7204.49
    (stable released 2025-06-24) (boo#1245332)
    * CVE-2025-6555: Use after free in Animation
    * CVE-2025-6556: Insufficient policy enforcement in Loader
    * CVE-2025-6557: Insufficient data validation in DevTools
  - dropped patches:
    chromium-137-heuristics_missing_includes.patch (upstream)
    chromium-137-pdfium_fix_pattribute.patch (upstream)
  - modified patches:
    chromium-125-compiler.patch (context)
    ffmpeg-new-channel-layout.patch (context)
    chromium-134-revert-rust-adler2.patch (context,reverse application)
    ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch (context)
    ppc-fedora-0002-regenerate-xnn-buildgn.patch (context)
    ppc-fedora-memory-allocator-dcheck-assert-fix.patch (context)
    chromium-warning-suppression-mappings.patch (context)
  - added patches:
    (conditional revert for old ffmpeg,
    upstream 129f48501a7c3fa4236234f2fa0aee490a845b59)
    chromium-138-revert_ffmpeg_FF_AV.patch
  - keeplibs:
    removed third_party/distributed_point_functions
    removed third_party/tflite/src/third_party/eigen3
    removed third_party/webrtc/rtc_base/third_party/base64
    added third_party/dragonbox
    (needed by ../v8/src/numbers/conversions.cc )
  - bump gn buildrequires to 0.20250520
* Tue Jun 17 2025 ro@suse.de
  - Chromium 137.0.7151.119
    (stable release 2025-06-17) (boo#1244711)
    * CVE-2025-6191: Integer overflow in V8
    * CVE-2025-6192: Use after free in Profiler
* Thu Jun 12 2025 Bernhard Wiedemann <bwiedemann@suse.com>
  - Replace usage of %jobs for reproducible builds (boo#1237231)
* Wed Jun 11 2025 ro@suse.de
  - Chromium 137.0.7151.103
    (stable release 2025-06-10) (boo#1244452)
    * CVE-2025-5958: Use after free in Media
    * CVE-2025-5959: Type Confusion in V8
* Tue Jun 03 2025 ro@suse.de
  - Chromium 137.0.7151.68
    (stable release 2025-06-03) (boo#1244019)
    * CVE-2025-5419: Out of bounds read and write in V8
    * CVE-2025-5068: Use after free in Blink
    - Google is aware that an exploit for CVE-2025-5419
      exists in the wild.
* Thu May 29 2025 ro@suse.de
  - added patches:
    ppc-fedora-0001-add-xnn-ppc64el-support.patch
    ppc-fedora-0002-regenerate-xnn-buildgn.patch
* Tue May 27 2025 ro@suse.de
  - Chromium 137.0.7151.55
    (stable release 2025-05-27) (boo#1243741)
    * CVE-2025-5063: Use after free in Compositing
    * CVE-2025-5280: Out of bounds write in V8
    * CVE-2025-5064: Inappropriate implementation in Background Fetch API
    * CVE-2025-5065: Inappropriate implementation in FileSystemAccess API
    * CVE-2025-5066: Inappropriate implementation in Messages
    * CVE-2025-5281: Inappropriate implementation in BFCache
    * CVE-2025-5283: Use after free in libvpx
    * CVE-2025-5067: Inappropriate implementation in Tab Strip
  - dropped patches:
    chromium-135-gperf-output.patch (upstream)
  - modified patches:
    chromium-125-compiler.patch (context)
    chromium-127-rust-clanglib.patch (context)
    ffmpeg-new-channel-layout.patch
    (drop one hunk where upstream dropped the code)
    system-libdrm.patch (context)
    ppc-fedora-fix-partition-alloc-compile.patch (context)
    ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch (context)
    ppc-fedora-0001-sandbox-Enable-seccomp_bpf-for-ppc64.patch (context)
  - added patches:
    chromium-137-pdfium_fix_pattribute.patch
    (fix typo in pAttribute attributes)
    chromium-137-heuristics_missing_includes.patch
    (upstream patch 4c736420952f355f18bdc4f4ea2d16e4514fa034)
    chromium-137-disruptive_notification_permissions_manager-missing_include.patch
    (missing include)
    - revert last skia patches for gather_unaligned until we have a port for ppc64le
      ppc-skia-revert-1.patch
      ppc-skia-revert-2.patch
      ppc-skia-revert-3.patch
  - keeplibs:
    added third_party/compiler-rt
* Wed May 14 2025 ro@suse.de
  - Chromium 136.0.7103.113
    (stable release 2025-05-14) (boo#1243205)
    * CVE-2025-4664: Insufficient policy enforcement in Loader
    * CVE-2025-4609: Incorrect handle provided in unspecified
      circumstances in Mojo
* Mon May 12 2025 ro@suse.de
  - try build on ppc64le
  - added patches (from fedora)
      ppc-fedora-add-ppc64-architecture-string.patch
      ppc-fedora-0001-linux-seccomp-bpf-ppc64-glibc-workaround-in-SIGSYS-h.patch
      ppc-fedora-0001-sandbox-Enable-seccomp_bpf-for-ppc64.patch
      ppc-fedora-0001-services-service_manager-sandbox-linux-Fix-TCGETS-de.patch
      ppc-fedora-0001-sandbox-linux-bpf_dsl-Update-syscall-ranges-for-ppc6.patch
      ppc-fedora-0001-sandbox-linux-Implement-partial-support-for-ppc64-sy.patch
      ppc-fedora-0001-sandbox-linux-Update-IsSyscallAllowed-in-broker_proc.patch
      ppc-fedora-0001-sandbox-linux-Update-syscall-helpers-lists-for-ppc64.patch
      ppc-fedora-0002-sandbox-linux-bpf_dsl-Modify-seccomp_macros-to-add-s.patch
      ppc-fedora-0003-sandbox-linux-system_headers-Update-linux-seccomp-he.patch
      ppc-fedora-0004-sandbox-linux-system_headers-Update-linux-signal-hea.patch
      ppc-fedora-0005-sandbox-linux-seccomp-bpf-Add-ppc64-syscall-stub.patch
      ppc-fedora-0005-sandbox-linux-update-unit-test-for-ppc64.patch
      ppc-fedora-0006-sandbox-linux-disable-timedwait-time64-ppc64.patch
      ppc-fedora-0007-sandbox-linux-add-ppc64-stat.patch
      ppc-fedora-Sandbox-linux-services-credentials.cc-PPC.patch
      ppc-fedora-0008-sandbox-fix-ppc64le-glibc234.patch
      ppc-fedora-0001-third_party-angle-Include-missing-header-cstddef-in-.patch
      ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch
      ppc-fedora-0001-third_party-libvpx-Properly-generate-gni-on-ppc64.patch
      ppc-fedora-0001-third_party-pffft-Include-altivec.h-on-ppc64-with-SI.patch
      ppc-fedora-0002-Add-PPC64-generated-files-for-boringssl.patch
      ppc-fedora-0002-third_party-lss-kernel-structs.patch
      ppc-fedora-0001-swiftshader-fix-build.patch
      ppc-fedora-Rtc_base-system-arch.h-PPC.patch
      ppc-fedora-0002-Include-cstddef-to-fix-build.patch
      ppc-fedora-0004-third_party-crashpad-port-curl-transport-ppc64.patch
      ppc-fedora-HACK-third_party-libvpx-use-generic-gnu.patch
      ppc-fedora-0001-third-party-hwy-wrong-include.patch
      ppc-fedora-HACK-debian-clang-disable-base-musttail.patch
      ppc-fedora-0001-Add-ppc64-target-to-libaom.patch
      ppc-fedora-0001-Add-pregenerated-config-for-libaom-on-ppc64.patch
      ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch
      ppc-fedora-0003-third_party-libvpx-Add-ppc64-generated-config.patch
      ppc-fedora-0004-third_party-libvpx-work-around-ambiguous-vsx.patch
      ppc-fedora-skia-vsx-instructions.patch
      ppc-fedora-0001-Implement-support-for-ppc64-on-Linux.patch
      ppc-fedora-0001-Implement-support-for-PPC64-on-Linux.patch
      ppc-fedora-0001-Force-baseline-POWER8-AltiVec-VSX-CPU-features-when-.patch
      ppc-fedora-fix-clang-selection.patch
      ppc-fedora-fix-rustc.patch
      ppc-fedora-fix-rust-linking.patch
      ppc-fedora-fix-breakpad-compile.patch
      ppc-fedora-fix-partition-alloc-compile.patch
      ppc-fedora-fix-study-crash.patch
      ppc-fedora-memory-allocator-dcheck-assert-fix.patch
      ppc-fedora-fix-different-data-layouts.patch
      ppc-fedora-0002-Add-ppc64-trap-instructions.patch
      ppc-fedora-fix-ppc64-linux-syscalls-headers.patch
      ppc-fedora-use-sysconf-page-size-on-ppc64.patch
      ppc-fedora-0001-Enable-ppc64-pointer-compression.patch
      ppc-fedora-dawn-fix-ppc64le-detection.patch
      ppc-fedora-add-ppc64-architecture-to-extensions.diff
      ppc-fedora-fix-unknown-warning-option-messages.diff
      ppc-fedora-add-ppc64-pthread-stack-size.patch
      ppc-fedora-fix-ppc64-rust_png-build-error.patch
  - added patches
      ppc-chromium-136-clang-config.patch
  - disable swiftshader on ppc64le like on aarch64
* Wed May 07 2025 ro@suse.de
  - Chromium 136.0.7103.92
    (stable release 2025-05-06) (boo#1242717)
    * CVE-2025-4372: Use after free in WebAudio
* Fri May 02 2025 ro@suse.de
  - Chromium 136.0.7103.48
    (stable release 2025-04-29) (boo#1242153)
    * CVE-2025-4096: Heap buffer overflow in HTML
    * CVE-2025-4050: Out of bounds memory access in DevTools
    * CVE-2025-4051: Insufficient data validation in DevTools
    * CVE-2025-4052: Inappropriate implementation in DevTools
  - added patches:
    chromium-warning-suppression-mappings.patch
    (from upstream, revert for llvm < 20)
  - dropped patches:
    fix-build-with-pipewire-1.3.82.patch (upstream)
  - modified patches:
    chromium-125-compiler.patch (context)
    gtk-414.patch (one more place with GSK_SUBSURFACE_NODE)
  - bump esbuild from 0.24.0 to 0.25.1
    * Fix incorrect paths in inline source maps (#4070, #4075, #4105)
    * Fix invalid generated source maps (#4080, #4082, #4104, #4107)
    * Fix a regression with non-file source map paths (#4078)
    * Update Go from 1.23.5 to 1.23.7 (#4076, #4077)
* Wed Apr 23 2025 ro@suse.de
  - Chromium 135.0.7049.114
    (stable release 2025-04-22)
    * stability fixes
* Tue Apr 22 2025 ro@suse.de
  - add patch chromium-135-gperf-output.patch from upstream
    to fix compilation when using gperp-3.2 and above
    which resolved the issue with the FALLTHROUGH comment
* Wed Apr 16 2025 ro@suse.de
  - Chromium 135.0.7049.95
    (stable release 2025-04-15) (boo#1241288)
    * CVE-2025-3619: Heap buffer overflow in Codecs
    * CVE-2025-3620: Use after free in USB
* Thu Apr 10 2025 ro@suse.de
  - update chromium-121-rust-clang_lib.patch to apply cleanly
* Tue Apr 08 2025 ro@suse.de
  - Chromium 135.0.7049.84
    (stable release 2025-04-08) (boo#1240968)
    * CVE-2025-3066: Use after free in Site Isolation
* Fri Apr 04 2025 ro@suse.de
  - add patch chromium-135-add_map_droppable.patch
    add MAP_DROPPABLE introduced by recent QT
    (boo#1238826, boo#1239780)
* Tue Apr 01 2025 ro@suse.de
  - Chromium 135.0.7049.52
    (stable release 2025-04-01) (boo#1240555)
    * CVE-2025-3066: Use after free in Navigations
    * CVE-2025-3067: Inappropriate implementation in Custom Tabs
    * CVE-2025-3068: Inappropriate implementation in Intents
    * CVE-2025-3069: Inappropriate implementation in Extensions
    * CVE-2025-3070: Insufficient validation of untrusted input in Extensions
    * CVE-2025-3071: Inappropriate implementation in Navigations
    * CVE-2025-3072: Inappropriate implementation in Custom Tabs
    * CVE-2025-3073: Inappropriate implementation in Autofill
    * CVE-2025-3074: Inappropriate implementation in Downloads
  - modified patches:
    system-libdrm.patch (context update)
    gcc-enable-lto.patch (context update)
    chromium-127-constexpr.patch (context update)
    chromium-norar.patch (context update)
  - added patches:
    gtk-414.patch (reverse apply since our gtk4 is too old)
  - add to keeplibs:
    third_party/protobuf/third_party/utf8_range
  - drop from keeplibs:
    third_party/iccjpeg (gone upstream)
  - config variable changed from use_qt to use_qt5
  - bump buildrequires for gn to 0.20250306
* Wed Mar 26 2025 ro@suse.de
  - drop chromium-134-revert-allowlist.patch
    (obsolete, gn has been updated)
  - also use nodejs 22 for sle15
* Sat Mar 22 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 134.0.6998.165
    * stability fixes (boo#1240022)
* Fri Mar 21 2025 ro@suse.de
  - drop chromium-120-make_unique-struct.patch (not needed)
* Thu Mar 20 2025 ro@suse.de
  - Chromium 134.0.6998.117
    (stable released 2025-03-20) (boo#1239819)
    * CVE-2025-2476: Use after free in Lens
* Wed Mar 19 2025 ro@suse.de
  - use rust1.85
* Fri Mar 14 2025 ro@suse.de
  - drop chromium-94-ffmpeg-roll.patch
    (build fail after ffmpeg updated from 4.4 to 4.4.5 in code15)
* Tue Mar 11 2025 ro@suse.de
  - Chromium 134.0.6998.88
    (stable released 2025-03-11) (boo#1239216)
    * CVE-2025-1920: Type Confusion in V8
    * CVE-2025-2135: Type Confusion in V8
    * CVE-TBD: Out of bounds write in GPU
    * CVE-2025-2136: Use after free in Inspector
    * CVE-2025-2137: Out of bounds read in V8
* Wed Mar 05 2025 ro@suse.de
  - replace patch
    chromium-134-specialize-some-to_value_list.patch
    by patch
    chromium-134-type-mismatch-error.patch (from fedora)
* Thu Feb 27 2025 ro@suse.de
  - Chromium 134.0.6998.35
    (stable release 2025-03-04) (boo#1238575)
    * CVE-2025-1914: Out of bounds read in V8
    * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools
    * CVE-2025-1916: Use after free in Profiles
    * CVE-2025-1917: Inappropriate Implementation in Browser UI
    * CVE-2025-1918: Out of bounds read in PDFium
    * CVE-2025-1919: Out of bounds read in Media
    * CVE-2025-1921: Inappropriate Implementation in Media Stream
    * CVE-2025-1922: Inappropriate Implementation in Selection
    * CVE-2025-1923: Inappropriate Implementation in Permission Prompts
  - modified patches:
    fix_building_widevinecdm_with_chromium.patch
    (do not define WIDEVINE_CDM_VERSION_STRING, gone upstream)
    system-libdrm.patch (context update)
  - added patches:
    chromium-134-revert-allowlist.patch
    (avoid having to update gn on all targets)
    chromium-134-revert-rust-adler2.patch
    (revert rust change from adler to adler2 while we have 1.83)
    chromium-134-specialize-some-to_value_list.patch
  - dropped patches (llvm17 is gone):
    chromium-127-clang17-traitors.patch
    chromium-add-atomicops.patch
    chromium-133-string_view.patch
  - add to keeplibs:
    third_party/search_engines_data
    v8/third_party/rapidhash-v8
  - drop from keeplibs:
    third_party/libavif (gone) (FIXME cleanup)
  - reenable qt6 for TW
* Wed Feb 26 2025 ro@suse.de
  - Chromium 133.0.6943.141 (boo#1237699)
    This update includes 1 security fix.
    * Various fixes from internal audits, fuzzing and other initiatives
* Mon Feb 24 2025 ro@suse.de
  - fix build with qt6 and enable qt6 also for 15.x
  - added patches:
    chromium-131-fix-qt-ui.pach (from fedora)
* Wed Feb 19 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 133.0.6943.126 (boo#1237343)
    * CVE-2025-0999: Heap buffer overflow in V8
    * CVE-2025-1426: Heap buffer overflow in GPU
    * CVE-2025-1006: Use after free in Network
* Tue Feb 18 2025 ro@suse.de
  - replace "with qt" by "with qt5"
  - add patch chromium-133-bring_back_and_disable_allowlist.patch
    trying to fix issues with YT playback (bsc#1237071)
* Fri Feb 14 2025 Antonio Larrosa <alarrosa@suse.com>
  - Fix patch to actually fix build with pipewire 1.3.82:
    * fix-build-with-pipewire-1.3.82.patch
* Thu Feb 13 2025 Antonio Larrosa <alarrosa@suse.com>
  - Add patch to fix build with pipewire 1.3.82:
    * fix-build-with-pipewire-1.3.82.patch
* Thu Feb 13 2025 ro@suse.de
  - Chromium 133.0.6943.98
    (stable released 2025-02-12) (bsc#1237121)
    * CVE-2025-0995: Use after free in V8
    * CVE-2025-0996: Inappropriate implementation in Browser UI
    * CVE-2025-0997: Use after free in Navigation
    * CVE-2025-0998: Out of bounds memory access in V8
* Wed Feb 05 2025 ro@suse.de
  - Chromium 133.0.6943.53
    (stable released 2024-02-04) (bsc#1236806)
    * CVE-2025-0444: Use after free in Skia
    * CVE-2025-0445: Use after free in V8
    * CVE-2025-0451: Inappropriate implementation in Extensions API
* Thu Jan 30 2025 ro@suse.de
  - dropped patches: (obsolete with recent llvm)
    chromium-130-no-hardware_destructive_interference_size.patch
* Thu Jan 30 2025 ro@suse.de
  - Chromium 133.0.6943.35
    (beta released 2025-01-29)
  - use llvm19 also on 15.6/SLE-15-SP6
  - dropped patches:
    chromium-125-disable-FFmpegAllowLists.patch
    chromium-119-assert.patch
    (code dropped upstream)
  - modified patches
    chromium-129-revert-AVFMT_FLAG_NOH264PARSE.patch
    (rest of code is gone upstream, see commit
    574c1e6678da435efb2ea9dba5dd890c2704b8af)
  - update context in
    chromium-102-regex_pattern-array.patch
    chromium-125-ffmpeg-5.x-reordered_opaque.patch
  - add to keeplibs:
    third_party/simdutf
    third_party/wasm_tts_engine (needed by tools/grit)
    v8/third_party/siphash (moved inside of v8)
    v8/third_party/utf8-decoder (moved inside of v8)
    v8/third_party/valgrind (moved inside of v8)
  - drop from keeplibs (gone in source):
    third_party/jstemplate does not exist
    third_party/qcms does not exist
  - drop buildreq for libevent and libevent from system libs
    as the lib was dropped upstream
  - added patches (as revert for llvm17 in sp6):
    chromium-add-atomicops.patch
    (upstream commit d29b01737a841b5627249d50f007dcdc7e26462b)
    (upstream commit 780efe38034cfdc1bdf4c74e82e7ca7c14e8ac5b
    does not seem to be in 133 yet)
    chromium-133-string_view.patch
    (one more place to use string_view, also only llvm17)
  - update INSTALL.sh to generate appdata.xml from template
* Thu Jan 30 2025 ro@suse.de
  - drop chromium-132-old_libdrm.patch
    obsolete as we are not building for 15.5 anymore
* Wed Jan 29 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 132.0.6834.159 (boo#1236586)
    * CVE-2025-0762: Use after free in DevTools
* Thu Jan 23 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 132.0.6834.110 (boo#1236306)
    * CVE-2025-0611: Object corruption in V8
    * CVE-2025-0612: Out of bounds memory access in V8
* Mon Jan 13 2025 ro@suse.de
  - Chromium 132.0.6834.83
    (stable released 2024-01-14) (bsc#1235892)
    * CVE-2025-0434: Out of bounds memory access in V8
    * CVE-2025-0435: Inappropriate implementation in Navigation
    * CVE-2025-0436: Integer overflow in Skia
    * CVE-2025-0437: Out of bounds read in Metrics
    * CVE-2025-0438: Stack buffer overflow in Tracing
    * CVE-2025-0439: Race in Frames
    * CVE-2025-0440: Inappropriate implementation in Fullscreen
    * CVE-2025-0441: Inappropriate implementation in Fenced Frames
    * CVE-2025-0442: Inappropriate implementation in Payments
    * CVE-2025-0443: Insufficient data validation in Extensions
    * CVE-2025-0446: Inappropriate implementation in Extensions
    * CVE-2025-0447: Inappropriate implementation in Navigation
    * CVE-2025-0448: Inappropriate implementation in Compositing
  - dropped patches:
    * chromium-131-unbundle-enable-freetype.patch (upstream)
  - added patches:
    * chromium-8d882c289f17e3a67d6d67d5ff7e9d16ebb4f19a.patch
      (apply git upstream reverse for 15.x with llvm17)
    * chromium-93-ffmpeg-4.4-rest.patch
      (split off to only apply after the reverse)
    * chromium-132-old_libdrm.patch
      (applied only on 15.5 with libdrm < 2.4.116)
    * chromium-132-pdfium-explicit-template.patch
      (error: alias template requires template arguments)
  - update context in
    * chromium-125-compiler.patch
    * chromium-127-rust-clanglib.patch
    * Cr122-ffmpeg-new-channel-layout.patch
    * gcc-enable-lto.patch
    * chromium-127-constexpr.patch
  - update esbuild to 0.24.0
    - drop old tarball
    - use upstream release tarball for 0.24.0
    - add vendor tarball for golang.org/x/sys
  - add to keeplibs:
    third_party/libtess2
    third_party/devtools-frontend/src/node_modules/fast-glob
* Fri Jan 10 2025 ro@suse.de
  - more work on 15.7/15-SP7 using recent llvm,rust,gcc
  - cleanup use of suse_version macro
  - cleanup use of conditionally applied patches, switch from
    autoset to setup/autopatch which allows to specify a range
    and apply remaining patches conditionally
* Wed Jan 08 2025 ro@suse.de
  - Chromium 131.0.6778.264 (boo#1235422)
    * CVE-2025-0291: Type Confusion in V8
    * Various fixes from internal audits, fuzzing and other initiatives
* Thu Dec 19 2024 ro@suse.de
  - Chromium 131.0.6778.204 (boo#1234704)
    * CVE-2024-12692: Type Confusion in V8
    * CVE-2024-12693: Out of bounds memory access in V8
    * CVE-2024-12694: Use after free in Compositing
    * CVE-2024-12695: Out of bounds write in V8
    * Various fixes from internal audits, fuzzing and other initiatives
* Wed Dec 11 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 131.0.6778.139 (boo#1234361)
    * CVE-2024-12381: Type Confusion in V8
    * CVE-2024-12382: Use after free in Translate
    * Various fixes from internal audits, fuzzing and other initiatives
* Wed Dec 04 2024 ro@suse.de
  - Chromium 131.0.6778.108
    (stable released 2024-12-04) (boo#1234118)
    * CVE-2024-12053: Type Confusion in V8
  - update patches:
    chromium-127-constexpr.patch
* Wed Nov 20 2024 ro@suse.de
  - Chromium 131.0.6778.85
    (stable released 2024-11-19) (boo#1233534)
    * CVE-2024-11395: Type Confusion in V8
* Wed Nov 06 2024 ro@suse.de
  - Chromium 131.0.6778.69
    (stable released 2024-11-12) (boo#1233311)
    * CVE-2024-11110: Inappropriate implementation in Blink.
    * CVE-2024-11111: Inappropriate implementation in Autofill.
    * CVE-2024-11112: Use after free in Media.
      (n/a for linux)
    * CVE-2024-11113: Use after free in Accessibility.
    * CVE-2024-11114: Inappropriate implementation in Views.
      (n/a for linux)
    * CVE-2024-11115: Insufficient policy enforcement in Navigation.
      (n/a for linux)
    * CVE-2024-11116: Inappropriate implementation in Paint.
    * CVE-2024-11117: Inappropriate implementation in FileSystem.
  - dropped patches:
    * chromium-130-missing-includes.patch (upstream)
    * chromium-125-lp155-typename.patch (not required with llvm)
  - modified patches:
    * chromium-127-bindgen.patch (drop all allowlist changes)
    * chromium-127-constexpr.patch (update from debian patch)
  - added patches:
    * chromium-131-unbundle-enable-freetype.patch
      from git, missing in 131 release
    * chromium-131-clang-stack-protector.patch
      (partial revert of upstream commit
      c3dadb02f611a360fb40fd8844ed3c1ef1e7834e)
  - drop from keeplibs: (deleted upstream)
    third_party/devtools-frontend/src/front_end/third_party/lodash-isequal
  - add to keeplibs:
    third_party/tflite/src/third_party/xla/xla/tsl (drop subdirs)
    third_party/ink
* Tue Nov 05 2024 ro@suse.de
  - Chromium 130.0.6723.116 (boo#1232843)
    * CVE-2024-10826: Use after free in Family Experiences
    * CVE-2024-10827: Use after free in Serial
* Wed Oct 30 2024 ro@suse.de
  - Chromium 130.0.6723.91 (boo#1232566)
    * CVE-2024-10487: Out of bounds write in Dawn
    * CVE-2024-10488: Use after free in WebRTC
* Mon Oct 28 2024 ro@suse.de
  - change BR for rust to require version 1.81
    (1.82 uses a newer llvm)
* Sat Oct 26 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 130.0.6723.69 (boo#1232060)
    * CVE-2024-10229: Inappropriate implementation in Extensions
    * CVE-2024-10230: Type Confusion in V8
    * CVE-2024-10231: Type Confusion in V8
* Sat Oct 12 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 130.0.6723.58 (boo#1231694)
    * CVE-2024-9954: Use after free in AI
    * CVE-2024-9955: Use after free in Web Authentication
    * CVE-2024-9956: Inappropriate implementation in Web Authentication
    * CVE-2024-9957: Use after free in UI
    * CVE-2024-9958: Inappropriate implementation in PictureInPicture
    * CVE-2024-9959: Use after free in DevTools
    * CVE-2024-9960: Use after free in Dawn
    * CVE-2024-9961: Use after free in Parcel Tracking
    * CVE-2024-9962: Inappropriate implementation in Permissions
    * CVE-2024-9963: Insufficient data validation in Downloads
    * CVE-2024-9964: Inappropriate implementation in Payments
    * CVE-2024-9965: Insufficient data validation in DevTools
    * CVE-2024-9966: Inappropriate implementation in Navigations
  - modified patches:
    * exclude_ymp.patch update context
    * chromium-125-compiler.patch update context
    * chromium-125-lp155-typename.patch drop hunks for rewritten
      proto_fetcher.h
    * chromium-127-bindgen.patch update context
  - added patches:
    * chromium-130-missing-includes.patch include optional, stack
    * chromium-130-no-hardware_destructive_interference_size.patch
      workaround for older libcpp
  - drop from keeplibs:
    courgette/third_party dropped upstream
  - add to keepllibs:
    third_party/fast_float needed by v8/src/numbers/conversion.cc
* Sat Oct 12 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 129.0.6668.100 (boo#1231420)
    * CVE-2024-9602: Type Confusion in V8
    * CVE-2024-9603: Type Confusion in V8
* Wed Oct 02 2024 ro@suse.de
  - Chromium 129.0.6668.89 (stable released 2024-09-24)
    (boo#1231232)
    * CVE-2024-7025: Integer overflow in Layout
    * CVE-2024-9369: Insufficient data validation in Mojo
    * CVE-2024-9370: Inappropriate implementation in V8
* Wed Sep 25 2024 ro@suse.de
  - Chromium 129.0.6668.70 (stable released 2024-09-24)
    (boo#1230964)
    * CVE-2024-9120: Use after free in Dawn
    * CVE-2024-9121: Inappropriate implementation in V8
    * CVE-2024-9122: Type Confusion in V8
    * CVE-2024-9123: Integer overflow in Skia
* Thu Sep 19 2024 ro@suse.de
  - bump BR for nodejs to minimal 20.0
  - dropped patches:
    * chromium-disable-GlobalMediaControlsCastStartStop.patch
      it was applied at the wrong place and the crash is gone
* Wed Sep 18 2024 ro@suse.de
  - Chromium 129.0.6668.58 (stable released 2024-09-17)
    (boo#1230678)
    * CVE-2024-8904: Type Confusion in V8
    * CVE-2024-8905: Inappropriate implementation in V8
    * CVE-2024-8906: Incorrect security UI in Downloads
    * CVE-2024-8907: Insufficient data validation in Omnibox
    * CVE-2024-8908: Inappropriate implementation in Autofill
    * CVE-2024-8909: Inappropriate implementation in UI
  - modified patches:
    * chromium-prop-codecs.patch update context
  - add to keeplibs:
    third_party/rapidhash
  - drop from keeplibs:
    third_party/libudev dropped upstream
    third_party/catapult/third_party/html5lib-python dropped upstream
  - add patches:
    chromium-129-revert-AVFMT_FLAG_NOH264PARSE.patch
    (not in our ffmpeg yet)
* Wed Sep 11 2024 ro@suse.de
  - Chromium 128.0.6613.137 (released 2024-09-10) (boo#1230391)
    * CVE-2024-8636: Heap buffer overflow in Skia
    * CVE-2024-8637: Use after free in Media Router
    * CVE-2024-8638: Type Confusion in V8
    * CVE-2024-8639: Use after free in Autofill
* Tue Sep 03 2024 ro@suse.de
  - Chromium 128.0.6613.119 (released 2024-09-02) (boo#1230108)
    * CVE-2024-8362: Use after free in WebAudio
    * CVE-2024-7970: Out of bounds write in V8
* Thu Aug 29 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 128.0.6613.113 (boo#1229897)
    * CVE-2024-7969: Type Confusion in V8
    * CVE-2024-8193: Heap buffer overflow in Skia
    * CVE-2024-8194: Type Confusion in V8
    * CVE-2024-8198: Heap buffer overflow in Skia
* Wed Aug 21 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 128.0.6613.84 (boo#1229591)
    * CVE-2024-7964: Use after free in Passwords
    * CVE-2024-7965: Inappropriate implementation in V8
    * CVE-2024-7966: Out of bounds memory access in Skia
    * CVE-2024-7967: Heap buffer overflow in Fonts
    * CVE-2024-7968: Use after free in Autofill
    * CVE-2024-7969: Type Confusion in V8
    * CVE-2024-7971: Type confusion in V8
    * CVE-2024-7972: Inappropriate implementation in V8
    * CVE-2024-7973: Heap buffer overflow in PDFium
    * CVE-2024-7974: Insufficient data validation in V8 API
    * CVE-2024-7975: Inappropriate implementation in Permissions
    * CVE-2024-7976: Inappropriate implementation in FedCM
    * CVE-2024-7977: Insufficient data validation in Installer
    * CVE-2024-7978: Insufficient policy enforcement in Data Transfer
    * CVE-2024-7979: Insufficient data validation in Installer
    * CVE-2024-7980: Insufficient data validation in Installer
    * CVE-2024-7981: Inappropriate implementation in Views
    * CVE-2024-8033: Inappropriate implementation in WebApp Installs
    * CVE-2024-8034: Inappropriate implementation in Custom Tabs
    * CVE-2024-8035: Inappropriate implementation in Extensions
    * Various fixes from internal audits, fuzzing and other initiatives
* Sun Aug 18 2024 ro@suse.de
  - Chromium 128.0.6613.36 (boo#1229426)
  - modified patches:
    * chromium-norar.patch drop most hunks,
      upstream has a config for this now
    * gcc-enable-lto.patch update context
    * chromium-125-compiler.patch update context
    * chromium-127-constexpr.patch update context
  - drop patches: (should be obsolete with llvm>17 and libc++)
    chromium-120-emplace.patch
    chromium-125-emplace-struct.patch
  - drop patches: (upstream)
    * chromium-121-nullptr_t-without-namespace-std.patch
    * chromium-123-stats-collector.patch
    * chromium-127-paint-layer-header.patch
    * chromium-127-ninja-1.21.1-deps-part0.patch
    * chromium-127-ninja-1.21.1-deps-part1.patch
    * chromium-127-ninja-1.21.1-deps-part2.patch
    * chromium-127-ninja-1.21.1-deps-part3.patch
  - disable rpmlint only for factory/tw where it is broken because
    of the large archive size of the source here
  - keeplibs add
    third_party/devtools-frontend/src/front_end/third_party/
    puppeteer/package/lib/esm/third_party/parsel-js
    third_party/tflite/src/third_party/xla/xla/tsl/framework
  - buildflags add
    safe_browsing_use_unrar=false
* Thu Aug 15 2024 ro@suse.de
  - Chromium 127.0.6533.119 (boo#1228941)
    * CVE-2024-7532: Out of bounds memory access in ANGLE
    * CVE-2024-7533: Use after free in Sharing
    * CVE-2024-7550: Type Confusion in V8
    * CVE-2024-7534: Heap buffer overflow in Layout
    * CVE-2024-7535: Inappropriate implementation in V8
    * CVE-2024-7536: Use after free in WebAudio
* Thu Aug 01 2024 ro@suse.de
  - Chromium 127.0.6533.88 (boo#1228628, boo#1228940, boo#1228942)
    * CVE-2024-6988: Use after free in Downloads
    * CVE-2024-6989: Use after free in Loader
    * CVE-2024-6991: Use after free in Dawn
    * CVE-2024-6992: Out of bounds memory access in ANGLE
    * CVE-2024-6993: Inappropriate implementation in Canvas
    * CVE-2024-6994: Heap buffer overflow in Layout
    * CVE-2024-6995: Inappropriate implementation in Fullscreen
    * CVE-2024-6996: Race in Frames
    * CVE-2024-6997: Use after free in Tabs
    * CVE-2024-6998: Use after free in User Education
    * CVE-2024-6999: Inappropriate implementation in FedCM
    * CVE-2024-7000: Use after free in CSS
    * CVE-2024-7001: Inappropriate implementation in HTML
    * CVE-2024-7003: Inappropriate implementation in FedCM
    * CVE-2024-7004: Insufficient validation of untrusted input
      in Safe Browsing
    * CVE-2024-7005: Insufficient validation of untrusted input
      in Safe Browsing
    * CVE-2024-6990: Uninitialized Use in Dawn
    * CVE-2024-7255: Out of bounds read in WebTransport
    * CVE-2024-7256: Insufficient data validation in Dawn
  - drop patches:
    * chromium-115-compiler-SkColor4f.patch only for llvm < 16
    * chromium-117-system-zstd.patch upstreamed
    * chromium-122-workaround_clang_bug-structured_binding.patch
    * chromium-125-tabstrip-include.patch upstreamed
    * chromium-126-missing-header-files.patch
    * chromium-126-RealTimeReportingBindings-missing-decl.patch
      upstreamed
    * chromium-126-no_matching_constructor.patch
    * chromium-126-no-format.patch upstreamed
  - switch from libstdc++ to libc++
  - drop patches obsolete when using libc++
    * chromium-126-debian-bad-font-gc00000.patch
    * chromium-126-debian-bad-font-gc2.patch
    * chromium-126-debian-bad-font-gc1.patch
    * chromium-126-debian-bad-font-gc00.patch
    * chromium-126-debian-bad-font-gc000.patch
    * chromium-126-debian-bad-font-gc11.patch
    * chromium-126-debian-bad-font-gc0.patch
    * chromium-126-debian-bad-font-gc0000.patch
    * chromium-126-debian-bad-font-gc3.patch
  - modify patches:
    * chromium-125-lp155-typename.patch
    - drop hunk in model_execution_util.h
    - drop hunk in model_quality_log_entry.h
  - dropping from keeplibs: (does not exist)
    base/third_party/valgrind
    third_party/maldoca
    third_party/maldoca/src/third_party
  - requires updated gn to build (newer than Feb 14 2024)
  - add patches:
    * chromium-127-bindgen.patch (from debian/patches/fixes))
    * chromium-127-rust-clanglib.patch (just first hunk from fedora)
    * chromium-127-clang17-traitors.patch
      workaround for clang < 18 from debiana (only used on 15.6)
    * chromium-127-constexpr.patch (from debian/patches/bookworm)
    * chromium-127-paint-layer-header.patch (from debian/patches/upstream)
    * chromium-127-ninja-1.21.1-deps-part0.patch (from fedora)
    * chromium-127-ninja-1.21.1-deps-part1.patch (from fedora)
    * chromium-127-ninja-1.21.1-deps-part2.patch (from fedora)
    * chromium-127-ninja-1.21.1-deps-part3.patch (from fedora)
  - buildrequire rust-bindgen to get proper binaries per arch
  - use qt5 for factory as well, qt6 fails with:
    ld.lld: error: undefined symbol: QByteArray::toStdString() const
    referenced by qt_shim.cc
    obj/ui/qt/qt6_shim/libqt6_shim.so.lto.qt_shim.o:(qt::QtShim::GetFontDescription() const)
  - drop patches:
    * chromium-125-debian-bad-font-gc11.patch
    * chromium-125-debian-bad-font-gc0000.patch
    * chromium-125-debian-bad-font-gc00.patch
    * chromium-125-debian-bad-font-gc0.patch
    * chromium-125-debian-bad-font-gc000.patch
    * chromium-125-debian-bad-font-gc1.patch
* Wed Jul 17 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 126.0.6478.182 (boo#1227979)
    * CVE-2024-6772: Inappropriate implementation in V8
    * CVE-2024-6773: Type Confusion in V8
    * CVE-2024-6774: Use after free in Screen Capture
    * CVE-2024-6775: Use after free in Media Stream
    * CVE-2024-6776: Use after free in Audio
    * CVE-2024-6777: Use after free in Navigation
    * CVE-2024-6778: Race in DevTools
    * CVE-2024-6779: Out of bounds memory access in V8
* Tue Jul 09 2024 Callum Farmer <gmbr3@opensuse.org>
  - Finalize 126
  - Removed patches:
    * chromium-125-debian-bad-font-gc2.patch
    * chromium-125-debian-bad-font-gc3.patch
  - Added patches:
    * chromium-126-RealTimeReportingBindings-missing-decl.patch
    * chromium-126-no-format.patch
* Mon Jul 01 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 126.0.6478.126 (boo#1226504, boo#1226205, boo#1226933)
    * CVE-2024-6290: Use after free in Dawn
    * CVE-2024-6291: Use after free in Swiftshader
    * CVE-2024-6292: Use after free in Dawn
    * CVE-2024-6293: Use after free in Dawn
    * CVE-2024-6100: Type Confusion in V8
    * CVE-2024-6101: Inappropriate implementation in WebAssembly
    * CVE-2024-6102: Out of bounds memory access in Dawn
    * CVE-2024-6103: Use after free in Dawn
    * CVE-2024-5830: Type Confusion in V8
    * CVE-2024-5831: Use after free in Dawn
    * CVE-2024-5832: Use after free in Dawn
    * CVE-2024-5833: Type Confusion in V8
    * CVE-2024-5834: Inappropriate implementation in Dawn
    * CVE-2024-5835: Heap buffer overflow in Tab Groups
    * CVE-2024-5836: Inappropriate Implementation in DevTools
    * CVE-2024-5837: Type Confusion in V8
    * CVE-2024-5838: Type Confusion in V8
    * CVE-2024-5839: Inappropriate Implementation in Memory Allocator
    * CVE-2024-5840: Policy Bypass in CORS
    * CVE-2024-5841: Use after free in V8
    * CVE-2024-5842: Use after free in Browser UI
    * CVE-2024-5843: Inappropriate implementation in Downloads
    * CVE-2024-5844: Heap buffer overflow in Tab Strip
    * CVE-2024-5845: Use after free in Audio
    * CVE-2024-5846: Use after free in PDFium
    * CVE-2024-5847: Use after free in PDFium
  - drop patches:
    * chromium-disable-parallel-gold.patch
    * chromium-125-appservice-include.patch
    * chromium-125-lens-include.patch
    * chromium-125-mojo-bindings-include.patch
    * chromium-125-no-vector-consts.patch
    * chromium-125-vulkan-include.patch
    * chromium-125-ninja.patch
    * chromium-125-no_matching_constructor.patch
    * chromium-125-missing-header-files.patch
  - add patches:
    * chromium-126-missing-header-files.patch
    * chromium-126-quiche-interator.patch
    * chromium-126-no_matching_constructor.patch
* Wed Jun 12 2024 Callum Farmer <gmbr3@opensuse.org>
  - Amend fix_building_widevinecdm_with_chromium.patch to allow
    Widevine on ARM64 (bsc#1226170)
* Fri May 31 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 125.0.6422.141 (boo#1225690)
    * CVE-2024-5493: Heap buffer overflow in WebRTC
    * CVE-2024-5494: Use after free in Dawn
    * CVE-2024-5495: Use after free in Dawn
    * CVE-2024-5496: Use after free in Media Session
    * CVE-2024-5497: Out of bounds memory access in Keyboard Inputs
    * CVE-2024-5498: Use after free in Presentation API
    * CVE-2024-5499: Out of bounds write in Streams API
* Fri May 24 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 125.0.6422.112
    * CVE-2024-5274: Type Confusion in V8 (boo#1225199)
* Tue May 21 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 125.0.6422.76 (boo#1224818)
    * CVE-2024-5157: Use after free in Scheduling
    * CVE-2024-5158: Type Confusion in V8
    * CVE-2024-5159: Heap buffer overflow in ANGLE
    * CVE-2024-5160: Heap buffer overflow in Dawn
    * Various fixes from internal audits, fuzzing and other initiatives
* Thu May 16 2024 ro@suse.de
  - Chromium 125.0.6422.60 (boo#1224341)
    * CVE-2024-4947: Type Confusion in V8
    * CVE-2024-4948: Use after free in Dawn
    * CVE-2024-4949: Use after free in V8
    * CVE-2024-4950: Inappropriate implementation in Downloads
  - Chromium 125.0.6422.41
    * New upstream (early) stable release.
  - drop upstreamed patches:
    * chromium-124-uint-includes.patch
    * chromium-124-fps-optional.patch
    * chromium-124-span-optional.patch
    * chromium-124-extractor-bitset.patch
    * chromium-124-atomic.patch
    * chromium-124-webgpu-optional.patch
    * chromium-124-angle-powf.patch
  - add debian upstream patches added for 125:
    * chromium-125-appservice-include.patch
    * chromium-125-lens-include.patch
    * chromium-125-mojo-bindings-include.patch
    * chromium-125-no-vector-consts.patch
    * chromium-125-vulkan-include.patch
    * chromium-125-tabstrip-include.patch
    * chromium-125-ninja.patch
  - add debian fixes patches to fix font gc crashes:
    * chromium-125-debian-bad-font-gc0000.patch
    * chromium-125-debian-bad-font-gc000.patch
    * chromium-125-debian-bad-font-gc00.patch
    * chromium-125-debian-bad-font-gc0.patch
    * chromium-125-debian-bad-font-gc11.patch
    * chromium-125-debian-bad-font-gc1.patch
    * chromium-125-debian-bad-font-gc2.patch
    * chromium-125-debian-bad-font-gc3.patch
  - add from fedora (reverse applied for older ffmpeg):
    * chromium-125-ffmpeg-5.x-reordered_opaque.patch
  - re-diff and rename:
    * from chromium-110-compiler.patch
      to chromium-125-compiler.patch
    * from chromium-120-emplace-struct.patch
      to chromium-125-emplace-struct.patch
    * from chromium-disable-FFmpegAllowLists.patch
      to chromium-125-disable-FFmpegAllowLists.patch
    * from chromium-122-missing-header-files.patch
      to chromium-125-missing-header-files.patch
    * from chromium-122-no_matching_constructor.patch
      to chromium-125-no_matching_constructor.patch
    * from chromium-122-lp155-typename.patch
      to chromium-125-lp155-typename.patch
  - third_party/zstd
    added to keeplibs for
    third_party/blink/renderer/platform:platform
  - third_party/tflite/src/third_party/xla/xla/tsl/util
    added to keeplibs for
    third_party/tflite/tflite
  - third_party/lens_server_proto
    added to keeplibs for
    gen/third_party/lens_server_proto
* Tue May 14 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 124.0.6367.207 (boo#1224294)
    * CVE-2024-4761: Out of bounds write in V8
* Fri May 10 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 124.0.6367.201 (boo#1224208)
    * CVE-2024-4671: Use after free in Visuals
  - Chromium 124.0.6367.155 (boo#1224045)
    * CVE-2024-4558: Use after free in ANGLE
    * CVE-2024-4559: Heap buffer overflow in WebAudio
* Fri May 03 2024 ro@suse.de
  - drop patches:
    * chromium-123-WebUI-static_assert.patch
* Thu May 02 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 124.0.6367.118 (boo#1223846)
    * CVE-2024-4331: Use after free in Picture In Picture
    * CVE-2024-4368: Use after free in Dawn
* Wed May 01 2024 Callum Farmer <gmbr3@opensuse.org>
  - Add patches:
    * chromium-123-missing-QtGui.patch
  - Restore libxml 2.12 check for chromium-124-system-libxml.patch
    which replaced chromium-121-blink-libxml-const.patch
* Fri Apr 26 2024 ro@suse.de
  - Chromium 124.0.6367.78 (boo#1223845)
    * CVE-2024-4058: Type Confusion in ANGLE
    * CVE-2024-4059: Out of bounds read in V8 API
    * CVE-2024-4060: Use after free in Dawn
* Wed Apr 17 2024 ro@suse.de
  - Chromium 124.0.6367.60 (boo#1222958)
    * CVE-2024-3832: Object corruption in V8.
    * CVE-2024-3833: Object corruption in WebAssembly.
    * CVE-2024-3834: Use after free in Downloads
    * CVE-2024-3837: Use after free in QUIC.
    * CVE-2024-3838: Inappropriate implementation in Autofill.
    * CVE-2024-3839: Out of bounds read in Fonts.
    * CVE-2024-3840: Insufficient policy enforcement in Site Isolation.
    * CVE-2024-3841: Insufficient data validation in Browser Switcher.
    * CVE-2024-3843: Insufficient data validation in Downloads.
    * CVE-2024-3844: Inappropriate implementation in Extensions.
    * CVE-2024-3845: Inappropriate implementation in Network.
    * CVE-2024-3846: Inappropriate implementation in Prompts.
    * CVE-2024-3847: Insufficient policy enforcement in WebUI.
  - drop patches:
    * chromium-123-optional2.patch
    * chromium-122-avoid-SFINAE-TypeConverter.patch
    * chromium-123-PA-InternalAllocator.patch
  - rediff patches:
    * chromium-110-compiler.patch
    * chromium-120-emplace.patch
    * chromium-122-no_matching_constructor.patch
    * chromium-122-lp155-typename.patch
  - add patches: from debian/fixes
    * chromium-123-stats-collector.patch
  - add patches: from debian/upstream
    * chromium-124-angle-powf.patch
    * chromium-124-atomic.patch
    * chromium-124-extractor-bitset.patch
    * chromium-124-fps-optional.patch
    * chromium-124-span-optional.patch
    * chromium-124-uint-includes.patch
    * chromium-124-webgpu-optional.patch
  - add patches:
    * chromium-123-WebUI-static_assert.patch
      workaround for compile issue in webui_contents_wrapper.h
    * chromium-124-system-libxml.patch (from fedora)
* Sun Apr 14 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 123.0.6312.122 (boo#1222707)
    * CVE-2024-3157: Out of bounds write in Compositing
    * CVE-2024-3516: Heap buffer overflow in ANGLE
    * CVE-2024-3515: Use after free in Dawn
  - Chromium 123.0.6312.105 (boo#1222260)
    * CVE-2024-3156: Inappropriate implementation in V8
    * CVE-2024-3158: Use after free in Bookmarks
    * CVE-2024-3159: Out of bounds memory access in V8
  - Chromium 123.0.6312.86 (boo#1222035)
    * CVE-2024-2883: Use after free in ANGLE
    * CVE-2024-2885: Use after free in Dawn
    * CVE-2024-2886: Use after free in WebCodecs
    * CVE-2024-2887: Type Confusion in WebAssembly
  - Chromium 123.0.6312.58 (boo#1221732)
    * CVE-2024-2625: Object lifecycle issue in V8
    * CVE-2024-2626: Out of bounds read in Swiftshader
    * CVE-2024-2627: Use after free in Canvas
    * CVE-2024-2628: Inappropriate implementation in Downloads
  - drop patches:
    * chromium-117-blink-BUILD-mnemonic.patch
    * chromium-121-blink-libxml-const.patch
    * chromium-122-BookmarkNode-missing-operator.patch
    * chromium-122-WebUI-static_assert.patch
    * chromium-122-PA-undo-internal-alloc.patch
* Mon Mar 18 2024 Callum Farmer <gmbr3@opensuse.org>
  - Use Python 3.11 on Leap
  - Rename chromium-122-skip_bubble_contents_wrapper_static_assert.patch
    to chromium-122-WebUI-static_assert.patch
  - Rename chromium-122-disable-FFmpegAllowLists.patch to
    chromium-disable-FFmpegAllowLists.patch
  - Rename chromium-122-static-assert.patch to
    chromium-122-BookmarkNode-missing-operator.patch
  - Rename chromium-122-undo-internal-alloc.patch to
    chromium-122-PA-undo-internal-alloc.patch
  - Rename chromium-122-typename.patch to
    chromium-122-lp155-typename.patch
  - Removed patches:
    * chromium-121-v8-c++20-p1.patch
    * chromium-121-v8-c++20.patch
    * chromium-122-unique_ptr.patch
    * chromium-122-python3-assignment-expressions.patch
    * chromium-122-el8-support-64kpage.patch
    * chromium-122-el7-inline-function.patch
    * chromium-122-el7-extra-operator.patch
    * chromium-122-el7-default-constructor-involving-anonymous-union.patch
    * chromium-122-constexpr.patch
    * chromium-122-clang-build-flags.patch
    * chromium-122-clang16-disable-auto-upgrade-debug-info.patch
    * chromium-122-clang16-buildflags.patch
    * chromium-122-arm64-memory_tagging.patch
    * chromium-121-el7-clang-version-warning.patch
    * chromium-116-lp155-url_load_stats-size-t.patch
    * chromium-icu72-2.patch
    * chromium-122-debian-upstream-mojo.patch
  - Patches merged into other patches:
    * chromium-122-debian-upstream-bitset.patch
    * chromium-122-debian-upstream-optional.patch
    * chromium-122-debian-upstream-uniqptr.patch
    * chromium-122-debian-fixes-optional.patch
    * chromium-122-norar.patch
  - Restore time clamper change to
    chromium-122-missing-header-files.patch
  - Fix missing/invalid casting in
    chromium-122-no_matching_constructor.patch
* Wed Mar 13 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 122.0.6261.128 (boo#1221335)
    * CVE-2024-2400: Use after free in Performance Manager
* Fri Mar 08 2024 ro@suse.de
  - Chromium 122.0.6261.111 (boo#1220131,boo#1220604,boo#1221105)
    * New upstream security release.
    * CVE-2024-2173: Out of bounds memory access in V8.
    * CVE-2024-2174: Inappropriate implementation in V8.
    * CVE-2024-2176: Use after free in FedCM.
  - Chromium 122.0.6261.94
    * CVE-2024-1669: Out of bounds memory access in Blink.
    * CVE-2024-1670: Use after free in Mojo.
    * CVE-2024-1671: Inappropriate implementation in Site Isolation.
    * CVE-2024-1672: Inappropriate implementation in Content Security Policy.
    * CVE-2024-1673: Use after free in Accessibility.
    * CVE-2024-1674: Inappropriate implementation in Navigation.
    * CVE-2024-1675: Insufficient policy enforcement in Download.
    * CVE-2024-1676: Inappropriate implementation in Navigation.
    * Type Confusion in V8
    * rediff chromium-disable-GlobalMediaControlsCastStartStop.patch
    * drop chromium-114-lld-argument.patch
      replaced by chromium-122-clang16-disable-auto-upgrade-debug-info.patch
    * drop chromium-121-no_matching_constructor.patch
      replaced by chromium-122-no_matching_constructor.patch
    * drop chromium-113-webview-namespace.patch (obsolete)
    * reduce chromium-norar.patch
      by the hunks in chromium-122-norar.patch
    * drop chromium-114-revert-av1enc-lp154.patch
      replaced by chromium-122-revert-av1enc-el9.patch
    * drop chromium-115-lp155-typename.patch
      chromium-116-lp155-typenames.patch
      chromium-117-lp155-typename.patch
      chromium-120-lp155-typename.patch
      replaced by chromium-122-typename.patch
    * drop chromium-121-missing-header-files.patch
      replaced by chromium-122-missing-header-files.patch
    * drop chromium-121-workaround_clang_bug-structured_binding.patch
      replaced by chromium-122-workaround_clang_bug-structured_binding.patch
    * drop chromium-121-no_matching_constructor.patch
      replaced by chromium-122-no_matching_constructor.patch
    * drop chromium-121-python3-invalid-escape-sequence.patch (upstream)
    * drop chromium-disable-FFmpegAllowLists.patch
      replaced by chromium-122-disable-FFmpegAllowLists.patch
    * drop chromium-121-avoid-SFINAE-TypeConverter.patch
      replaced by chromium-122-avoid-SFINAE-TypeConverter.patch
    * add buildrequires for rust
    * add patches from fedora package for 121 and 122
    * chromium-121-el7-clang-version-warning.patch
    * chromium-121-v8-c++20-p1.patch
    * chromium-121-v8-c++20.patch
    * chromium-122-arm64-memory_tagging.patch
    * chromium-122-clang16-buildflags.patch
    * chromium-122-clang16-disable-auto-upgrade-debug-info.patch
    * chromium-122-clang-build-flags.patch
    * chromium-122-constexpr.patch
    * chromium-122-disable-FFmpegAllowLists.patch
    * chromium-122-el7-default-constructor-involving-anonymous-union.patch
    * chromium-122-el7-extra-operator.patch
    * chromium-122-el7-inline-function.patch
    * chromium-122-el8-support-64kpage.patch
    * chromium-122-missing-header-files.patch
    * chromium-122-no_matching_constructor.patch
    * chromium-122-norar.patch
    * chromium-122-python3-assignment-expressions.patch
    * chromium-122-revert-av1enc-el9.patch
    * chromium-122-static-assert.patch
    * chromium-122-typename.patch
    * chromium-122-unique_ptr.patch
    * chromium-122-workaround_clang_bug-structured_binding.patch
    * from debian add
    * chromium-122-undo-internal-alloc.patch
    * chromium-122-debian-upstream-bitset.patch
    * chromium-122-debian-upstream-mojo.patch
    * chromium-122-debian-upstream-optional.patch
    * chromium-122-debian-upstream-uniqptr.patch
    * chromium-122-debian-fixes-optional.patch
    * added compile fix needed on code15
      chromium-122-skip_bubble_contents_wrapper_static_assert.patch
      to prevent "static assertion expression is not an integral constant expression"
      "in call to 'operator+(&"."[0], ShoppingInsightsSidePanelUI::GetWebUIName())'"
      in bubble_contents_wrapper.h:153
  - replace Cr121-ffmpeg-new-channel-layout.patch by
    Cr122-ffmpeg-new-channel-layout.patch (rediff against 122)
  - drop chromium-121-system-old-ffmpeg.patch
* Fri Mar 08 2024 Callum Farmer <gmbr3@opensuse.org>
  - Add Cr121-ffmpeg-new-channel-layout.patch to rollback more FFmpeg
    changes so that FFmpeg 4 will work on Leap
  - Prepare for libxml 2.12
* Sat Mar 02 2024 Callum Farmer <gmbr3@opensuse.org>
  - Chromium 121.0.6167.184 (boo#1219118, boo#1219387, boo#1219661)
    * CVE-2024-1284: Use after free in Mojo
    * CVE-2024-1283: Heap buffer overflow in Skia
    * CVE-2024-1060: Use after free in Canvas
    * CVE-2024-1059: Use after free in WebRTC
    * CVE-2024-1077: Use after free in Network
    * CVE-2024-0807: Use after free in WebAudio
    * CVE-2024-0812: Inappropriate implementation in Accessibility
    * CVE-2024-0808: Integer underflow in WebUI
    * CVE-2024-0810: Insufficient policy enforcement in DevTools
    * CVE-2024-0814: Incorrect security UI in Payments
    * CVE-2024-0813: Use after free in Reading Mode
    * CVE-2024-0806: Use after free in Passwords
    * CVE-2024-0805: Inappropriate implementation in Downloads
    * CVE-2024-0804: Insufficient policy enforcement in iOS Security UI
    * CVE-2024-0811: Inappropriate implementation in Extensions API
    * CVE-2024-0809: Inappropriate implementation in Autofill
  - Removed patches:
    * chromium-117-includes.patch
    * chromium-118-includes.patch
    * chromium-119-dont-redefine-ATSPI-version-macros.patch
    * chromium-120-missing-header-files.patch
    * chromium-120-no_matching_constructor.patch
    * chromium-120-nullptr_t-without-namespace-std.patch
    * chromium-120-workaround_clang_bug-structured_binding.patch
    * gcc13-fix.patch
    * chromium-113-webauth-include-variant.patch
    * chromium-110-system-libffi.patch
  - Added patches:
    * chromium-121-no_matching_constructor.patch
    * chromium-121-nullptr_t-without-namespace-std.patch
    * chromium-121-workaround_clang_bug-structured_binding.patch
    * chromium-121-missing-header-files.patch
    * chromium-121-rust-clang_lib.patch
    * chromium-121-python3-invalid-escape-sequence.patch
    * chromium-121-rust-clang_lib.patch
    * chromium-121-avoid-SFINAE-TypeConverter.patch
    * chromium-121-blink-libxml-const.patch
  - Add patch chromium-disable-FFmpegAllowLists.patch:
    disable codec checker this will always fail (bsc#1219070)
* Wed Jan 17 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 120.0.6099.224 (boo#1218892)
    * CVE-2024-0517: Out of bounds write in V8
    * CVE-2024-0518: Type Confusion in V8
    * CVE-2024-0519: Out of bounds memory access in V8
    * Various fixes from internal audits, fuzzing and other initiatives
* Sun Jan 14 2024 Callum Farmer <gmbr3@opensuse.org>
  - Replace chromium-120-lp155-revert-clang-build-failure.patch
    with chromium-120-make_unique-struct.patch - which avoids
    reverting changes and instead provides a stub constructor to fix
    build on Leap
* Sat Jan 13 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 120.0.6099.216 (boo#1217839, boo#1218048, boo#1218302,
    boo#1218533, boo#1218719)
    * CVE-2024-0333: Insufficient data validation in Extensions
    * CVE-2024-0222: Use after free in ANGLE
    * CVE-2024-0223: Heap buffer overflow in ANGLE
    * CVE-2024-0224: Use after free in WebAudio
    * CVE-2024-0225: Use after free in WebGPU
    * CVE-2023-7024: Heap buffer overflow in WebRTC
    * CVE-2023-6702: Type Confusion in V8
    * CVE-2023-6703: Use after free in Blink
    * CVE-2023-6704: Use after free in libavif (boo#1218303)
    * CVE-2023-6705: Use after free in WebRTC
    * CVE-2023-6706: Use after free in FedCM
    * CVE-2023-6707: Use after free in CSS
    * CVE-2023-6508: Use after free in Media Stream
    * CVE-2023-6509: Use after free in Side Panel Search
    * CVE-2023-6510: Use after free in Media Capture
    * CVE-2023-6511: Inappropriate implementation in Autofill
    * CVE-2023-6512: Inappropriate implementation in Web Browser UI
  - drop patches:
    * chromium-system-libusb.patch
    * chromium-119-nullptr_t-without-namespace-std.patch
    * chromium-119-no_matching_constructor.patch
    * chromium-117-workaround_clang_bug-structured_binding.patch
  - add patches:
    * chromium-120-nullptr_t-without-namespace-std.patch
    * chromium-120-emplace.patch
    * chromium-120-lp155-typename.patch
    * chromium-120-no_matching_constructor.patch
    * chromium-120-missing-header-files.patch
    * chromium-120-emplace-struct.patch
    * chromium-120-workaround_clang_bug-structured_binding.patch
  - add patches for Leap that revert braking changes:
    * chromium-120-lp155-revert-clang-build-failure.patch
* Wed Nov 29 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 119.0.6045.199 (boo#1217616)
    * CVE-2023-6348: Type Confusion in Spellcheck
    * CVE-2023-6347: Use after free in Mojo
    * CVE-2023-6346: Use after free in WebAudio
    * CVE-2023-6350: Out of bounds memory access in libavif (boo#1217614)
    * CVE-2023-6351: Use after free in libavif (boo#1217615)
    * CVE-2023-6345: Integer overflow in Skia
    * Various fixes from internal audits, fuzzing and other initiatives
* Wed Nov 15 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 119.0.6045.159 (boo#1217142)
    * CVE-2023-5997: Use after free in Garbage Collection
    * CVE-2023-6112: Use after free in Navigation
    * Various fixes from internal audits, fuzzing and other initiatives
* Fri Nov 10 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 119.0.6045.123 (boo#1216978)
    * CVE-2023-5996: Use after free in WebAudio
  - Chromium 119.0.6045.105 (boo#1216783)
    * CVE-2023-5480: Inappropriate implementation in Payments
    * CVE-2023-5482: Insufficient data validation in USB
    * CVE-2023-5849: Integer overflow in USB
    * CVE-2023-5850: Incorrect security UI in Downloads
    * CVE-2023-5851: Inappropriate implementation in Downloads
    * CVE-2023-5852: Use after free in Printing
    * CVE-2023-5853: Incorrect security UI in Downloads
    * CVE-2023-5854: Use after free in Profiles
    * CVE-2023-5855: Use after free in Reading Mode
    * CVE-2023-5856: Use after free in Side Panel
    * CVE-2023-5857: Inappropriate implementation in Downloads
    * CVE-2023-5858: Inappropriate implementation in WebApp Provider
    * CVE-2023-5859: Incorrect security UI in Picture In Picture
  - dropped patches:
    * chromium-98-gtk4-build.patch
    * chromium-118-system-freetype.patch
    * chromium-118-no_matching_constructor.patch
  - added patches:
    * chromium-119-no_matching_constructor.patch
    * chromium-119-dont-redefine-ATSPI-version-macros.patch
    * chromium-119-nullptr_t-without-namespace-std.patch
    * chromium-119-assert.patch
* Tue Oct 24 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 118.0.5993.117 (boo#1216549)
    * CVE-2023-5472: Use after free in Profiles
    * Various fixes from internal audits, fuzzing and other initiatives
* Wed Oct 18 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 118.0.5993.88:
    * unspecified security fix (boo#1216392)
* Wed Oct 11 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - refresh chromium-117-emplace_back_on_vector-c++20.patch and
    chromium-117-lp155-constructors.patch to
    chromium-118-no_matching_constructor.patch
* Tue Oct 10 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 118.0.5993.70 (boo#1216111)
    * CVE-2023-5218: Use after free in Site Isolation
    * CVE-2023-5487: Inappropriate implementation in Fullscreen
    * CVE-2023-5484: Inappropriate implementation in Navigation
    * CVE-2023-5475: Inappropriate implementation in DevTools
    * CVE-2023-5483: Inappropriate implementation in Intents
    * CVE-2023-5481: Inappropriate implementation in Downloads
    * CVE-2023-5476: Use after free in Blink History
    * CVE-2023-5474: Heap buffer overflow in PDF
    * CVE-2023-5479: Inappropriate implementation in Extensions API
    * CVE-2023-5485: Inappropriate implementation in Autofill
    * CVE-2023-5478: Inappropriate implementation in Autofill
    * CVE-2023-5477: Inappropriate implementation in Installer
    * CVE-2023-5486: Inappropriate implementation in Input
    * CVE-2023-5473: Use after free in Cast
  - Build with system freetype (again), and zstd
  - add patches:
    * chromium-118-system-freetype.patch
    * chromium-117-system-zstd.patch
* Sat Oct 07 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 118.0.5993.54
  - add patches:
    * chromium-118-includes.patch
* Wed Oct 04 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 117.0.5938.149:
    * CVE-2023-5346: Type Confusion in V8 (boo#1215924)
* Wed Sep 27 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 117.0.5938.132 (boo#1215776):
    * CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx (boo#1215778)
    * CVE-2023-5186: Use after free in Passwords
    * CVE-2023-5187: Use after free in Extensions
* Fri Sep 22 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 117.0.5938.92:
    * stability improvements
* Wed Sep 20 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Add explicit build dependency on libepoxy for Tumbleweed
* Sun Sep 17 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 117.0.5938.88 (boo#1215279)
    * CVE-2023-4900: Inappropriate implementation in Custom Tabs
    * CVE-2023-4901: Inappropriate implementation in Prompts
    * CVE-2023-4902: Inappropriate implementation in Input
    * CVE-2023-4903: Inappropriate implementation in Custom Mobile Tabs
    * CVE-2023-4904: Insufficient policy enforcement in Downloads
    * CVE-2023-4905: Inappropriate implementation in Prompts
    * CVE-2023-4906: Insufficient policy enforcement in Autofill
    * CVE-2023-4907: Inappropriate implementation in Intents
    * CVE-2023-4908: Inappropriate implementation in Picture in Picture
    * CVE-2023-4909: Inappropriate implementation in Interstitials
  - drop patches:
    * chromium-100-InMilliseconds-constexpr.patch
    * chromium-115-Qt-moc-version.patch
    * chromium-116-profile-view-utils-vector-include.patch
    * chromium-116-blink-variant-include.patch
    * chromium-116-abseil-limits-include.patch
    * chromium-116-lp155-constuctors.patch
    * chromium-115-workaround_clang_bug-structured_binding.patch
    * chromium-115-emplace_back_on_vector-c++20.patch
  - add patches:
    * chromium-117-blink-BUILD-mnemonic.patch
    * chromium-117-includes.patch
    * chromium-117-lp155-constructors.patch
    * chromium-117-string-convert.patch
    * chromium-117-lp155-typename.patch
    * chromium-117-workaround_clang_bug-structured_binding.patch
    * chromium-117-emplace_back_on_vector-c++20.patch
* Wed Sep 13 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - CVE-2023-4863: build with the bundled library on Leap (boo#1215231)
* Tue Sep 12 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 116.0.5845.187 (boo#1215231):
    * CVE-2023-4863: Heap buffer overflow in WebP
* Wed Sep 06 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 116.0.5845.179 (boo#1215023):
    * CVE-2023-4761: Out of bounds memory access in FedCM
    * CVE-2023-4762: Type Confusion in V8
    * CVE-2023-4763: Use after free in Networks
    * CVE-2023-4764: Incorrect security UI in BFCache
* Wed Aug 30 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 116.0.5845.140 (boo#1214758):
    * CVE-2023-4572: Use after free in MediaStream
* Wed Aug 23 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 116.0.5845.110 (boo#1214487):
    * CVE-2023-4427: Out of bounds memory access in V8
    * CVE-2023-4428: Out of bounds memory access in CSS
    * CVE-2023-4429: Use after free in Loader
    * CVE-2023-4430: Use after free in Vulkan
    * CVE-2023-4431: Out of bounds memory access in Fonts
* Mon Aug 14 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 116.0.5845.96
    * New CSS features: Motion Path, and "display" and
      "content-visibility" animations
    * Web APIs: AbortSignal.any(), BYOB support for Fetch, Back/
      forward cache NotRestoredReason API, Document Picture-in-
      Picture, Expanded Wildcards in Permissions Policy Origins,
      FedCM bundle: Login Hint API, User Info API, and RP Context API,
      Non-composed Mouse and Pointer enter/leave events,
      Remove document.open sandbox inheritance,
      Report Critical-CH caused restart in NavigationTiming
  - fix a number of security issues (boo#1214301):
    * CVE-2023-2312: Use after free in Offline
    * CVE-2023-4349: Use after free in Device Trust Connectors
    * CVE-2023-4350: Inappropriate implementation in Fullscreen
    * CVE-2023-4351: Use after free in Network
    * CVE-2023-4352: Type Confusion in V8
    * CVE-2023-4353: Heap buffer overflow in ANGLE
    * CVE-2023-4354: Heap buffer overflow in Skia
    * CVE-2023-4355: Out of bounds memory access in V8
    * CVE-2023-4356: Use after free in Audio
    * CVE-2023-4357: Insufficient validation of untrusted input in XML
    * CVE-2023-4358: Use after free in DNS
    * CVE-2023-4359: Inappropriate implementation in App Launcher
    * CVE-2023-4360: Inappropriate implementation in Color
    * CVE-2023-4361: Inappropriate implementation in Autofill
    * CVE-2023-4362: Heap buffer overflow in Mojom IDL
    * CVE-2023-4363: Inappropriate implementation in WebShare
    * CVE-2023-4364: Inappropriate implementation in Permission Prompts
    * CVE-2023-4365: Inappropriate implementation in Fullscreen
    * CVE-2023-4366: Use after free in Extensions
    * CVE-2023-4367: Insufficient policy enforcement in Extensions API
    * CVE-2023-4368: Insufficient policy enforcement in Extensions API
  - drop patches:
    * chromium-115-add_BoundSessionRefreshCookieFetcher::Result.patch
    * chromium-115-verify_name_match-include.patch
    * chromium-86-fix-vaapi-on-intel.patch
    * chromium-115-skia-include.patch
    * chromium-115-dont-pass-nullptr-to-construct-re2-StringPiece.patch
  - add patches:
    * chromium-116-profile-view-utils-vector-include.patch
    * chromium-116-blink-variant-include.patch
    * chromium-116-lp155-url_load_stats-size-t.patch
    * chromium-116-abseil-limits-include.patch
    * chromium-116-lp155-typenames.patch
    * chromium-116-lp155-constuctors.patch
  - Build with bundled re2 on Leap
* Wed Aug 09 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Fix crash with extensions (boo#1214003)
    chromium-115-dont-pass-nullptr-to-construct-re2-StringPiece.patch
* Thu Aug 03 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 115.0.5790.170 (boo#1213920)
    * CVE-2023-4068: Type Confusion in V8
    * CVE-2023-4069: Type Confusion in V8
    * CVE-2023-4070: Type Confusion in V8
    * CVE-2023-4071: Heap buffer overflow in Visuals
    * CVE-2023-4072: Out of bounds read and write in WebGL
    * CVE-2023-4073: Out of bounds memory access in ANGLE
    * CVE-2023-4074: Use after free in Blink Task Scheduling
    * CVE-2023-4075: Use after free in Cast
    * CVE-2023-4076: Use after free in WebRTC
    * CVE-2023-4077: Insufficient data validation in Extensions
    * CVE-2023-4078: Inappropriate implementation in Extensions
* Fri Jul 28 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Specify re2 build dependency in a way that makes Leap packages
    build in devel project and in Maintenance
* Sun Jul 23 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 115.0.5790.102:
    * stability fix
  - Add build fixes on Leap:
    * chromium-115-emplace_back_on_vector-c++20.patch
    * chromium-115-compiler-SkColor4f.patch
    * chromium-115-workaround_clang_bug-structured_binding.patch
    * chromium-115-add_BoundSessionRefreshCookieFetcher::Result.patch
  - adjust chromium-115-lp155-typename.patch
  - drop chromium-114-workaround_clang_bug-structured_binding.patch
* Wed Jul 19 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 115.0.5790.98
    * Security: The Storage, Service Worker, and Communication APIs
      are now partitioned in third-party contexts to prevent certain
      types of side-channel cross-site tracking
    * HTTPS: Automatically and optimistically upgrade all main-frame
      navigations to HTTPS, with fast fallback to HTTP.
    * CSS: accept multiple values of the display property
    * CSS: support boolean context style container queries
    * CSS: support scroll-driven animations
    * Increase the maximum size of a WebAssembly.Module() on the main
      thread to 8 MB
    * FedCM: Support credential management mediation requirements for
      auto re-authentication
    * Deprecate the document.domain setter
    * Deprecate mutation events
    * Security fixes (boo#1213462):
      CVE-2023-3727: Use after free in WebRTC
      CVE-2023-3728: Use after free in WebRTC
      CVE-2023-3730: Use after free in Tab Groups
      CVE-2023-3732: Out of bounds memory access in Mojo
      CVE-2023-3733: Inappropriate implementation in WebApp Installs
      CVE-2023-3734: Inappropriate implementation in Picture In Picture
      CVE-2023-3735: Inappropriate implementation in Web API Permission Prompts
      CVE-2023-3736: Inappropriate implementation in Custom Tabs
      CVE-2023-3737: Inappropriate implementation in Notifications
      CVE-2023-3738: Inappropriate implementation in Autofill
      CVE-2023-3740: Insufficient validation of untrusted input in Themes
      Various fixes from internal audits, fuzzing and other initiatives
  - drop chromium-113-typename.patch
  - add chromium-115-skia-include.patch
  - add chromium-115-verify_name_match-include.patch
  - add chromium-115-lp155-typename.patch
  - Add chromium-115-Qt-moc-version.patch: support Qt5 & Qt6 without
    built-in copy of shim
* Tue Jun 27 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 114.0.5735.198 (boo#1212755):
    * CVE-2023-3420: Type Confusion in V8
    * CVE-2023-3421: Use after free in Media
    * CVE-2023-3422: Use after free in Guest View
* Sun Jun 25 2023 Callum Farmer <gmbr3@opensuse.org>
  - Install Qt5 library & prepare for Qt6 in 115
* Wed Jun 14 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 114.0.5735.133 (boo#1212302):
    * CVE-2023-3214: Use after free in Autofill payments
    * CVE-2023-3215: Use after free in WebRTC
    * CVE-2023-3216: Type Confusion in V8
    * CVE-2023-3217: Use after free in WebXR
    * Various fixes from internal audits, fuzzing and other initiatives
* Wed Jun 07 2023 Andreas Stieger <Andreas.Stieger@gmx.de>
  - Fix Leap 15.4 build - chromium-114-revert-av1enc-lp154.patch
* Tue Jun 06 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 114.0.5735.106 (boo#1212044):
    * CVE-2023-3079: Type Confusion in V8
* Sun Jun 04 2023 Callum Farmer <gmbr3@opensuse.org>
  - Chromium 114.0.5735.90 (boo#1211843):
    * CSS text-wrap: balance is available
    * Cookies partitioned by top level site (CHIPS)
    * New Popover API
  - Security fixes:
    * CVE-2023-2929: Out of bounds write in Swiftshader
    * CVE-2023-2930: Use after free in Extensions
    * CVE-2023-2931: Use after free in PDF
    * CVE-2023-2932: Use after free in PDF
    * CVE-2023-2933: Use after free in PDF
    * CVE-2023-2934: Out of bounds memory access in Mojo
    * CVE-2023-2935: Type Confusion in V8
    * CVE-2023-2936: Type Confusion in V8
    * CVE-2023-2937: Inappropriate implementation in Picture In Picture
    * CVE-2023-2938: Inappropriate implementation in Picture In Picture
    * CVE-2023-2939: Insufficient data validation in Installer
    * CVE-2023-2940: Inappropriate implementation in Downloads
    * CVE-2023-2941: Inappropriate implementation in Extensions API
  - Drop patches:
    * chromium-103-VirtualCursor-std-layout.patch
    * chromium-113-system-zlib.patch
    * chromium-113-workaround_clang_bug-structured_binding.patch
  - Add patches
    * chromium-114-workaround_clang_bug-structured_binding.patch
    * chromium-114-lld-argument.patch
* Tue May 30 2023 Callum Farmer <gmbr3@opensuse.org>
  - Un-bundle zlib again
  - Remove un-needed patches:
    * chromium-112-default-comparison-operators.patch
    * chromium-109-clang-lp154.patch
    * chromium-clang-nomerge.patch
    * chromium-ffmpeg-lp152.patch
    * chromium-lp151-old-drm.patch
  - Added patches:
    * chromium-113-system-zlib.patch
* Sun May 28 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - build with llvm15 on Leap
* Tue May 16 2023 Andreas Stieger <Andreas.Stieger@gmx.de>
  - Chromium 113.0.5672.126 (boo#1211442):
    * CVE-2023-2721: Use after free in Navigation
    * CVE-2023-2722: Use after free in Autofill UI
    * CVE-2023-2723: Use after free in DevTools
    * CVE-2023-2724: Type Confusion in V8
    * CVE-2023-2725: Use after free in Guest View
    * CVE-2023-2726: Inappropriate implementation in WebApp Installs
    * Various fixes from internal audits, fuzzing and other initiatives
* Tue May 09 2023 Andreas Stieger <Andreas.Stieger@gmx.de>
  - Chromium 113.0.5672.92 (boo#1211211)
  - Multiple security fixes (boo#1211036):
    * CVE-2023-2459: Inappropriate implementation in Prompts
    * CVE-2023-2460: Insufficient validation of untrusted input in Extensions
    * CVE-2023-2461: Use after free in OS Inputs
    * CVE-2023-2462: Inappropriate implementation in Prompts
    * CVE-2023-2463: Inappropriate implementation in Full Screen Mode
    * CVE-2023-2464: Inappropriate implementation in PictureInPicture
    * CVE-2023-2465: Inappropriate implementation in CORS
    * CVE-2023-2466: Inappropriate implementation in Prompts
    * CVE-2023-2467: Inappropriate implementation in Prompts
    * CVE-2023-2468: Inappropriate implementation in PictureInPicture
  - drop chromium-94-sql-no-assert.patch
  - drop no-location-leap151.patch
  - add chromium-113-webview-namespace.patch
  - add chromium-113-webauth-include-variant.patch
  - add chromium-113-typename.patch
  - add chromium-113-workaround_clang_bug-structured_binding.patch
* Wed Apr 19 2023 Andreas Stieger <Andreas.Stieger@gmx.de>
  - Chromium 112.0.5615.165 (boo#1210618):
    * CVE-2023-2133: Out of bounds memory access in Service Worker API
    * CVE-2023-2134: Out of bounds memory access in Service Worker API
    * CVE-2023-2135: Use after free in DevTools
    * CVE-2023-2136: Integer overflow in Skia
    * CVE-2023-2137: Heap buffer overflow in sqlite
  - drop chromium-112-feed_protos.patch
* Sun Apr 16 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Fix Leap 15.4 build failures from default comparison operators
    defined outside of the class definition, a C++20 feature
    adding chromium-112-default-comparison-operators.patch
* Sat Apr 15 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 112.0.5615.121:
    * CVE-2023-2033: Type Confusion in V8 (boo#1210478)
* Fri Apr 07 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Revert a breaking change with chromium-112-feed_protos.patch
* Tue Apr 04 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 112.0.5615.49
    * CSS now supports nesting rules.
    * The algorithm to set the initial focus on <dialog> elements was updated.
    * No-op fetch() handlers on service workers are skipped from now on to make navigations faster
    * The setter for document.domain is now deprecated.
    * The recorder in devtools can now record with pierce selectors.
    * Security fixes (boo#1210126):
    * CVE-2023-1810: Heap buffer overflow in Visuals
    * CVE-2023-1811: Use after free in Frames
    * CVE-2023-1812: Out of bounds memory access in DOM Bindings
    * CVE-2023-1813: Inappropriate implementation in Extensions
    * CVE-2023-1814: Insufficient validation of untrusted input in Safe Browsing
    * CVE-2023-1815: Use after free in Networking APIs
    * CVE-2023-1816: Incorrect security UI in Picture In Picture
    * CVE-2023-1817: Insufficient policy enforcement in Intents
    * CVE-2023-1818: Use after free in Vulkan
    * CVE-2023-1819: Out of bounds read in Accessibility
    * CVE-2023-1820: Heap buffer overflow in Browser History
    * CVE-2023-1821: Inappropriate implementation in WebShare
    * CVE-2023-1822: Incorrect security UI in Navigation
    * CVE-2023-1823: Inappropriate implementation in FedCM
* Mon Mar 27 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 111.0.5563.147:
    * nth-child() validation performance regression for SAP apps
* Thu Mar 23 2023 Guillaume GARDET <guillaume.gardet@opensuse.org>
  - Update gcc13-fix.patch with few fixes required for aarch64,
    borrowed from Fedora's gcc13 patch
* Wed Mar 22 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 111.0.5563.110 (boo#1209598)
    * CVE-2023-1528: Use after free in Passwords
    * CVE-2023-1529: Out of bounds memory access in WebHID
    * CVE-2023-1530: Use after free in PDF
    * CVE-2023-1531: Use after free in ANGLE
    * CVE-2023-1532: Out of bounds read in GPU Video
    * CVE-2023-1533: Use after free in WebProtect
    * CVE-2023-1534: Out of bounds read in ANGLE
* Mon Mar 20 2023 Martin Liška <mliska@suse.cz>
  - Add gcc13-fix.patch in order to support GCC 13.
* Thu Mar 09 2023 Callum Farmer <gmbr3@opensuse.org>
  - Revert back to GCC 11 on 15.4 as Clang 13 doesn't support GCC 12
* Thu Mar 09 2023 Callum Farmer <gmbr3@opensuse.org>
  - Bump Leap's GCC to 12 as Chromium really likes newer standards
* Thu Mar 09 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 111.0.5563.64
    * New View Transitions API
    * CSS Color Level 4
    * New developer tools in style panel for color functionality
    * CSS added trigonometric functions, additional root font units
      and extended the n-th child pseudo selector.
    * previousslide and nextslide actions are now part of the Media
      Session API
    * A number of security fixes (boo#1209040)
    * CVE-2023-1213: Use after free in Swiftshader
    * CVE-2023-1214: Type Confusion in V8
    * CVE-2023-1215: Type Confusion in CSS
    * CVE-2023-1216: Use after free in DevTools
    * CVE-2023-1217: Stack buffer overflow in Crash reporting
    * CVE-2023-1218: Use after free in WebRTC
    * CVE-2023-1219: Heap buffer overflow in Metrics
    * CVE-2023-1220: Heap buffer overflow in UMA
    * CVE-2023-1221: Insufficient policy enforcement in Extensions API
    * CVE-2023-1222: Heap buffer overflow in Web Audio API
    * CVE-2023-1223: Insufficient policy enforcement in Autofill
    * CVE-2023-1224: Insufficient policy enforcement in Web Payments API
    * CVE-2023-1225: Insufficient policy enforcement in Navigation
    * CVE-2023-1226: Insufficient policy enforcement in Web Payments API
    * CVE-2023-1227: Use after free in Core
    * CVE-2023-1228: Insufficient policy enforcement in Intents
    * CVE-2023-1229: Inappropriate implementation in Permission prompts
    * CVE-2023-1230: Inappropriate implementation in WebApp Installs
    * CVE-2023-1231: Inappropriate implementation in Autofill
    * CVE-2023-1232: Insufficient policy enforcement in Resource Timing
    * CVE-2023-1233: Insufficient policy enforcement in Resource Timing
    * CVE-2023-1234: Inappropriate implementation in Intents
    * CVE-2023-1235: Type Confusion in DevTools
    * CVE-2023-1236: Inappropriate implementation in Internals
  - drop patches:
    * chromium-86-ImageMemoryBarrierData-init.patch
    * chromium-93-InkDropHost-crash.patch
    * chromium-110-NativeThemeBase-fabs.patch
    * chromium-110-CredentialUIEntry-const.patch
    * chromium-110-DarkModeLABColorSpace-pow.patch
    * v8-move-the-Stack-object-from-ThreadLocalTop.patch
    * chromium-icu72-1.patch
* Thu Feb 23 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 110.0.5481.177 (boo#1208589)
    * CVE-2023-0927: Use after free in Web Payments API
    * CVE-2023-0928: Use after free in SwiftShader
    * CVE-2023-0929: Use after free in Vulkan
    * CVE-2023-0930: Heap buffer overflow in Video
    * CVE-2023-0931: Use after free in Video
    * CVE-2023-0932: Use after free in WebRTC
    * CVE-2023-0933: Integer overflow in PDF
    * CVE-2023-0941: Use after free in Prompts
    * Various fixes from internal audits, fuzzing and other initiatives
* Thu Feb 16 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 110.0.5481.100
    * fix regression on SAP Business Objects web UI
    * fix date formatting behavior change from ICU 72
* Wed Feb 08 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 110.0.5481.77 (boo#1208029):
    * CVE-2023-0696: Type Confusion in V8
    * CVE-2023-0697: Inappropriate implementation in Full screen mode
    * CVE-2023-0698: Out of bounds read in WebRTC
    * CVE-2023-0699: Use after free in GPU
    * CVE-2023-0700: Inappropriate implementation in Download
    * CVE-2023-0701: Heap buffer overflow in WebUI
    * CVE-2023-0702: Type Confusion in Data Transfer
    * CVE-2023-0703: Type Confusion in DevTools
    * CVE-2023-0704: Insufficient policy enforcement in DevTools
    * CVE-2023-0705: Integer overflow in Core
    * Various fixes from internal audits, fuzzing and other initiatives
  - build with bundled libavif
  - dropped patches:
    * chromium-109-compiler.patch
    * chromium-icu72-3.patch
  - added patches:
    * chromium-110-compiler.patch
    * chromium-110-system-libffi.patch
    * chromium-110-NativeThemeBase-fabs.patch
    * chromium-110-CredentialUIEntry-const.patch
    * chromium-110-DarkModeLABColorSpace-pow.patch
    * v8-move-the-Stack-object-from-ThreadLocalTop.patch
* Wed Jan 25 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 109.0.5414.119 (boo#1207512):
    * CVE-2023-0471: Use after free in WebTransport
    * CVE-2023-0472: Use after free in WebRTC
    * CVE-2023-0473: Type Confusion in ServiceWorker API
    * CVE-2023-0474: Use after free in GuestView
    * Various fixes from internal audits, fuzzing and other
      initiatives
* Tue Jan 17 2023 Callum Farmer <gmbr3@opensuse.org>
  - Added patches:
    * chromium-icu72-1.patch: ensure TextCodecCJK doesn't conflict
      with system icu (bsc#1207147)
    * chromium-icu72-2.patch: align default characters for old icu
      with that of ICU 72
    * chromium-icu72-3.patch: make V8 aware of space in ICU 72 time
      format
* Tue Jan 10 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Chromium 109.0.5414.74:
    * Add support for MathML Core
    * CSS: Auto range support for font descriptors inside @font-face
      rule
    * CSS: Add lh length unit
    * CSS: Add hyphenate-limit-chars property
    * CSS: Snap border, outline and column-rule widths before layout
    * API: Improved screen sharing and web conferencing: hints for
      suppressing local audio playback, and Conditional Focus
    * API: HTTP response status code in the Resource Timing API
    * API: Same-site cross-origin prerendering triggered by the
      speculation rules API
    * Remove Event.path API
    * CVE-2023-0128: Use after free in Overview Mode
    * CVE-2023-0129: Heap buffer overflow in Network Service
    * CVE-2023-0130: Inappropriate implementation in Fullscreen API
    * CVE-2023-0131: Inappropriate implementation in iframe Sandbox
    * CVE-2023-0132: Inappropriate implementation in Permission prompts
    * CVE-2023-0133: Inappropriate implementation in Permission prompts
    * CVE-2023-0134: Use after free in Cart
    * CVE-2023-0135: Use after free in Cart
    * CVE-2023-0136: Inappropriate implementation in Fullscreen API
    * CVE-2023-0137: Heap buffer overflow in Platform Apps
    * CVE-2023-0138: Heap buffer overflow in libphonenumber
    * CVE-2023-0139: Insufficient validation of untrusted input in Downloads
    * CVE-2023-0140: Inappropriate implementation in File System API
    * CVE-2023-0141: Insufficient policy enforcement in CORS
    * Various fixes from internal audits, fuzzing and other initiatives
  - drop patches:
    * chromium-gcc11.patch - not needed
    * chromium-107-system-zlib.patch - upstream
    * chromium-108-compiler.patch
  - add patches:
    * chromium-109-compiler.patch
    * chromium-109-clang-lp154.patch

Files

/usr/bin/chromedriver
/usr/lib64/chromium/chromedriver
/usr/share/licenses/chromedriver
/usr/share/licenses/chromedriver/LICENSE


Generated by rpm2html 1.8.1

Fabrice Bellet, Mon Aug 17 23:45:55 2026