Skip to content

chore: cherry-pick 1 changes from chromium#51904

Merged
MarshallOfSound merged 1 commit into
42-x-yfrom
security-backport/42-x-y/2026-06-05
Jun 6, 2026
Merged

chore: cherry-pick 1 changes from chromium#51904
MarshallOfSound merged 1 commit into
42-x-yfrom
security-backport/42-x-y/2026-06-05

Conversation

@VerteDinde

Copy link
Copy Markdown
Member

Backports the following changes:

The enforcement code for both CVEs is already in Chromium 148.0.7778.218, but the feature flags default off and Chrome enabled them on stable via Finch, which Electron does not have. This flag flip makes the in-tree fixes active.

All other CVEs in the Chrome 148.0.7778.178 stable release were verified already present in the 42-x-y tree. Intentionally not backported:

  • 7900197 (QUIC follow-up hardening) and 7718888 (ui/gfx follow-up hardening) — landed on main after the M148 branch cut and were never merged to M148 by Chrome; the fixes Chrome shipped for CVE-2026-9114 and CVE-2026-9117 are already in-tree.
  • 7765503 (CVE-2026-9123) — touches only chromecast/media/, which Electron does not compile.

Notes: Security: backported fixes for CVE-2026-9115, CVE-2026-9116.

@VerteDinde VerteDinde requested a review from a team as a code owner June 5, 2026 23:27
@VerteDinde VerteDinde added semver/patch backwards-compatible bug fixes backport-check-skip Skip trop's backport validity checking 42-x-y security 🔒 labels Jun 5, 2026
@MarshallOfSound MarshallOfSound merged commit 55b29e8 into 42-x-y Jun 6, 2026
92 checks passed
@release-clerk

release-clerk Bot commented Jun 6, 2026

Copy link
Copy Markdown

Release Notes Persisted

Security: backported fixes for CVE-2026-9115, CVE-2026-9116.

@MarshallOfSound MarshallOfSound deleted the security-backport/42-x-y/2026-06-05 branch June 6, 2026 07:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

42-x-y backport-check-skip Skip trop's backport validity checking security 🔒 semver/patch backwards-compatible bug fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants