chromium-bin
Version: 147.0.7727.15Playwright is a framework for Web Testing and Automation. It allows testing Chromium, Firefox and WebKit with a single API.
What is chromium-bin?
Playwright is a framework for Web Testing and Automation. It allows testing Chromium, Firefox and WebKit with a single API.
How to use this package
Quick install
Installs the package into the current environment for this session. Use --build or --runtime to persist it as a build-time or runtime dependency.
min add chromium-bin Declare as a task dependency in minimal.toml
Listing the package under tasks.<name>.packages makes it available inside that task’s sandbox.
[tasks.dev]
packages = ["chromium-bin"] Build-time vs runtime
Choose build-time for tools needed during compilation, runtime for dynamic libraries loaded at runtime.
min add --build chromium-bin
min add --runtime chromium-bin Dependencies (34)
| Name | Version | Kind |
|---|---|---|
| alsa-lib | 1.2.15.3 | runtime |
| at-spi2-core | 2.54.2 | runtime |
| atk | 2.38.0 | runtime |
| base | — | build |
| bash | 5.3 | runtime |
| cairo | 1.18.4 | runtime |
| cups | 2.4.19 | runtime |
| dbus | 1.16.2 | runtime |
| eudev | 3.2.14 | runtime |
| expat | 2.7.5 | runtime |
| fontconfig | 2.17.1 | runtime |
| freetype | 2.14.1 | runtime |
| fribidi | 1.0.16 | runtime |
| gcc CVE:1 | 15.2.0 | runtime |
| glib | 2.86.4 | runtime |
| glibc CVE:3 | 2.42 | runtime |
| harfbuzz | 14.2.0 | runtime |
| libdrm | 2.4.131 | runtime |
| liberation-fonts | 2.1.5 | runtime |
| libx11 | 1.8.12 | runtime |
| libxcb | 1.17.0 | runtime |
| libxcomposite | 0.4.6 | runtime |
| libxdamage | 1.1.6 | runtime |
| libxext | 1.3.6 | runtime |
| libxfixes | 6.0.1 | runtime |
| libxkbcommon | 1.13.1 | runtime |
| libxrandr | 1.5.4 | runtime |
| libxrender | 0.9.12 | runtime |
| libxshmfence | 1.3.3 | runtime |
| mesa | 25.3.5 | runtime |
| nspr | 4.38.2 | runtime |
| nss | 3.121 | runtime |
| pango | 1.56.4 | runtime |
| unzip | 6.0 | build |
Dependants (1)
| Name | Version |
|---|---|
| agent-browser | 0.15.1 |
No direct advisories
This package inherits 15 transitive advisories from its dependencies.
Showing 15 transitive advisories via chromium-bin's dependencies
No advisories match the current filters.
| Status | IDs | Package | Severity | |||
|---|---|---|---|---|---|---|
| Critical ( 0 ) | ||||||
| High ( 12 ) | ||||||
| Affected: 2.42 | glibc | High: 7.5 | ||||
SummaryNo summary published for this advisory. Via: glibc Affected ranges
CVSS vector:
References | ||||||
| Affected: 2.42 | glibc | High: 7.5 | ||||
SummaryNo summary published for this advisory. Via: glibc Affected ranges
CVSS vector:
References | ||||||
| Affected: 2.42 | glibc | High: 8.4 | ||||
SummaryNo summary published for this advisory. Via: glibc Affected ranges
CVSS vector:
| ||||||
| Affected: 3.6.2 | openssl | High: 7.5 | ||||
SummaryNo summary published for this advisory. Affected ranges
CVSS vector:
References
| ||||||
| Resolved in 9ceb800ac26fd81a5eaf27ef366d5fce47e80447 | harfbuzz | High | ||||
SummaryHeap-buffer-overflow in OT::cvar::decompile_tuple_variations Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 4e2f409bce77b97de2d098365977beeeb4447b1e | harfbuzz | High | ||||
SummaryHeap-use-after-free in hb_bit_set_invertible_t::next Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 4e2f409bce77b97de2d098365977beeeb4447b1e | harfbuzz | High | ||||
SummaryHeap-use-after-free in OT::CoverageFormat1::intersected_coverage_glyphs Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 4e2f409bce77b97de2d098365977beeeb4447b1e | harfbuzz | High | ||||
SummaryHeap-use-after-free in hb_bit_set_invertible_t::intersects Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 0df65d82dbc41e8da00adb243de5918db532c8a6 | openssl | High | ||||
SummaryHeap-buffer-overflow in asn1_ex_i2c Affected ranges
Fixed in:
References | ||||||
| Resolved in 00fdbca4f6a5c4623b9c4838da502cccce8aaa74 | harfbuzz | High | ||||
SummaryHeap-buffer-overflow in BEInt<unsigned short, 2>::operator unsigned short Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 00fdbca4f6a5c4623b9c4838da502cccce8aaa74 | harfbuzz | High | ||||
SummaryHeap-buffer-overflow in BEInt<unsigned short, 2>::operator unsigned short Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Resolved in 7a6686a589ed6bf17a5af0b8012501e4d4ee2ded | harfbuzz | High | ||||
SummaryHeap-buffer-overflow in BEInt<unsigned short, 2>::operator unsigned short Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Medium ( 3 ) | ||||||
| Under investigation | libpng | Medium: 5.4 | ||||
SummaryLIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue. Affected ranges
CVSS vector:
| ||||||
| Resolved in 04d60de6ae06562262f04e8e2e4d9441c66233e0 | harfbuzz | Medium | ||||
SummaryUse-of-uninitialized-value in CFF::cff2_cs_opset_t<cff2_cs_opset_subr_subset_t, CFF::subr_subset_param_t, CFF: Via: harfbuzz Affected ranges
Fixed in:
References | ||||||
| Affected: 15.2.0 | gcc | Medium: 4.8 | ||||
Summary**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being detected. This stack-protector failure only applies to C99-style dynamically-sized local variables or those created using alloca(). The stack-protector operates as intended for statically-sized local variables. The default behavior when the stack-protector detects an overflow is to terminate your application, resulting in controlled loss of availability. An attacker who can exploit a buffer overflow without triggering the stack-protector might be able to change program flow control to cause an uncontrolled loss of availability or to go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself. Via: gcc Affected ranges
CVSS vector:
| ||||||
| Low ( 0 ) | ||||||
| Unknown ( 0 ) | ||||||
95 components
No components match your filter.
| Packages | Version |
|---|---|
| chromium-bin ROOT | 147.0.7727.15 |
| acl | 2.3.2 |
| alsa-lib | 1.2.15.3 |
| at-spi2-core | 2.54.2 |
| atk | 2.38.0 |
| attr | 2.5.2 |
| autoconf | 2.73 |
| automake | 1.18.1 |
| bash | 5.3 |
| bash-bootstrap | 5.3 |
| binutils | 2.46.1 |
| bison | 3.8.2 |
| bzip2 | 1.0.8 |
| cairo | 1.18.4 |
| cmake | 4.2.3 |
| coreutils | 9.11 |
| cups | 2.4.19 |
| curl | 8.20.0 |
| dbus | 1.16.2 |
| diffutils | 3.12 |
| eudev | 3.2.14 |
| expat | 2.7.5 |
| file | 5.47 |
| findutils | 4.10.0 |
| flex | 2.6.4 |
| fontconfig | 2.17.1 |
| freetype | 2.14.1 |
| fribidi | 1.0.16 |
| gawk | 5.4.0 |
| gawk-bootstrap | 5.3.2 |
| gcc | 15.2.0 |
| gdbm | 1.26 |
| glib | 2.86.4 |
| glibc | 2.42 |
| gmp | 6.3.0 |
| gperf | 3.1 |
| grep | 3.12 |
| gzip | 1.14 |
| harfbuzz | 14.2.0 |
| icu | 78.3 |
| libcap | 2.78 |
| libdrm | 2.4.131 |
| liberation-fonts | 2.1.5 |
| libffi | 3.5.2 |
| libidn2 | 2.3.8 |
| libpng | 1.6.58 |
| libpsl | 0.21.5 |
| libtool | 2.5.4 |
| libunistring | 1.4.1 |
| libuv | 1.52.1 |
| libx11 | 1.8.12 |
| libxau | 1.0.12 |
| libxcb | 1.17.0 |
| libxcomposite | 0.4.6 |
| libxdamage | 1.1.6 |
| libxdmcp | 1.1.5 |
| libxext | 1.3.6 |
| libxfixes | 6.0.1 |
| libxkbcommon | 1.13.1 |
| libxml2 | 2.15.3 |
| libxrandr | 1.5.4 |
| libxrender | 0.9.12 |
| libxshmfence | 1.3.3 |
| linux_headers | 6.12.43 |
| lz4 | 1.10.0 |
| m4 | 1.4.21 |
| make | 4.4.1 |
| mesa | 25.3.5 |
| meson | 1.10.1 |
| mpc | 1.4.0 |
| mpfr | 4.2.2 |
| ncurses | 6.5-20250830 |
| ninja | 1.13.2 |
| nspr | 4.38.2 |
| nss | 3.121 |
| openssl | 3.6.2 |
| pango | 1.56.4 |
| pcre2 | 10.47 |
| perl | 5.42.0 |
| pixman | 0.46.4 |
| pkgconf | 2.5.1 |
| python | 3.14.5 |
| readline | 8.3 |
| sed | 4.9 |
| setuptools | 82.0.1 |
| sqlite | 3.50.4 |
| tar | 1.35 |
| unzip | 6.0 |
| util-linux | 2.42.1 |
| xcb-proto | 1.17.0 |
| xorgproto | 2025.1 |
| xtrans | 1.6.0 |
| xz | 5.8.3 |
| zlib | 1.3.2 |
| zstd | 1.5.7 |