From ${URL} : TUESDAY, FEBRUARY 9, 2016 Stable Channel Update The stable channel has been updated to 48.0.2564.109 for Windows, Mac, and Linux. Security Fixes and Rewards Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed. This update includes 6 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chromium security page for more information. [$7500][546677] High CVE-2016-1622: Same-origin bypass in Extensions. Credit to anonymous. [$7500][577105] High CVE-2016-1623: Same-origin bypass in DOM. Credit to Mariusz Mlynski. [$TBD][583607] High CVE-2016-1624: Buffer overflow in Brotli. Credit to lukezli. [$1000][509313] Medium CVE-2016-1625: Navigation bypass in Chrome Instant. Credit to Jann Horn. [571480] Medium CVE-2016-1626: Out-of-bounds read in PDFium. Credit to anonymous, working with HP's Zero Day Initiative. As usual, our ongoing internal security work: [585517] CVE-2016-1627: Various fixes from internal audits, fuzzing and other initiatives. @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Waiting on upstream to provide a source tarball for 48.0.2564.109.
https://groups.google.com/a/chromium.org/forum/#!msg/chromium-packagers/ulCADD8aNV8/etwNbtKsGAAJ
the tarball seems to be available now, but it is 412M
(In reply to Agostino Sarubbo from comment #3) > the tarball seems to be available now, but it is 412M the lite tarball is available too.
chromium-48.0.2564.109 has been added to the gentoo repository. Please stabilize it.
amd64 stable
Missing x86 stabilization, but the version is made obsolete by bug 575434
Added to existing GLSA.
This issue was resolved and addressed in GLSA 201603-09 at https://security.gentoo.org/glsa/201603-09 by GLSA coordinator Kristian Fiskerstrand (K_F).