Skip to content
All distributions

Updated 00:01

Determinate Secure Packages distribution

secure-packages-26.05SupportedFIPS supportedUntil November 2029

Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

479

last 30 days

Fixed within SLA

18

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

506 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
Fixed within SLAMediumChrome Mac pre-151.0.7922.72 local attacker bypasses navigation restrictions via malicious fileAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighRemote out-of-bounds memory read in Chrome Dawn via crafted HTML before 151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumRemote attacker could bypass navigation restrictions via Media in Chrome Android <151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighRace in Chrome Updater on Windows allows local privilege escalation pre-151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumSkia uninitialized use in Chrome Windows leaks process memory via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome <151.0.7922.72 AI input validation bug enables sandbox escape from compromised renderer via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome WebAuthn input validation flaw allows sandbox escape via PDF (pre-151.0.7922.72)Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAHighChrome <151.0.7922.72 V8 type confusion allows sandboxed code execution via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 Navigation input validation flaw lets compromised renderer bypass restrictions via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome Notifications validation flaw enables sandbox escape via crafted PDF after renderer compromise (pre-151)Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome pre-151.0.7922.72 Bluetooth policy bug allows same-origin policy bypass via crafted HTML from compromised rendererAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome pre-151 Speech policy bug enables remote site isolation bypass via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLALowChrome Android <151.0.7922.72 cross-origin data leak via crafted HTML, local attackerAug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAMediumUI spoofing in Chrome Global Media Controls via crafted HTML before 151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient input validation in Chrome Cast allowed same-origin policy bypass via crafted HTML pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Blink flaw lets remote attacker leak cross-origin data via crafted HTML pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLALowChrome Android <151.0.7922.72 UI flaw enables cross-origin data leak via crafted pageAug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAHighV8 race condition in Chrome <151.0.7922.72 enables remote code execution in sandbox via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome WebCodecs side-channel exposes sensitive process memory via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome prior to 151.0.7922.72 CSS policy bypass leaks cross-origin data via crafted HTML pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Extensions policy flaw allows DAC bypass via crafted domains (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Mac IME pre-151.0.7922.72 flaw allows remote process memory disclosure via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 DevTools policy flaw lets local attacker bypass navigation restrictions via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome Mac Views flaw allows local memory disclosure via crafted HTML pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome iOS pre-151.0.7922.72 permits UI spoofing via crafted HTML pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome <151.0.7922.72 Frame implementation allows remote OOB memory access via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 Passwords lacks input validation, enabling UI spoofing by privileged network attackerAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighGoogle Chrome Passwords prior to 151.0.7922.72 allows remote sandbox RCE via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumWebXR uninitialized use leaks process memory in Chrome Android before 151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighUse-after-free in Chrome iOS pre-151.0.7922.72 enables remote heap corruption via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumMac Chrome Views bug allowed local process memory disclosure via crafted HTML prior to 151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome iOS <151.0.7922.72: Incorrect security UI allows remote HTML UI spoofingAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumIncorrect security UI on Chrome Android pre-151.0.7922.72 enables domain spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 SVG bug allows cross-origin data leak via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumBlink UXSS in Chrome <151.0.7922.72 allows remote script/HTML injection via crafted pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Android pre-151.0.7922.72 Session bug allows remote bypass of navigation restrictions via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient policy enforcement enables no-referrer bypass via crafted HTML in Chrome iOS <151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Network vulnerability leaked cross-origin data via crafted HTML page pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome pre-151.0.7922.72 Views flaw enables remote UI spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLALowLow-severity CORS flaw in Chrome <151.0.7922.72 enables cross-origin leak via compromised rendererAug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAHighChrome pre-151.0.7922.72 Scheduling flaw enables sandbox RCE via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient input validation in Chrome Payments allows UI spoofing via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumPolicy bypass in Chrome MHTML before 151.0.7922.72 leaks cross-origin dataAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumAndroid Chrome WebView policy enforcement bug allows navigation bypass via crafted HTML before 151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome V8 pre-151.0.7922.72 allows sandbox code execution via malicious extensionAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighGoogle Chrome WebRTC heap buffer overflow enables remote out-of-bounds read via crafted HTML pre-151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighChrome Mac Safe Browsing bug pre-151.0.7922.72 allows RCE via malicious fileAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumUninitialized GPU use in Chrome Android pre-151.0.7922.72 leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome V8 type confusion enables sandboxed code execution via malicious extension (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome <151.0.7922.72 WebSockets use-after-free allows remote sandbox escape via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems