Skip to content
All distributions

Updated 01:00

Determinate Secure Packages distribution

secure-packages-26.05SupportedFIPS supportedUntil November 2029

Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

479

last 30 days

Fixed within SLA

18

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

506 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
Fixed within SLAMediumInsufficient input validation in Chrome Mac Updater allows sandbox escape from compromised rendererAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumWebXR vulnerability leaks Chrome process memory via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMedium<151.0.7922.72 Chrome Android ANGLE use-after-free allows sandbox escape via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome DevTools insufficient input validation enables sandbox escape via crafted HTML from compromised rendererAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumWebXR uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome pre-151.0.7922.72 WebUI input validation flaw enables sandbox escape via malicious network trafficAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighChrome <151.0.7922.72 TabStrip use-after-free enables heap corruption via crafted HTML and UI gesturesAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighUse-after-free in Chrome Enterprise pre-151.0.7922.72 enables remote heap corruption via HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Paint cross-origin data leak via crafted HTML before 151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome WebRTC lifecycle bug pre-151.0.7922.72 allows remote heap corruption via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumRemote attacker could bypass same-origin policy in Headless Chrome <151.0.7922.72 via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 extension policy flaw allows site isolation bypass via malicious extensionAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighWebXR integer overflow in Chrome <151.0.7922.72 enables sandboxed remote code execution via crafted HTML pageAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Autofill cross-origin data leak via crafted HTML page prior to 151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Autofill cross-origin data leak via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 CSS bug enables UXSS via crafted HTML pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumPre-151.0.7922.72 Chrome Payments bug leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighPDFium use-after-free enables sandboxed RCE via crafted PDF in Chrome <151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome for iOS before 151.0.7922.72 allows UI spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumiOS Chrome <151.0.7922.72: insufficient policy enforcement enables HTML-based discretionary access control bypassAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumCryptographic flaw in WebAppInstalls allows local sandbox escape via crafted HTML in Android Chrome pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumPre-151.0.7922.72 Chrome Passwords cross-origin data leak via crafted page, UI gesturesAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Cast pre-151.0.7922.72 insufficient input validation leaks cross-origin data on LANAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome <151.0.7922.72 WebXR out-of-bounds read enables remote memory disclosureAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighChrome USB policy enforcement bug (<151.0.7922.72) allows remote privilege escalation via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighInsufficient input validation in Chrome Dawn allows remote sandbox escape via crafted HTML pageAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumType confusion in Tab allows sandbox escape post-renderer compromise in Chrome Android <151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalGoogle Chrome Mac Crypto bug allows sandbox escape from compromised renderer via crafted HTML pre-151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAHighChrome Mac Updater pre-151.0.7922.72 local OS-level privilege escalation via malicious fileAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighChrome Windows pre-151.0.7922.72: Local privilege escalation via malicious fileAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighChrome Windows Tracing use-after-free allows local privilege escalation via malicious file (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighInsufficient input validation in Chrome Updater allows local privilege escalation via malicious file (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLALowAndroid Chrome <151.0.7922.72: Omnibox spoofing via malicious local file; insufficient input validationAug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome <151.0.7922.72 favicon implementation leaks cross-origin data via crafted HTML pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome WebNN uninitialized use on Windows <151.0.7922.72 leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Network cross-origin data leak via crafted HTML before 151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome Mac pre-151.0.7922.72 network flaw enables sandbox escape via crafted HTML after renderer compromiseAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalDevTools race on Mac Chrome pre-151.0.7922.72 enables sandbox escape from compromised rendererAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 WebMCP policy flaw enables remote same-origin policy bypass via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 DevTools: compromised renderer injects script/HTML into privileged pagesAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Media Router pre-151.0.7922.72 Same-Origin Policy bypass via crafted HTML by remote attackerAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumPre-151.0.7922.72 Chrome Autofill side-channel leak enables cross-origin exfiltration via compromised rendererAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Permissions bug pre-151.0.7922.72 enables same-origin policy bypass via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome iOS <151.0.7922.72 Omnibox spoofing via malicious network trafficAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalInteger overflow in Google Chrome Codecs enables remote sandbox escape via crafted video pre-151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalANGLE input validation flaw allows sandbox escape via crafted HTML in Chrome <151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Windows Media bug pre-151.0.7922.72 allows compromised renderer to bypass same-origin policy via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 CSS UXSS allows remote script/HTML injection via crafted pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumPre-151.0.7922.72 Chrome Cast input validation allowed local attacker to leak cross-origin dataAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome CSS flaw before 151.0.7922.72 leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems