Skip to content
All distributions

Updated 02:00

Determinate Secure Packages distribution

secure-packages-26.05SupportedFIPS supportedUntil November 2029

Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

479

last 30 days

Fixed within SLA

18

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

506 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
Fixed within SLAMediumChrome iOS <151.0.7922.72 SOP bypass via crafted HTML requiring specific user gesturesAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome iOS race allows remote UI spoofing via crafted HTML before 151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome Passwords UI flaw enables domain spoofing via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumUI spoofing vulnerability in Chrome for iOS before 151.0.7922.72 via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome iOS pre-151.0.7922.72 incorrect security UI enables domain spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome DevTools untrusted input validation flaw enables sandbox escape via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAHighChrome <151.0.7922.72 V8 use-after-free enables sandboxed remote code execution via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome for iOS <151.0.7922.72 allows remote UI spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome Passwords validation flaw enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome Passwords pre-151.0.7922.72 cross-origin data leak via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalUse-after-free in ANGLE allows sandbox escape in Google Chrome pre-151.0.7922.72 via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient validation of untrusted input in Chrome Passwords allows UI spoofing by compromised rendererAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome for iOS <151.0.7922.72 navigation restriction bypass via crafted HTML by remote attackerAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Passwords vulnerability pre-151.0.7922.72 leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome for iOS <151.0.7922.72 allows UI spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome CSS bug before 151.0.7922.72 enables UXSS via crafted HTML pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLALowChrome for iOS <151.0.7922.72 cross-origin data leak via crafted HTML and UI gestures Medium severityAug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Android <151.0.7922.72 Passwords policy bug allows discretionary access control bypass via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient ServiceWorker policy enforcement enabled same-origin policy bypass in Google Chrome pre-151.0.7922.72 via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 WebXR policy enforcement flaw enables same-origin policy bypassAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome iOS race condition allows remote UI spoofing via crafted HTML pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome before 151.0.7922.72 extension policy flaw enables bypass of navigation restrictionsAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome pre-151.0.7922.72 Autofill policy flaw leaked cross-origin data via crafted pagesAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome <151.0.7922.72 WebAppInstalls vulnerability allows remote UI spoofing via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumRemote UXSS via crafted HTML in Chrome <151.0.7922.72 Network componentAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumPre-151.0.7922.72 Chrome ReportingAndNEL cross-origin data leak via crafted HTML pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighAndroid Chrome Speech policy enforcement bug enables compromised renderer privilege escalation via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome GuestView insufficient policy enforcement enables cross-origin data leak pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumiOS Chrome input validation flaw bypasses navigation restrictions via crafted HTML, pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumPolicy enforcement flaw allows navigation bypass in Chrome for iOS <151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 DigitalCredentials flaw enables remote UI spoofing via crafted HTML pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighUse-after-free in Chrome ANGLE on Windows allows sandbox escape via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Dawn uninitialized use leaks cross-origin data via crafted HTML, pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Extensions input validation bug enables sandbox escape via crafted HTML after renderer compromise (<151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumWebGL uninitialized use leaks cross-origin data in Chrome Android before 151.0.7922.72 via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome V8 use-after-free enables sandboxed RCE via crafted HTML before 151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome Extensions pre-151.0.7922.72 input validation flaw enables renderer sandbox escapeAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient Glic policy enforcement in Chrome Android <151.0.7922.72 allows remote navigation bypass via HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalUse-after-free in Chrome Media enables sandbox escape via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome pre-151 Save to Drive input validation bug enabling renderer sandbox escape via crafted PDFAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalANGLE out-of-bounds read/write allows remote attacker sandbox escape via crafted HTML in Chrome <151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumPre-151.0.7922.72 Chrome MediaRecording bug leaks process memory via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Safe Browsing input validation bug pre-151.0.7922.72 enables DAC bypass via malicious fileAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumGoogle Chrome WebXR side-channel leak exposes process memory via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient input validation enables Chrome Android pre-151.0.7922.72 Omnibox spoofing via crafted HTML after renderer compromiseAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumRemote UI spoofing via crafted HTML in Chrome Android Messages pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Windows ANGLE uninitialized use leaks process memory via crafted HTML pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome prior to 151.0.7922.72 extension flaw allows malicious extensions to leak cross-origin dataAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighUse-after-free in Chrome Extensions pre-151.0.7922.72 enables sandboxed arbitrary code executionAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLALowAndroid Chrome Clipboard validation flaw prior to 151.0.7922.72 leaks cross-origin data locallyAug 4, 2026Nov 2, 2026Aug 4, 2026same day

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems