Skip to content
All distributions

Updated 03:00

Determinate Secure Packages distribution

secure-packages-26.05SupportedFIPS supportedUntil November 2029

Built on Nixpkgs 26.05. Available for use in production environments and covered by our standard service-level agreement (SLA).

Fixed within SLA

479

last 30 days

Fixed within SLA

18

last 7 days

Open

27

not yet fixed but still within SLA

Overdue

0

open

Missed SLA

0

last 30 days

Determinate Secure Packages is available through FlakeHub to organizations with access. Not a customer yet? Get in touch to gain access or schedule a demo.

Email sales@determinate.systems

Standardflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05/0";
}
FIPS variant

FIPS variantflake.nix

{
  inputs.nixpkgs.url = "https://flakehub.com/f/DeterminateSystems/secure-packages-26.05-fips/0";
}

In the FIPS variant, every covered package is compliant with Federal Information Processing Standards (FIPS). Using the FIPS variant has the details.

506 CVEs tracked

CVEStatusSeveritySummaryClock startedDeadlineFixedTime to fix
Fixed within SLAMediumGoogle Chrome WebProtect bug pre-151.0.7922.72 lets compromised renderer leak cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 GPU bug allows cross-origin data leak after renderer compromise via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome pre-151.0.7922.72 NoStatePrefetch side-channel allowed remote cross-origin data leaks via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151.0.7922.72 Codecs uninitialized use leaks memory via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalDawn heap buffer overflow in Chrome <151.0.7922.72 enables potential remote sandbox escape via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Skia uninitialized use allows cross-origin data leak via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Autofill vulnerability pre-151.0.7922.72: remote cross-origin data leak via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighUse-after-free in Chrome Views on Mac pre-151.0.7922.72 enables remote heap corruption via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighGoogle Chrome AdFilter sandbox RCE via crafted HTML before 151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighChrome pre-151.0.7922.72 ANGLE use-after-free allows remote sandbox escape via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient input validation in Chrome Android Payments enables UI spoofing via compromised rendererAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Mac GPU use-after-free allows sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumSkia out-of-bounds read enables sandbox escape after renderer compromise, Chrome <151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome Linux File Input vulnerability enables remote sandbox escape via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Payments insufficient policy enforcement allows cross-origin data leak via crafted HTML pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighWebView untrusted input validation flaw enables sandbox escape in Chrome Android prior to 151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAMediumANGLE uninitialized use in Chrome <151.0.7922.72 leaks cross-origin data via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumInsufficient policy enforcement allows UXSS via malicious extensions in Chrome pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumAndroid Chrome Bluetooth use-after-free enables sandbox escape by compromised renderer via crafted HTML pre-151.0.7922.72Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumAndroid Chrome <151 WebView input validation bug lets compromised renderer escape sandbox via HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Android QUIC flaw enabled remote cross-origin data leak via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLALowPre-151.0.7922.72 Chrome SVG flaw leaks cross-origin data via crafted HTMLAug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAMediumAndroid Chrome Autofill prior to 151.0.7922.72 leaks cross-origin data via crafted pageAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome <151 Autofill side-channel allowed cross-origin data leak via crafted page and UI gesturesAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome Android <151.0.7922.72 WebGL out-of-bounds write enables remote sandbox escape via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalWebGL integer overflow allows sandbox escape in Chrome Android before 151.0.7922.72 via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAHighV8 type confusion in Chrome <151.0.7922.72 allows sandboxed RCE via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighWebView lifecycle bug in Android Chrome pre-151.0.7922.72 allowed renderer-compromised sandbox escapeAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLACriticalANGLE out-of-bounds write allows remote sandbox escape via crafted HTML in Chrome <151.0.7922.72 High severityAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLALowHigh-severity Chrome Passwords policy flaw leaks cross-origin data via compromised renderer (pre-151.0.7922.72)Aug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAHighHigh-severity use-after-free in Input enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.72Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLACriticalUse-after-free in ANGLE allows remote sandbox escape via crafted HTML on Chrome <151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalHigh severity ANGLE integer overflow in Chrome <151.0.7922.72 enables remote sandbox escape via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLALowChrome Passwords before 151.0.7922.72: cross-origin data leak via crafted HTML, UI gesturesAug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAMediumHigh-severity ANGLE uninitialized use in Chrome pre-151.0.7922.72 enables remote memory disclosure via crafted HTMLAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighChrome Mac Skia race pre-151.0.7922.72 enables sandboxed remote code execution via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome Mac <151.0.7922.72 Downloads race allows sandbox escape after renderer compromise via crafted HTML pageAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalGoogle Chrome Mac <151.0.7922.72 MHTML flaw enables sandbox escape from compromised renderer via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome Mac pre-151.0.7922.72 Downloads race allows sandbox escape after renderer compromiseAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLACriticalGoogle Chrome Audio use-after-free enables sandbox escape from compromised renderer via crafted HTML pre-151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Windows pre-151.0.7922.72 Media uninitialized use info leak via crafted HTML requiring renderer compromiseAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighHigh-severity Chrome <151.0.7922.72 libxml integer overflow allows sandboxed RCE via crafted HTMLAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome <151.0.7922.72 ANGLE use-after-free enables sandbox escape via crafted HTMLAug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome iOS <151.0.7922.72 policy enforcement bug allows navigation restriction bypass via crafted HTML remote attackerAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLALowChrome <151.0.7922.72 Skia cross-origin data leak via crafted HTML with compromised rendererAug 4, 2026Nov 2, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome pre-151.0.7922.72 Actor input validation flaw leaks cross-origin data via compromised rendererAug 4, 2026Sep 18, 2026Aug 4, 2026same day
Fixed within SLAHighUse-after-free in Chrome Views enables local attacker sandbox escape via malicious file (pre-151.0.7922.72)Aug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLAHighChrome on Android UI input validation flaw pre-151.0.7922.72 allows local cross-origin data leakAug 4, 2026Aug 19, 2026Aug 4, 2026same day
Fixed within SLACriticalChrome ANGLE type confusion enabling sandbox escape via crafted HTML in versions <151.0.7922.72Aug 4, 2026Aug 11, 2026Aug 4, 2026same day
Fixed within SLAMediumChrome Media side-channel allows remote cross-origin data leak via crafted HTML (pre-151.0.7922.72)Aug 4, 2026Sep 18, 2026Aug 4, 2026same day

Make CVE remediation our job, not yours.

Tell us what you run. We'll show you what Determinate Secure Packages covers, how the SLA applies, and how to get started.

Email sales@determinate.systems