Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
-
Chromium 148.0.7778.167 (boo#1265159)
-
Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175)
- CVE-2026-7896: Integer overflow in Blink
- CVE-2026-7897: Use after free in Mobile
- CVE-2026-7898: Use after free in Chromoting
- CVE-2026-7899: Out of bounds read and write in V8
- CVE-2026-7900: Heap buffer overflow in ANGLE
- CVE-2026-7901: Use after free in ANGLE
- CVE-2026-7902: Out of bounds memory access in V8
- CVE-2026-7903: Integer overflow in ANGLE
- CVE-2026-7904: Out of bounds read in Fonts
- CVE-2026-7905: Insufficient validation of untrusted input in Media
- CVE-2026-7906: Use after free in SVG
- CVE-2026-7907: Use after free in DOM
- CVE-2026-7908: Use after free in Fullscreen
- CVE-2026-7909: Inappropriate implementation in ServiceWorker
- CVE-2026-7910: Use after free in Views
- CVE-2026-7911: Use after free in Aura
- CVE-2026-7912: Integer overflow in GPU
- CVE-2026-7913: Insufficient policy enforcement in DevTools
- CVE-2026-7914: Type Confusion in Accessibility
- CVE-2026-7915: Insufficient data validation in DevTools
- CVE-2026-7916: Insufficient data validation in InterestGroups
- CVE-2026-7917: Use after free in Fullscreen
- CVE-2026-7918: Use after free in GPU
- CVE-2026-7919: Use after free in Aura
- CVE-2026-7920: Use after free in Skia
- CVE-2026-7921: Use after free in Passwords
- CVE-2026-7922: Use after free in ServiceWorker
- CVE-2026-7923: Out of bounds write in Skia
- CVE-2026-7924: Uninitialized Use in Dawn
- CVE-2026-7925: Use after free in Chromoting
- CVE-2026-7926: Use after free in PresentationAPI
- CVE-2026-7927: Type Confusion in Runtime
- CVE-2026-7928: Use after free in WebRTC
- CVE-2026-7929: Use after free in MediaRecording
- CVE-2026-7930: Insufficient validation of untrusted input in Cookies
- CVE-2026-7931: Insufficient validation of untrusted input in iOS
- CVE-2026-7932: Insufficient policy enforcement in Downloads
- CVE-2026-7933: Out of bounds read in WebCodecs
- CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker
- CVE-2026-7935: Inappropriate implementation in Speech
- CVE-2026-7936: Object lifecycle issue in V8
- CVE-2026-7937: Insufficient policy enforcement in DevTools
- CVE-2026-7938: Use after free in CSS
- CVE-2026-7939: Inappropriate implementation in SanitizerAPI
- CVE-2026-7940: Use after free in V8
- CVE-2026-7941: Insufficient validation of untrusted input in Mobile
- CVE-2026-7942: Integer overflow in ANGLE
- CVE-2026-7943: Insufficient validation of untrusted input in ANGLE
- CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache
- CVE-2026-7945: Insufficient validation of untrusted input in COOP
- CVE-2026-7946: Insufficient policy enforcement in WebUI
- CVE-2026-7947: Insufficient validation of untrusted input in Network
- CVE-2026-7948: Race in Chromoting
- CVE-2026-7949: Out of bounds read in Skia
- CVE-2026-7950: Out of bounds read and write in GFX
- CVE-2026-7951: Out of bounds write in WebRTC
- CVE-2026-7952: Insufficient policy enforcement in Extensions
- CVE-2026-7953: Insufficient validation of untrusted input in Omnibox
- CVE-2026-7954: Race in Shared Storage
- CVE-2026-7955: Uninitialized Use in GPU
- CVE-2026-7956: Use after free in Navigation
- CVE-2026-7957: Out of bounds write in Media
- CVE-2026-7958: Inappropriate implementation in ServiceWorker
- CVE-2026-7959: Inappropriate implementation in Navigation
- CVE-2026-7960: Race in Speech
- CVE-2026-7961: Insufficient validation of untrusted input in Permissions
- CVE-2026-7962: Insufficient policy enforcement in DirectSockets
- CVE-2026-7963: Inappropriate implementation in ServiceWorker
- CVE-2026-7964: Insufficient validation of untrusted input in FileSystem
- CVE-2026-7965: Insufficient validation of untrusted input in DevTools
- CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation
- CVE-2026-7967: Insufficient validation of untrusted input in Navigation
- CVE-2026-7968: Insufficient validation of untrusted input in CORS
- CVE-2026-7969: Integer overflow in Network
- CVE-2026-7970: Use after free in TopChrome
- CVE-2026-7971: Inappropriate implementation in ORB
- CVE-2026-7972: Uninitialized Use in GPU
- CVE-2026-7973: Integer overflow in Dawn
- CVE-2026-7974: Use after free in Blink
- CVE-2026-7975: Use after free in DevTools
- CVE-2026-7976: Use after free in Views
- CVE-2026-7977: Inappropriate implementation in Canvas
- CVE-2026-7978: Inappropriate implementation in Companion
- CVE-2026-7979: Inappropriate implementation in Media
- CVE-2026-7980: Use after free in WebAudio
- CVE-2026-7981: Out of bounds read in Codecs
- CVE-2026-7982: Uninitialized Use in WebCodecs
- CVE-2026-7983: Out of bounds read in Dawn
- CVE-2026-7984: Use after free in ReadingMode
- CVE-2026-7985: Use after free in GPU
- CVE-2026-7986: Insufficient policy enforcement in Autofill
- CVE-2026-7987: Use after free in WebRTC
- CVE-2026-7988: Type Confusion in WebRTC
- CVE-2026-7989: Insufficient data validation in DataTransfer
- CVE-2026-7990: Insufficient validation of untrusted input in Updater
- CVE-2026-7991: Use after free in UI
- CVE-2026-7992: Insufficient validation of untrusted input in UI
- CVE-2026-7993: Insufficient validation of untrusted input in Payments
- CVE-2026-7994: Inappropriate implementation in Chromoting
- CVE-2026-7995: Out of bounds read in AdFilter
- CVE-2026-7996: Insufficient validation of untrusted input in SSL
- CVE-2026-7997: Insufficient validation of untrusted input in Updater
- CVE-2026-7998: Insufficient validation of untrusted input in Dialog
- CVE-2026-7999: Inappropriate implementation in V8
- CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver
- CVE-2026-8001: Use after free in Printing
- CVE-2026-8002: Use after free in Audio
- CVE-2026-8003: Insufficient validation of untrusted input in TabGroups
- CVE-2026-8004: Insufficient policy enforcement in DevTools
- CVE-2026-8005: Insufficient validation of untrusted input in Cast
- CVE-2026-8006: Insufficient policy enforcement in DevTools
- CVE-2026-8007: Insufficient validation of untrusted input in Cast
- CVE-2026-8008: Inappropriate implementation in DevTools
- CVE-2026-8009: Inappropriate implementation in Cast
- CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation
- CVE-2026-8011: Insufficient policy enforcement in Search
- CVE-2026-8012: Inappropriate implementation in MHTML
- CVE-2026-8013: Insufficient validation of untrusted input in FedCM
- CVE-2026-8014: Inappropriate implementation in Preload
- CVE-2026-8015: Inappropriate implementation in Media
- CVE-2026-8016: Use after free in WebRTC
- CVE-2026-8017: Side-channel information leakage in Media
- CVE-2026-8018: Insufficient policy enforcement in DevTools
- CVE-2026-8019: Insufficient policy enforcement in WebApp
- CVE-2026-8020: Uninitialized Use in GPU
- CVE-2026-8021: Script injection in UI
- CVE-2026-8022: Inappropriate implementation in MHTML
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1264175
- SUSE Bug 1265159
- SUSE CVE CVE-2026-7896 page
- SUSE CVE CVE-2026-7897 page
- SUSE CVE CVE-2026-7898 page
- SUSE CVE CVE-2026-7899 page
- SUSE CVE CVE-2026-7900 page
- SUSE CVE CVE-2026-7901 page
- SUSE CVE CVE-2026-7902 page
- SUSE CVE CVE-2026-7903 page
- SUSE CVE CVE-2026-7904 page
- SUSE CVE CVE-2026-7905 page
- SUSE CVE CVE-2026-7906 page
- SUSE CVE CVE-2026-7907 page
- SUSE CVE CVE-2026-7908 page
- SUSE CVE CVE-2026-7909 page
- SUSE CVE CVE-2026-7910 page
- SUSE CVE CVE-2026-7911 page
- SUSE CVE CVE-2026-7912 page
Описание
Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-7896
- SUSE Bug 1264175
Описание
Use after free in Mobile in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-7897
- SUSE Bug 1264175
Описание
Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-7898
- SUSE Bug 1264175
Описание
Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7899
- SUSE Bug 1264175
Описание
Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7900
- SUSE Bug 1264175
Описание
Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7901
- SUSE Bug 1264175
Описание
Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7902
- SUSE Bug 1264175
Описание
Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7903
- SUSE Bug 1264175
Описание
Out of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7904
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7905
- SUSE Bug 1264175
Описание
Use after free in SVG in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7906
- SUSE Bug 1264175
Описание
Use after free in DOM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7907
- SUSE Bug 1264175
Описание
Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7908
- SUSE Bug 1264175
Описание
Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7909
- SUSE Bug 1264175
Описание
Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7910
- SUSE Bug 1264175
Описание
Use after free in Aura in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7911
- SUSE Bug 1264175
Описание
Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7912
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7913
- SUSE Bug 1264175
Описание
Type Confusion in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7914
- SUSE Bug 1264175
Описание
Insufficient data validation in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7915
- SUSE Bug 1264175
Описание
Insufficient data validation in InterestGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7916
- SUSE Bug 1264175
Описание
Use after free in Fullscreen in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7917
- SUSE Bug 1264175
Описание
Use after free in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7918
- SUSE Bug 1264175
Описание
Use after free in Aura in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7919
- SUSE Bug 1264175
Описание
Use after free in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7920
- SUSE Bug 1264175
Описание
Use after free in Passwords in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7921
- SUSE Bug 1264175
Описание
Use after free in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7922
- SUSE Bug 1264175
Описание
Out of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7923
- SUSE Bug 1264175
Описание
Uninitialized Use in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7924
- SUSE Bug 1264175
Описание
Use after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7925
- SUSE Bug 1264175
Описание
Use after free in PresentationAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7926
- SUSE Bug 1264175
Описание
Type Confusion in Runtime in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7927
- SUSE Bug 1264175
Описание
Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7928
- SUSE Bug 1264175
Описание
Use after free in MediaRecording in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-7929
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Cookies in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7930
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7931
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7932
- SUSE Bug 1264175
Описание
Out of bounds read in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7933
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7934
- SUSE Bug 1264175
Описание
Inappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7935
- SUSE Bug 1264175
Описание
Object lifecycle issue in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7936
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7937
- SUSE Bug 1264175
Описание
Use after free in CSS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7938
- SUSE Bug 1264175
Описание
Inappropriate implementation in SanitizerAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7939
- SUSE Bug 1264175
Описание
Use after free in V8 in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7940
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7941
- SUSE Bug 1264175
Описание
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7942
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7943
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Persistent Cache in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7944
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7945
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7946
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7947
- SUSE Bug 1264175
Описание
Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7948
- SUSE Bug 1264175
Описание
Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7949
- SUSE Bug 1264175
Описание
Out of bounds read and write in GFX in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary read/write via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7950
- SUSE Bug 1264175
Описание
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7951
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in Extensions in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7952
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7953
- SUSE Bug 1264175
Описание
Race in Shared Storage in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7954
- SUSE Bug 1264175
Описание
Uninitialized Use in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7955
- SUSE Bug 1264175
Описание
Use after free in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7956
- SUSE Bug 1264175
Описание
Out of bounds write in Media in Google Chrome on Mac, iOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7957
- SUSE Bug 1264175
Описание
Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7958
- SUSE Bug 1264175
Описание
Inappropriate implementation in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7959
- SUSE Bug 1264175
Описание
Race in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7960
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Permissions in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7961
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in DirectSockets in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary read/write via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7962
- SUSE Bug 1264175
Описание
Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7963
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in FileSystem in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7964
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7965
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7966
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7967
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in CORS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7968
- SUSE Bug 1264175
Описание
Integer overflow in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7969
- SUSE Bug 1264175
Описание
Use after free in TopChrome in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7970
- SUSE Bug 1264175
Описание
Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7971
- SUSE Bug 1264175
Описание
Uninitialized Use in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7972
- SUSE Bug 1264175
Описание
Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7973
- SUSE Bug 1264175
Описание
Use after free in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7974
- SUSE Bug 1264175
Описание
Use after free in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7975
- SUSE Bug 1264175
Описание
Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7976
- SUSE Bug 1264175
Описание
Inappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7977
- SUSE Bug 1264175
Описание
Inappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7978
- SUSE Bug 1264175
Описание
Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7979
- SUSE Bug 1264175
Описание
Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7980
- SUSE Bug 1264175
Описание
Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7981
- SUSE Bug 1264175
Описание
Uninitialized Use in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7982
- SUSE Bug 1264175
Описание
Out of bounds read in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7983
- SUSE Bug 1264175
Описание
Use after free in ReadingMode in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7984
- SUSE Bug 1264175
Описание
Use after free in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7985
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in Autofill in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7986
- SUSE Bug 1264175
Описание
Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7987
- SUSE Bug 1264175
Описание
Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7988
- SUSE Bug 1264175
Описание
Insufficient data validation in DataTransfer in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7989
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7990
- SUSE Bug 1264175
Описание
Use after free in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7991
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7992
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7993
- SUSE Bug 1264175
Описание
Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7994
- SUSE Bug 1264175
Описание
Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-7995
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in SSL in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-7996
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-7997
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Dialog in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-7998
- SUSE Bug 1264175
Описание
Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-7999
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8000
- SUSE Bug 1264175
Описание
Use After Free in Printing in Google Chrome on Linux, Mac, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8001
- SUSE Bug 1264175
Описание
Use after free in Audio in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8002
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in TabGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8003
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8004
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8005
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8006
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8007
- SUSE Bug 1264175
Описание
Inappropriate implementation in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8008
- SUSE Bug 1264175
Описание
Inappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8009
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8010
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in Search in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8011
- SUSE Bug 1264175
Описание
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8012
- SUSE Bug 1264175
Описание
Insufficient validation of untrusted input in FedCM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8013
- SUSE Bug 1264175
Описание
Inappropriate implementation in Preload in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8014
- SUSE Bug 1264175
Описание
Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8015
- SUSE Bug 1264175
Описание
Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8016
- SUSE Bug 1264175
Описание
Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8017
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8018
- SUSE Bug 1264175
Описание
Insufficient policy enforcement in WebApp in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8019
- SUSE Bug 1264175
Описание
Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8020
- SUSE Bug 1264175
Описание
Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8021
- SUSE Bug 1264175
Описание
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted MHTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-8022
- SUSE Bug 1264175