Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 150.0.7871.124 (boo#1271415):
- CVE-2026-15764: Use after free in Ozone
- CVE-2026-15765: Use after free in Ozone
- CVE-2026-15766: Uninitialized Use in Skia
- CVE-2026-15767: Heap buffer overflow in libyuv
- CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas
- CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming
- CVE-2026-15770: Uninitialized Use in V8
- CVE-2026-15771: Insufficient validation of untrusted input in Media
- CVE-2026-15772: Use after free in GPU
- CVE-2026-15773: Use after free in Core
- CVE-2026-15774: Use after free in Skia
- CVE-2026-15775: Insufficient policy enforcement in V8
- CVE-2026-15776: Type Confusion in V8
- CVE-2026-15777: Use after free in UI
- CVE-2026-15778: Insufficient validation of untrusted input in Navigation
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1271415
- SUSE CVE CVE-2026-15764 page
- SUSE CVE CVE-2026-15765 page
- SUSE CVE CVE-2026-15766 page
- SUSE CVE CVE-2026-15767 page
- SUSE CVE CVE-2026-15768 page
- SUSE CVE CVE-2026-15769 page
- SUSE CVE CVE-2026-15770 page
- SUSE CVE CVE-2026-15771 page
- SUSE CVE CVE-2026-15772 page
- SUSE CVE CVE-2026-15773 page
- SUSE CVE CVE-2026-15774 page
- SUSE CVE CVE-2026-15775 page
- SUSE CVE CVE-2026-15776 page
- SUSE CVE CVE-2026-15777 page
- SUSE CVE CVE-2026-15778 page
Описание
Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-15764
- SUSE Bug 1271415
Описание
Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-15765
- SUSE Bug 1271415
Описание
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15766
- SUSE Bug 1271415
Описание
Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15767
- SUSE Bug 1271415
Описание
Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15768
- SUSE Bug 1271415
Описание
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15769
- SUSE Bug 1271415
Описание
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15770
- SUSE Bug 1271415
Описание
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15771
- SUSE Bug 1271415
Описание
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15772
- SUSE Bug 1271415
Описание
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15773
- SUSE Bug 1271415
Описание
Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15774
- SUSE Bug 1271415
Описание
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15775
- SUSE Bug 1271415
Описание
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15776
- SUSE Bug 1271415
Описание
Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15777
- SUSE Bug 1271415
Описание
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-15778
- SUSE Bug 1271415