Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 150.0.7871.128 (boo#1271656):
- CVE-2026-15899: Use after free in CameraCapture
- CVE-2026-15900: Use after free in GPU
- CVE-2026-15901: Use after free in Network
- CVE-2026-15902: Use after free in Cast
- CVE-2026-15903: Out of bounds read and write in V8
- CVE-2026-15904: Use after free in Ozone
- CVE-2026-15905: Use after free in Aura
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1271656
- SUSE CVE CVE-2026-15899 page
- SUSE CVE CVE-2026-15900 page
- SUSE CVE CVE-2026-15901 page
- SUSE CVE CVE-2026-15902 page
- SUSE CVE CVE-2026-15903 page
- SUSE CVE CVE-2026-15904 page
- SUSE CVE CVE-2026-15905 page
Описание
Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-15899
- SUSE Bug 1271656
Описание
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-15900
- SUSE Bug 1271656
Описание
Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-15901
- SUSE Bug 1271656
Описание
Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15902
- SUSE Bug 1271656
Описание
Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15903
- SUSE Bug 1271656
Описание
Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15904
- SUSE Bug 1271656
Описание
Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-15905
- SUSE Bug 1271656