Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 150.0.7871.181 (boo#1272156):
- CVE-2026-16420: Type Confusion in WebAudio
- CVE-2026-16421: Inappropriate implementation in WebAudio
- CVE-2026-16413: Out of bounds write in ANGLE
- CVE-2026-16414: Insufficient validation of untrusted input in Chromecast
- CVE-2026-16415: Insufficient validation of untrusted input in Extensions
- CVE-2026-16416: Integer overflow in Chromecast
- CVE-2026-16417: Uninitialized Use in Skia
- CVE-2026-16418: Stack buffer overflow in V8
- CVE-2026-16419: Out of bounds read and write in ANGLE
- CVE-2026-16422: Insufficient validation of untrusted input in Certificate
- CVE-2026-16423: Use after free in UI
- CVE-2026-16424: Use after free in GPU
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1272156
- SUSE CVE CVE-2026-16413 page
- SUSE CVE CVE-2026-16414 page
- SUSE CVE CVE-2026-16415 page
- SUSE CVE CVE-2026-16416 page
- SUSE CVE CVE-2026-16417 page
- SUSE CVE CVE-2026-16418 page
- SUSE CVE CVE-2026-16419 page
- SUSE CVE CVE-2026-16420 page
- SUSE CVE CVE-2026-16421 page
- SUSE CVE CVE-2026-16422 page
- SUSE CVE CVE-2026-16423 page
- SUSE CVE CVE-2026-16424 page
Описание
Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16413
- SUSE Bug 1272156
Описание
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16414
- SUSE Bug 1272156
Описание
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16415
- SUSE Bug 1272156
Описание
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16416
- SUSE Bug 1272156
Описание
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16417
- SUSE Bug 1272156
Описание
Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16418
- SUSE Bug 1272156
Описание
Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16419
- SUSE Bug 1272156
Описание
Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16420
- SUSE Bug 1272156
Описание
Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16421
- SUSE Bug 1272156
Описание
Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16422
- SUSE Bug 1272156
Описание
Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16423
- SUSE Bug 1272156
Описание
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-16424
- SUSE Bug 1272156