Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 151.0.7922.108 (boo#1274549):
- CVE-2026-19137: Use after free in WebGL
- CVE-2026-19149: Use after free in Aura
- CVE-2026-19154: Use after free in Skia
- CVE-2026-19157: Out of bounds write in ANGLE
- CVE-2026-19170: Use after free in WebGL
- CVE-2026-19172: Use after free in Views
- CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks
- CVE-2026-19168: Inappropriate implementation in V8
- CVE-2026-19138: Heap buffer overflow in CrashReporting
- CVE-2026-19139: Race in CredentialProvider
- CVE-2026-19140: Use after free in GPU
- CVE-2026-19141: Use after free in Resources
- CVE-2026-19142: Use after free in Views
- CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
- CVE-2026-19144: Use after free in HTML
- CVE-2026-19145: Use after free in Translate
- CVE-2026-19146: Uninitialized Use in GPU
- CVE-2026-19147: Use after free in Aura
- CVE-2026-19148: Out of bounds write in GPU
- CVE-2026-19150: Inappropriate implementation in V8
- CVE-2026-19151: Use after free in V8
- CVE-2026-19152: Inappropriate implementation in Navigation
- CVE-2026-19153: Insufficient validation of untrusted input in Workers
- CVE-2026-19155: Use after free in Payments
- CVE-2026-19156: Heap buffer overflow in Base
- CVE-2026-19158: Use after free in Views
- CVE-2026-19159: Use after free in Views
- CVE-2026-19160: Uninitialized Use in Skia
- CVE-2026-19161: Uninitialized Use in Skia
- CVE-2026-19162: Out of bounds write in V8
- CVE-2026-19163: Use after free in Media
- CVE-2026-19164: Insufficient validation of untrusted input in Codecs
- CVE-2026-19165: Use after free in Extensions
- CVE-2026-19166: Use after free in Web Authentication
- CVE-2026-19167: Integer overflow in GPU
- CVE-2026-19171: Use after free in Media
- CVE-2026-19173: Out of bounds write in Skia
- CVE-2026-19174: Integer overflow in V8
- CVE-2026-19175: Use after free in Payments
- CVE-2026-19176: Use after free in Skia
- CVE-2026-19177: Insufficient validation of untrusted input in UI
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1274549
- SUSE CVE CVE-2026-19137 page
- SUSE CVE CVE-2026-19138 page
- SUSE CVE CVE-2026-19139 page
- SUSE CVE CVE-2026-19140 page
- SUSE CVE CVE-2026-19141 page
- SUSE CVE CVE-2026-19142 page
- SUSE CVE CVE-2026-19143 page
- SUSE CVE CVE-2026-19144 page
- SUSE CVE CVE-2026-19145 page
- SUSE CVE CVE-2026-19146 page
- SUSE CVE CVE-2026-19147 page
- SUSE CVE CVE-2026-19148 page
- SUSE CVE CVE-2026-19149 page
- SUSE CVE CVE-2026-19150 page
- SUSE CVE CVE-2026-19151 page
- SUSE CVE CVE-2026-19152 page
- SUSE CVE CVE-2026-19153 page
- SUSE CVE CVE-2026-19154 page
Описание
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-19137
- SUSE Bug 1274549
Описание
Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19138
- SUSE Bug 1274549
Описание
Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19139
- SUSE Bug 1274549
Описание
Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19140
- SUSE Bug 1274549
Описание
Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19141
- SUSE Bug 1274549
Описание
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19142
- SUSE Bug 1274549
Описание
Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19143
- SUSE Bug 1274549
Описание
Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19144
- SUSE Bug 1274549
Описание
Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19145
- SUSE Bug 1274549
Описание
Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19146
- SUSE Bug 1274549
Описание
Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19147
- SUSE Bug 1274549
Описание
Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19148
- SUSE Bug 1274549
Описание
Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-19149
- SUSE Bug 1274549
Описание
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19150
- SUSE Bug 1274549
Описание
Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19151
- SUSE Bug 1274549
Описание
Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19152
- SUSE Bug 1274549
Описание
Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19153
- SUSE Bug 1274549
Описание
Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-19154
- SUSE Bug 1274549
Описание
Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19155
- SUSE Bug 1274549
Описание
Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19156
- SUSE Bug 1274549
Описание
Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-19157
- SUSE Bug 1274549
Описание
Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19158
- SUSE Bug 1274549
Описание
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19159
- SUSE Bug 1274549
Описание
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19160
- SUSE Bug 1274549
Описание
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19161
- SUSE Bug 1274549
Описание
Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19162
- SUSE Bug 1274549
Описание
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19163
- SUSE Bug 1274549
Описание
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19164
- SUSE Bug 1274549
Описание
Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19165
- SUSE Bug 1274549
Описание
Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19166
- SUSE Bug 1274549
Описание
Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19167
- SUSE Bug 1274549
Описание
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19168
- SUSE Bug 1274549
Описание
Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19169
- SUSE Bug 1274549
Описание
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-19170
- SUSE Bug 1274549
Описание
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19171
- SUSE Bug 1274549
Описание
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-19172
- SUSE Bug 1274549
Описание
Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19173
- SUSE Bug 1274549
Описание
Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19174
- SUSE Bug 1274549
Описание
Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19175
- SUSE Bug 1274549
Описание
Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19176
- SUSE Bug 1274549
Описание
Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-19177
- SUSE Bug 1274549