Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 151.0.7922.169 (boo#1275706):
- CVE-2026-76034: Buffer overflow in WebGL
- CVE-2026-76036: Buffer overflow in Dawn
- CVE-2026-76033: Inappropriate implementation in CORS
- CVE-2026-76037: Link following in CredentialProvider
- CVE-2026-76044: Race condition in USB
- CVE-2026-76039: Incorrect reference resolution in Core
- CVE-2026-76040: Use after free in Browser
- CVE-2026-76035: Inappropriate implementation in Media
- CVE-2026-76042: Use of uninitialized resource in GPU
- CVE-2026-76046: Buffer overflow in ANGLE
- CVE-2026-76043: Incorrect calculation in V8
- CVE-2026-76041: Information leak in Skia
- CVE-2026-76047: Type confusion in V8
- CVE-2026-76038: Type confusion in V8
- CVE-2026-76045: Use after free in WebGL
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1275706
- SUSE CVE CVE-2026-76033 page
- SUSE CVE CVE-2026-76034 page
- SUSE CVE CVE-2026-76035 page
- SUSE CVE CVE-2026-76036 page
- SUSE CVE CVE-2026-76037 page
- SUSE CVE CVE-2026-76038 page
- SUSE CVE CVE-2026-76039 page
- SUSE CVE CVE-2026-76040 page
- SUSE CVE CVE-2026-76041 page
- SUSE CVE CVE-2026-76042 page
- SUSE CVE CVE-2026-76043 page
- SUSE CVE CVE-2026-76044 page
- SUSE CVE CVE-2026-76045 page
- SUSE CVE CVE-2026-76046 page
- SUSE CVE CVE-2026-76047 page
Описание
Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76033
- SUSE Bug 1275706
Описание
Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-76034
- SUSE Bug 1275706
Описание
Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76035
- SUSE Bug 1275706
Описание
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-76036
- SUSE Bug 1275706
Описание
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76037
- SUSE Bug 1275706
Описание
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76038
- SUSE Bug 1275706
Описание
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76039
- SUSE Bug 1275706
Описание
Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76040
- SUSE Bug 1275706
Описание
Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76041
- SUSE Bug 1275706
Описание
Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76042
- SUSE Bug 1275706
Описание
Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76043
- SUSE Bug 1275706
Описание
Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76044
- SUSE Bug 1275706
Описание
Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76045
- SUSE Bug 1275706
Описание
Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76046
- SUSE Bug 1275706
Описание
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-76047
- SUSE Bug 1275706