Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
-
Chromium 152.0.7977.82 (boo#1278683):
- CVE-2026-85046: Type confusion in V8
- CVE-2026-85052: Out of bounds read in CrashReporting
- CVE-2026-85043: Incomplete cleanup in Network
- CVE-2026-85048: Use after free in Compositing
- CVE-2026-85045: Race condition in V8
- CVE-2026-85050: Out of bounds write in WebGL
- CVE-2026-85053: Improper resource exposure in CacheStorage
- CVE-2026-85042: Use after free in DevTools
- CVE-2026-85049: Use after free in Skia
- CVE-2026-85051: Type confusion in Compositing
- CVE-2026-85047: Improper input validation in Transactions Platform
- CVE-2026-85044: Use of released resource in Mobile
-
Chromium 152.0.7977.75 (boo#1278072):
- CVE-2026-84353: Use after free in Shared Tab Groups
- CVE-2026-84352: Use after free in WebGL
- CVE-2026-84354: Incorrect authorization in FileSystem
- CVE-2026-84359: Information leak in Skia
- CVE-2026-84357: Improper input validation in Omnibox
- CVE-2026-84324: Use after free in Proxy
- CVE-2026-84349: Use after free in Browser
- CVE-2026-84326: Uninitialized resource in V8
- CVE-2026-84333: Use after free in Dawn
- CVE-2026-84351: Buffer overflow in GPU
- CVE-2026-84325: Improper input validation in DataTransfer
- CVE-2026-84328: Missing authorization in FileSystem
- CVE-2026-84347: Use after free in WebRTC
- CVE-2026-84323: Missing authorization in FileSystem
- CVE-2026-84355: Incorrect authorization in Navigation
- CVE-2026-84358: Improper privilege management in Downloads
- CVE-2026-84332: Incorrect authorization in SiteSettings
- CVE-2026-84330: UI misrepresentation in FullScreen
- CVE-2026-84334: Incorrect authorization in Chromoting
- CVE-2026-84348: Information leak in MediaCapture
- CVE-2026-84335: Incorrect authorization in TabStrip
- CVE-2026-84327: Incorrect authorization in Autofill
- CVE-2026-84329: Confused deputy in CredentialProvider
- CVE-2026-84356: UI misrepresentation in FullScreen
- CVE-2026-84350: Use after free in TabStrip
- CVE-2026-84331: Incorrect authorization in Actor
-
Disabled EULA dialog to use preferences instead of a hardcoded return
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1278072
- SUSE Bug 1278683
- SUSE CVE CVE-2026-84323 page
- SUSE CVE CVE-2026-84324 page
- SUSE CVE CVE-2026-84325 page
- SUSE CVE CVE-2026-84326 page
- SUSE CVE CVE-2026-84327 page
- SUSE CVE CVE-2026-84328 page
- SUSE CVE CVE-2026-84329 page
- SUSE CVE CVE-2026-84330 page
- SUSE CVE CVE-2026-84331 page
- SUSE CVE CVE-2026-84332 page
- SUSE CVE CVE-2026-84333 page
- SUSE CVE CVE-2026-84334 page
- SUSE CVE CVE-2026-84335 page
- SUSE CVE CVE-2026-84347 page
- SUSE CVE CVE-2026-84348 page
- SUSE CVE CVE-2026-84349 page
- SUSE CVE CVE-2026-84350 page
Описание
Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-84323
- SUSE Bug 1278072
Описание
Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-84324
- SUSE Bug 1278072
Описание
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-84325
- SUSE Bug 1278072
Описание
Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-84326
- SUSE Bug 1278072
Описание
Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-84327
- SUSE Bug 1278072
Описание
Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-84328
- SUSE Bug 1278072
Описание
Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-84329
- SUSE Bug 1278072
Описание
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-84330
- SUSE Bug 1278072
Описание
Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-84331
- SUSE Bug 1278072
Описание
Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-84332
- SUSE Bug 1278072
Описание
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-84333
- SUSE Bug 1278072
Описание
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-84334
- SUSE Bug 1278072
Описание
Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-84335
- SUSE Bug 1278072
Описание
Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-84347
- SUSE Bug 1278072
Описание
Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-84348
- SUSE Bug 1278072
Описание
Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-84349
- SUSE Bug 1278072
Описание
Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-84350
- SUSE Bug 1278072
Описание
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-84351
- SUSE Bug 1278072
Описание
Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-84352
- SUSE Bug 1278072
Описание
Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-84353
- SUSE Bug 1278072
Описание
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-84354
- SUSE Bug 1278072
Описание
Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-84355
- SUSE Bug 1278072
Описание
UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-84356
- SUSE Bug 1278072
Описание
Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-84357
- SUSE Bug 1278072
Описание
Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-84358
- SUSE Bug 1278072
Описание
Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-84359
- SUSE Bug 1278072
Описание
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-85042
- SUSE Bug 1278683
Описание
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-85043
- SUSE Bug 1278683
Описание
Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-85044
- SUSE Bug 1278683
Описание
Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-85045
- SUSE Bug 1278683
Описание
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-85046
- SUSE Bug 1278683
Описание
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-85047
- SUSE Bug 1278683
Описание
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-85048
- SUSE Bug 1278683
Описание
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-85049
- SUSE Bug 1278683
Описание
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-85050
- SUSE Bug 1278683
Описание
Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-85051
- SUSE Bug 1278683
Описание
Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-85052
- SUSE Bug 1278683
Описание
Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-85053
- SUSE Bug 1278683