Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21799-1

Опубликовано: 05 сент. 2026
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Changes in chromium:

  • Chromium 152.0.7977.82 (boo#1278683):

    • CVE-2026-85046: Type confusion in V8
    • CVE-2026-85052: Out of bounds read in CrashReporting
    • CVE-2026-85043: Incomplete cleanup in Network
    • CVE-2026-85048: Use after free in Compositing
    • CVE-2026-85045: Race condition in V8
    • CVE-2026-85050: Out of bounds write in WebGL
    • CVE-2026-85053: Improper resource exposure in CacheStorage
    • CVE-2026-85042: Use after free in DevTools
    • CVE-2026-85049: Use after free in Skia
    • CVE-2026-85051: Type confusion in Compositing
    • CVE-2026-85047: Improper input validation in Transactions Platform
    • CVE-2026-85044: Use of released resource in Mobile
  • Chromium 152.0.7977.75 (boo#1278072):

    • CVE-2026-84353: Use after free in Shared Tab Groups
    • CVE-2026-84352: Use after free in WebGL
    • CVE-2026-84354: Incorrect authorization in FileSystem
    • CVE-2026-84359: Information leak in Skia
    • CVE-2026-84357: Improper input validation in Omnibox
    • CVE-2026-84324: Use after free in Proxy
    • CVE-2026-84349: Use after free in Browser
    • CVE-2026-84326: Uninitialized resource in V8
    • CVE-2026-84333: Use after free in Dawn
    • CVE-2026-84351: Buffer overflow in GPU
    • CVE-2026-84325: Improper input validation in DataTransfer
    • CVE-2026-84328: Missing authorization in FileSystem
    • CVE-2026-84347: Use after free in WebRTC
    • CVE-2026-84323: Missing authorization in FileSystem
    • CVE-2026-84355: Incorrect authorization in Navigation
    • CVE-2026-84358: Improper privilege management in Downloads
    • CVE-2026-84332: Incorrect authorization in SiteSettings
    • CVE-2026-84330: UI misrepresentation in FullScreen
    • CVE-2026-84334: Incorrect authorization in Chromoting
    • CVE-2026-84348: Information leak in MediaCapture
    • CVE-2026-84335: Incorrect authorization in TabStrip
    • CVE-2026-84327: Incorrect authorization in Autofill
    • CVE-2026-84329: Confused deputy in CredentialProvider
    • CVE-2026-84356: UI misrepresentation in FullScreen
    • CVE-2026-84350: Use after free in TabStrip
    • CVE-2026-84331: Incorrect authorization in Actor
  • Disabled EULA dialog to use preferences instead of a hardcoded return

Список пакетов

openSUSE Leap 16.0
chromedriver-152.0.7977.82-bp160.1.1
chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки

Описание

Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-152.0.7977.82-bp160.1.1
openSUSE Leap 16.0:chromium-152.0.7977.82-bp160.1.1

Ссылки
Уязвимость openSUSE-SU-2026:21799-1