Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 153.0.8010.47 (boo#1280687):
- CVE-2026-91726: Out of bounds read in WebGL
- CVE-2026-91721: Use after free in Internals
- CVE-2026-91749: Use after free in Workers
- CVE-2026-91724: Use after free in Input
- CVE-2026-91728: Integer overflow in V8
- CVE-2026-91734: Incorrect authorization in Core
- CVE-2026-91727: Incorrect reference resolution in Extensions
- CVE-2026-91743: Race condition in Core
- CVE-2026-91744: Race condition in PlatformIntegration
- CVE-2026-91712: Race condition in Extensions
- CVE-2026-91748: Race condition in Extensions
- CVE-2026-91720: Uninitialized resource in ANGLE
- CVE-2026-91731: Type confusion in Compositing
- CVE-2026-91747: Use after free in Skia
- CVE-2026-91733: Improper state validation in Skia
- CVE-2026-91741: Type confusion in CacheStorage
- CVE-2026-91709: Type confusion in ServiceWorker
- CVE-2026-91717: Missing authorization in Android
- CVE-2026-91735: Incorrect authorization in WebUI
- CVE-2026-91708: Race condition in Network
- CVE-2026-91736: Use after free in DOM
- CVE-2026-91740: Uninitialized resource in Skia
- CVE-2026-91710: Use after free in WebAppInstalls
- CVE-2026-91718: Use after free in Core
- CVE-2026-91716: Use after free in Auth
- CVE-2026-91746: Integer overflow in Compositing
- CVE-2026-91729: Use after free in DigitalCredentials
- CVE-2026-91737: Use after free in PDF
- CVE-2026-91711: Out of bounds write in ServiceWorker
- CVE-2026-91715: Type confusion in ServiceWorker
- CVE-2026-91745: Use after free in V8
- CVE-2026-91723: Race condition in WebAppInstalls
- CVE-2026-91732: Missing authorization in AppManifest
- CVE-2026-91742: Confused deputy in PriceTracking
- CVE-2026-91714: Observable discrepancy in Fonts
- CVE-2026-91725: Observable discrepancy in CSS
- CVE-2026-91739: Missing authorization in Transactions Platform
- CVE-2026-91713: Missing authorization in Browser
- CVE-2026-91738: Improper input validation in ANGLE
- CVE-2026-91730: Incomplete cleanup in GetUserMedia
- CVE-2026-91722: Use after free in Input
- CVE-2026-91719: Code injection in XML
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1280687
- SUSE CVE CVE-2026-91708 page
- SUSE CVE CVE-2026-91709 page
- SUSE CVE CVE-2026-91710 page
- SUSE CVE CVE-2026-91711 page
- SUSE CVE CVE-2026-91712 page
- SUSE CVE CVE-2026-91713 page
- SUSE CVE CVE-2026-91714 page
- SUSE CVE CVE-2026-91715 page
- SUSE CVE CVE-2026-91716 page
- SUSE CVE CVE-2026-91717 page
- SUSE CVE CVE-2026-91718 page
- SUSE CVE CVE-2026-91719 page
- SUSE CVE CVE-2026-91720 page
- SUSE CVE CVE-2026-91721 page
- SUSE CVE CVE-2026-91722 page
- SUSE CVE CVE-2026-91723 page
- SUSE CVE CVE-2026-91724 page
- SUSE CVE CVE-2026-91725 page
Описание
Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91708
- SUSE Bug 1280687
Описание
Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91709
- SUSE Bug 1280687
Описание
Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91710
- SUSE Bug 1280687
Описание
Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91711
- SUSE Bug 1280687
Описание
Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91712
- SUSE Bug 1280687
Описание
Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-91713
- SUSE Bug 1280687
Описание
Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-91714
- SUSE Bug 1280687
Описание
Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91715
- SUSE Bug 1280687
Описание
Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91716
- SUSE Bug 1280687
Описание
Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91717
- SUSE Bug 1280687
Описание
Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91718
- SUSE Bug 1280687
Описание
Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-91719
- SUSE Bug 1280687
Описание
Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91720
- SUSE Bug 1280687
Описание
Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-91721
- SUSE Bug 1280687
Описание
Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-91722
- SUSE Bug 1280687
Описание
Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-91723
- SUSE Bug 1280687
Описание
Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91724
- SUSE Bug 1280687
Описание
Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-91725
- SUSE Bug 1280687
Описание
Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-91726
- SUSE Bug 1280687
Описание
Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91727
- SUSE Bug 1280687
Описание
Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91728
- SUSE Bug 1280687
Описание
Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91729
- SUSE Bug 1280687
Описание
Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-91730
- SUSE Bug 1280687
Описание
Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91731
- SUSE Bug 1280687
Описание
Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-91732
- SUSE Bug 1280687
Описание
Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91733
- SUSE Bug 1280687
Описание
Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91734
- SUSE Bug 1280687
Описание
Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91735
- SUSE Bug 1280687
Описание
Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91736
- SUSE Bug 1280687
Описание
Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91737
- SUSE Bug 1280687
Описание
Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-91738
- SUSE Bug 1280687
Описание
Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-91739
- SUSE Bug 1280687
Описание
Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91740
- SUSE Bug 1280687
Описание
Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91741
- SUSE Bug 1280687
Описание
Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-91742
- SUSE Bug 1280687
Описание
Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91743
- SUSE Bug 1280687
Описание
Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91744
- SUSE Bug 1280687
Описание
Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91745
- SUSE Bug 1280687
Описание
Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91746
- SUSE Bug 1280687
Описание
Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91747
- SUSE Bug 1280687
Описание
Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-91748
- SUSE Bug 1280687
Описание
Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-91749
- SUSE Bug 1280687