Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21913-1

Опубликовано: 18 сент. 2026
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Changes in chromium:

  • Chromium 153.0.8010.47 (boo#1280687):
    • CVE-2026-91726: Out of bounds read in WebGL
    • CVE-2026-91721: Use after free in Internals
    • CVE-2026-91749: Use after free in Workers
    • CVE-2026-91724: Use after free in Input
    • CVE-2026-91728: Integer overflow in V8
    • CVE-2026-91734: Incorrect authorization in Core
    • CVE-2026-91727: Incorrect reference resolution in Extensions
    • CVE-2026-91743: Race condition in Core
    • CVE-2026-91744: Race condition in PlatformIntegration
    • CVE-2026-91712: Race condition in Extensions
    • CVE-2026-91748: Race condition in Extensions
    • CVE-2026-91720: Uninitialized resource in ANGLE
    • CVE-2026-91731: Type confusion in Compositing
    • CVE-2026-91747: Use after free in Skia
    • CVE-2026-91733: Improper state validation in Skia
    • CVE-2026-91741: Type confusion in CacheStorage
    • CVE-2026-91709: Type confusion in ServiceWorker
    • CVE-2026-91717: Missing authorization in Android
    • CVE-2026-91735: Incorrect authorization in WebUI
    • CVE-2026-91708: Race condition in Network
    • CVE-2026-91736: Use after free in DOM
    • CVE-2026-91740: Uninitialized resource in Skia
    • CVE-2026-91710: Use after free in WebAppInstalls
    • CVE-2026-91718: Use after free in Core
    • CVE-2026-91716: Use after free in Auth
    • CVE-2026-91746: Integer overflow in Compositing
    • CVE-2026-91729: Use after free in DigitalCredentials
    • CVE-2026-91737: Use after free in PDF
    • CVE-2026-91711: Out of bounds write in ServiceWorker
    • CVE-2026-91715: Type confusion in ServiceWorker
    • CVE-2026-91745: Use after free in V8
    • CVE-2026-91723: Race condition in WebAppInstalls
    • CVE-2026-91732: Missing authorization in AppManifest
    • CVE-2026-91742: Confused deputy in PriceTracking
    • CVE-2026-91714: Observable discrepancy in Fonts
    • CVE-2026-91725: Observable discrepancy in CSS
    • CVE-2026-91739: Missing authorization in Transactions Platform
    • CVE-2026-91713: Missing authorization in Browser
    • CVE-2026-91738: Improper input validation in ANGLE
    • CVE-2026-91730: Incomplete cleanup in GetUserMedia
    • CVE-2026-91722: Use after free in Input
    • CVE-2026-91719: Code injection in XML

Список пакетов

openSUSE Leap 16.0
chromedriver-153.0.8010.47-bp160.1.1
chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки

Описание

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.47-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.47-bp160.1.1

Ссылки
Уязвимость openSUSE-SU-2026:21913-1