Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21921-1

Опубликовано: 20 сент. 2026
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Changes in chromium:

  • Chromium 153.0.8010.52 (boo#1281123):
    • CVE-2026-93374: Use after free in Dawn
    • CVE-2026-93372: Buffer overflow in WebGL
    • CVE-2026-93375: Incorrect reference resolution in Tracing
    • CVE-2026-93382: Use after free in PDFium
    • CVE-2026-93387: Improper state validation in Skia
    • CVE-2026-93373: Use after free in Extensions
    • CVE-2026-93381: Buffer overflow in PDFium
    • CVE-2026-93379: Incorrect authorization in ORB
    • CVE-2026-93377: Type confusion in V8
    • CVE-2026-93380: Race condition in FileSystem
    • CVE-2026-93384: Server-side request forgery in Omnibox
    • CVE-2026-93383: Information leak in Permissions
    • CVE-2026-93376: Out of bounds read in DataTransfer
    • CVE-2026-93378: Missing authorization in Storage
    • CVE-2026-93385: Information leak in Paint
    • CVE-2026-93386: UI misrepresentation in WebAppInstalls

Список пакетов

openSUSE Leap 16.0
chromedriver-153.0.8010.52-bp160.1.1
chromium-153.0.8010.52-bp160.1.1

Описание

Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки

Описание

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
openSUSE Leap 16.0:chromedriver-153.0.8010.52-bp160.1.1
openSUSE Leap 16.0:chromium-153.0.8010.52-bp160.1.1

Ссылки
Уязвимость openSUSE-SU-2026:21921-1