Описание
Security update for chromium
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 153.0.8010.52 (boo#1281123):
- CVE-2026-93374: Use after free in Dawn
- CVE-2026-93372: Buffer overflow in WebGL
- CVE-2026-93375: Incorrect reference resolution in Tracing
- CVE-2026-93382: Use after free in PDFium
- CVE-2026-93387: Improper state validation in Skia
- CVE-2026-93373: Use after free in Extensions
- CVE-2026-93381: Buffer overflow in PDFium
- CVE-2026-93379: Incorrect authorization in ORB
- CVE-2026-93377: Type confusion in V8
- CVE-2026-93380: Race condition in FileSystem
- CVE-2026-93384: Server-side request forgery in Omnibox
- CVE-2026-93383: Information leak in Permissions
- CVE-2026-93376: Out of bounds read in DataTransfer
- CVE-2026-93378: Missing authorization in Storage
- CVE-2026-93385: Information leak in Paint
- CVE-2026-93386: UI misrepresentation in WebAppInstalls
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1281123
- SUSE CVE CVE-2026-93372 page
- SUSE CVE CVE-2026-93373 page
- SUSE CVE CVE-2026-93374 page
- SUSE CVE CVE-2026-93375 page
- SUSE CVE CVE-2026-93376 page
- SUSE CVE CVE-2026-93377 page
- SUSE CVE CVE-2026-93378 page
- SUSE CVE CVE-2026-93379 page
- SUSE CVE CVE-2026-93380 page
- SUSE CVE CVE-2026-93381 page
- SUSE CVE CVE-2026-93382 page
- SUSE CVE CVE-2026-93383 page
- SUSE CVE CVE-2026-93384 page
- SUSE CVE CVE-2026-93385 page
- SUSE CVE CVE-2026-93386 page
- SUSE CVE CVE-2026-93387 page
Описание
Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-93372
- SUSE Bug 1281123
Описание
Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-93373
- SUSE Bug 1281123
Описание
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Затронутые продукты
Ссылки
- CVE-2026-93374
- SUSE Bug 1281123
Описание
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-93375
- SUSE Bug 1281123
Описание
Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-93376
- SUSE Bug 1281123
Описание
Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-93377
- SUSE Bug 1281123
Описание
Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-93378
- SUSE Bug 1281123
Описание
Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-93379
- SUSE Bug 1281123
Описание
Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-93380
- SUSE Bug 1281123
Описание
Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-93381
- SUSE Bug 1281123
Описание
Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-93382
- SUSE Bug 1281123
Описание
Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-93383
- SUSE Bug 1281123
Описание
Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-93384
- SUSE Bug 1281123
Описание
Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2026-93385
- SUSE Bug 1281123
Описание
UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2026-93386
- SUSE Bug 1281123
Описание
Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2026-93387
- SUSE Bug 1281123