openSUSE-SU-2025:20032-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2025:20032-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2025:20032-1
Upstream
CVE (19)
Related
Published
2026-08-31T08:39:29Z
Modified
2026-09-06T18:26:26Z
Summary
Security update for chromium
Details

This update for chromium fixes the following issues:

Chromium 141.0.7390.122:

  • CVE-2025-12036: Inappropriate implementation in V8 (boo#1252402)

Chromium 141.0.7390.107:

  • CVE-2025-11756: Use after free in Safe Browsing (boo#1252013)

Chromium 141.0.7390.76:

  • Do not send URLs as AIM input. This is to resolve a privacy concern, around passing urls to AI Mode.

Chromium 141.0.7390.65 (boo#1251334):

  • CVE-2025-11458: Heap buffer overflow in Sync
  • CVE-2025-11460: Use after free in Storage
  • CVE-2025-11211: Out of bounds read in WebCodecs

Chromium 141.0.7390.54 (stable released 2025-09-30) (boo#1250780)

  • CVE-2025-11205: Heap buffer overflow in WebGPU
  • CVE-2025-11206: Heap buffer overflow in Video
  • CVE-2025-11207: Side-channel information leakage in Storage
  • CVE-2025-11208: Inappropriate implementation in Media
  • CVE-2025-11209: Inappropriate implementation in Omnibox
  • CVE-2025-11210: Side-channel information leakage in Tab
  • CVE-2025-11211: Out of bounds read in Media
  • CVE-2025-11212: Inappropriate implementation in Media
  • CVE-2025-11213: Inappropriate implementation in Omnibox
  • CVE-2025-11215: Off by one error in V8
  • CVE-2025-11216: Inappropriate implementation in Storage
  • CVE-2025-11219: Use after free in V8
  • Various fixes from internal audits, fuzzing and other initiatives

Chromium 141.0.7390.37 (beta released 2025-09-24)

Chromium 140.0.7339.207 (boo#1250472)

  • CVE-2025-10890: Side-channel information leakage in V8
  • CVE-2025-10891: Integer overflow in V8
  • CVE-2025-10892: Integer overflow in V8
References

Affected packages

openSUSE:Leap 16.0 / chromium

Package

Name
chromium
Purl
pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
141.0.7390.122-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "chromedriver":  "141.0.7390.122-bp160.1.1",
            "chromium":  "141.0.7390.122-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2025:20032-1.json"