openSUSE-SU-2026:21799-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21799-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21799-1
Upstream
CVE (38)
  • CVE-2026-84323
  • CVE-2026-84324
  • CVE-2026-84325
  • CVE-2026-84326
  • CVE-2026-84327
  • CVE-2026-84328
  • CVE-2026-84329
  • CVE-2026-84330
  • CVE-2026-84331
  • CVE-2026-84332
  • CVE-2026-84333
  • CVE-2026-84334
  • CVE-2026-84335
  • CVE-2026-84347
  • CVE-2026-84348
  • CVE-2026-84349
  • CVE-2026-84350
  • CVE-2026-84351
  • CVE-2026-84352
  • CVE-2026-84353
  • CVE-2026-84354
  • CVE-2026-84355
  • CVE-2026-84356
  • CVE-2026-84357
  • CVE-2026-84358
  • CVE-2026-84359
  • CVE-2026-85042
  • CVE-2026-85043
  • CVE-2026-85044
  • CVE-2026-85045
  • CVE-2026-85046
  • CVE-2026-85047
  • CVE-2026-85048
  • CVE-2026-85049
  • CVE-2026-85050
  • CVE-2026-85051
  • CVE-2026-85052
  • CVE-2026-85053
Related
Published
2026-09-05T23:43:46Z
Modified
2026-09-09T18:23:16Z
Summary
Security update for chromium
Details

This update for chromium fixes the following issues:

Changes in chromium:

  • Chromium 152.0.7977.82 (boo#1278683):

    • CVE-2026-85046: Type confusion in V8
    • CVE-2026-85052: Out of bounds read in CrashReporting
    • CVE-2026-85043: Incomplete cleanup in Network
    • CVE-2026-85048: Use after free in Compositing
    • CVE-2026-85045: Race condition in V8
    • CVE-2026-85050: Out of bounds write in WebGL
    • CVE-2026-85053: Improper resource exposure in CacheStorage
    • CVE-2026-85042: Use after free in DevTools
    • CVE-2026-85049: Use after free in Skia
    • CVE-2026-85051: Type confusion in Compositing
    • CVE-2026-85047: Improper input validation in Transactions Platform
    • CVE-2026-85044: Use of released resource in Mobile
  • Chromium 152.0.7977.75 (boo#1278072):

    • CVE-2026-84353: Use after free in Shared Tab Groups
    • CVE-2026-84352: Use after free in WebGL
    • CVE-2026-84354: Incorrect authorization in FileSystem
    • CVE-2026-84359: Information leak in Skia
    • CVE-2026-84357: Improper input validation in Omnibox
    • CVE-2026-84324: Use after free in Proxy
    • CVE-2026-84349: Use after free in Browser
    • CVE-2026-84326: Uninitialized resource in V8
    • CVE-2026-84333: Use after free in Dawn
    • CVE-2026-84351: Buffer overflow in GPU
    • CVE-2026-84325: Improper input validation in DataTransfer
    • CVE-2026-84328: Missing authorization in FileSystem
    • CVE-2026-84347: Use after free in WebRTC
    • CVE-2026-84323: Missing authorization in FileSystem
    • CVE-2026-84355: Incorrect authorization in Navigation
    • CVE-2026-84358: Improper privilege management in Downloads
    • CVE-2026-84332: Incorrect authorization in SiteSettings
    • CVE-2026-84330: UI misrepresentation in FullScreen
    • CVE-2026-84334: Incorrect authorization in Chromoting
    • CVE-2026-84348: Information leak in MediaCapture
    • CVE-2026-84335: Incorrect authorization in TabStrip
    • CVE-2026-84327: Incorrect authorization in Autofill
    • CVE-2026-84329: Confused deputy in CredentialProvider
    • CVE-2026-84356: UI misrepresentation in FullScreen
    • CVE-2026-84350: Use after free in TabStrip
    • CVE-2026-84331: Incorrect authorization in Actor
  • Disabled EULA dialog to use preferences instead of a hardcoded return

References

Affected packages

openSUSE:Leap 16.0 / chromium

Package

Name
chromium
Purl
pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
152.0.7977.82-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "chromedriver":  "152.0.7977.82-bp160.1.1",
            "chromium":  "152.0.7977.82-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21799-1.json"