SUSE alert openSUSE-SU-2026:20849-1 (chromium)
| From: | null@suse.de | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:20849-1: important: Security update for chromium | |
| Date: | Mon, 01 Jun 2026 17:51:42 +0200 | |
| Message-ID: | <20260601155142.D6B01FCCC@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE security update: security update for chromium ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20849-1 Rating: important References: * bsc#1266471 Cross-References: * CVE-2026-10000 * CVE-2026-10001 * CVE-2026-10002 * CVE-2026-10003 * CVE-2026-10004 * CVE-2026-10005 * CVE-2026-10006 * CVE-2026-10007 * CVE-2026-10008 * CVE-2026-10009 * CVE-2026-10010 * CVE-2026-10011 * CVE-2026-10012 * CVE-2026-10013 * CVE-2026-10014 * CVE-2026-10015 * CVE-2026-10016 * CVE-2026-10017 * CVE-2026-10018 * CVE-2026-10019 * CVE-2026-10020 * CVE-2026-10021 * CVE-2026-10022 * CVE-2026-9872 * CVE-2026-9873 * CVE-2026-9874 * CVE-2026-9875 * CVE-2026-9876 * CVE-2026-9877 * CVE-2026-9878 * CVE-2026-9879 * CVE-2026-9880 * CVE-2026-9881 * CVE-2026-9882 * CVE-2026-9883 * CVE-2026-9884 * CVE-2026-9885 * CVE-2026-9886 * CVE-2026-9887 * CVE-2026-9888 * CVE-2026-9889 * CVE-2026-9890 * CVE-2026-9891 * CVE-2026-9892 * CVE-2026-9893 * CVE-2026-9894 * CVE-2026-9895 * CVE-2026-9896 * CVE-2026-9897 * CVE-2026-9898 * CVE-2026-9899 * CVE-2026-9900 * CVE-2026-9901 * CVE-2026-9902 * CVE-2026-9903 * CVE-2026-9904 * CVE-2026-9905 * CVE-2026-9906 * CVE-2026-9907 * CVE-2026-9908 * CVE-2026-9909 * CVE-2026-9910 * CVE-2026-9911 * CVE-2026-9912 * CVE-2026-9913 * CVE-2026-9914 * CVE-2026-9915 * CVE-2026-9916 * CVE-2026-9917 * CVE-2026-9918 * CVE-2026-9919 * CVE-2026-9920 * CVE-2026-9921 * CVE-2026-9922 * CVE-2026-9923 * CVE-2026-9924 * CVE-2026-9925 * CVE-2026-9926 * CVE-2026-9927 * CVE-2026-9928 * CVE-2026-9929 * CVE-2026-9930 * CVE-2026-9931 * CVE-2026-9932 * CVE-2026-9933 * CVE-2026-9934 * CVE-2026-9935 * CVE-2026-9936 * CVE-2026-9937 * CVE-2026-9938 * CVE-2026-9939 * CVE-2026-9940 * CVE-2026-9941 * CVE-2026-9942 * CVE-2026-9943 * CVE-2026-9944 * CVE-2026-9945 * CVE-2026-9946 * CVE-2026-9947 * CVE-2026-9948 * CVE-2026-9949 * CVE-2026-9950 * CVE-2026-9951 * CVE-2026-9952 * CVE-2026-9953 * CVE-2026-9954 * CVE-2026-9955 * CVE-2026-9956 * CVE-2026-9957 * CVE-2026-9958 * CVE-2026-9959 * CVE-2026-9960 * CVE-2026-9961 * CVE-2026-9962 * CVE-2026-9963 * CVE-2026-9964 * CVE-2026-9965 * CVE-2026-9966 * CVE-2026-9967 * CVE-2026-9968 * CVE-2026-9969 * CVE-2026-9970 * CVE-2026-9971 * CVE-2026-9972 * CVE-2026-9973 * CVE-2026-9974 * CVE-2026-9975 * CVE-2026-9976 * CVE-2026-9977 * CVE-2026-9978 * CVE-2026-9979 * CVE-2026-9980 * CVE-2026-9981 * CVE-2026-9982 * CVE-2026-9983 * CVE-2026-9984 * CVE-2026-9985 * CVE-2026-9986 * CVE-2026-9987 * CVE-2026-9988 * CVE-2026-9989 * CVE-2026-9990 * CVE-2026-9991 * CVE-2026-9992 * CVE-2026-9993 * CVE-2026-9994 * CVE-2026-9995 * CVE-2026-9996 * CVE-2026-9997 * CVE-2026-9998 * CVE-2026-9999 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 151 vulnerabilities and has one bug fix can now be installed. Description: This update for chromium fixes the following issues: Changes in chromium: - Chromium 148.0.7778.215 (boo#1266471): * CVE-2026-9872: Out of bounds write in GPU * CVE-2026-9873: Use after free in Network * CVE-2026-9874: Use after free in Dawn * CVE-2026-9875: Out of bounds read in WebGL * CVE-2026-9876: Use after free in WebGL * CVE-2026-9877: Use after free in ANGLE * CVE-2026-9878: Use after free in ANGLE * CVE-2026-9879: Out of bounds write in ANGLE * CVE-2026-9880: Insufficient validation of untrusted input in WebGL * CVE-2026-9881: Use after free in Bluetooth * CVE-2026-9882: Integer overflow in ANGLE * CVE-2026-9883: Use after free in Base * CVE-2026-9884: Use after free in Browser * CVE-2026-9885: Insufficient validation of untrusted input in UI * CVE-2026-9886: Use after free in Base * CVE-2026-9887: Use after free in Proxy * CVE-2026-9888: Use after free in WebView * CVE-2026-9889: Out of bounds read and write in Dawn * CVE-2026-9890: Use after free in XR * CVE-2026-9891: Use after free in Extensions * CVE-2026-9892: Inappropriate implementation in Skia * CVE-2026-9893: Use after free in Skia * CVE-2026-9894: Use after free in GPU * CVE-2026-9895: Out of bounds read in GPU * CVE-2026-9896: Out of bounds write in V8 * CVE-2026-9897: Use after free in DOM * CVE-2026-9898: Insufficient validation of untrusted input in GPU * CVE-2026-9899: Use after free in ANGLE * CVE-2026-9900: Out of bounds write in ANGLE * CVE-2026-9901: Use after free in ANGLE * CVE-2026-9902: Use after free in Accessibility * CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation * CVE-2026-9904: Use after free in ANGLE * CVE-2026-9905: Use after free in Accessibility * CVE-2026-9906: Out of bounds write in GPU * CVE-2026-9907: Out of bounds read in Dawn * CVE-2026-9908: Out of bounds read in ANGLE * CVE-2026-9909: Integer overflow in Skia * CVE-2026-9910: Out of bounds memory access in ANGLE * CVE-2026-9911: Integer overflow in ANGLE * CVE-2026-9912: Inappropriate implementation in GPU * CVE-2026-9913: Inappropriate implementation in ANGLE * CVE-2026-9914: Insufficient validation of untrusted input in ANGLE * CVE-2026-9915: Heap buffer overflow in ANGLE * CVE-2026-9916: Out of bounds write in ANGLE * CVE-2026-9917: Uninitialized Use in WebGL * CVE-2026-9918: Inappropriate implementation in Tint * CVE-2026-9919: Out of bounds read in WebGL * CVE-2026-9920: Uninitialized Use in GPU * CVE-2026-9921: Uninitialized Use in WebGL * CVE-2026-9922: Use after free in GPU * CVE-2026-9923: Use after free in Skia * CVE-2026-9924: Heap buffer overflow in ANGLE * CVE-2026-9925: Use after free in ANGLE * CVE-2026-9926: Heap buffer overflow in ANGLE * CVE-2026-9927: Use after free in ANGLE * CVE-2026-9928: Out of bounds read in ANGLE * CVE-2026-9929: Inappropriate implementation in WebGL * CVE-2026-9930: Out of bounds write in Dawn * CVE-2026-9931: Use after free in GPU * CVE-2026-9932: Use after free in ANGLE * CVE-2026-9933: Use after free in Input * CVE-2026-9934: Use after free in Aura * CVE-2026-9935: Uninitialized Use in ANGLE * CVE-2026-9936: Use after free in GFX * CVE-2026-9937: Use after free in UI * CVE-2026-9938: Inappropriate implementation in V8 * CVE-2026-9939: Heap buffer overflow in WebCodecs * CVE-2026-9940: Heap buffer overflow in ANGLE * CVE-2026-9941: Use after free in ANGLE * CVE-2026-9942: Uninitialized Use in ANGLE * CVE-2026-9943: Out of bounds read in WebGL * CVE-2026-9944: Uninitialized Use in ANGLE * CVE-2026-9945: Use after free in Media * CVE-2026-9946: Use after free in ANGLE * CVE-2026-9947: Use after free in XML * CVE-2026-9948: Use after free in Views * CVE-2026-9949: Use after free in Core * CVE-2026-9950: Insufficient validation of untrusted input in iOS * CVE-2026-9951: Use after free in UI * CVE-2026-9952: Use after free in WebAudio * CVE-2026-9953: Out of bounds read in ANGLE * CVE-2026-9954: Use after free in TabStrip * CVE-2026-9955: Inappropriate implementation in iOS * CVE-2026-9956: Use after free in iOS * CVE-2026-9957: Use after free in PDF * CVE-2026-9958: Use after free in PDFium * CVE-2026-9959: Race in WebRTC * CVE-2026-9960: Integer overflow in PDFium * CVE-2026-9961: Use after free in SurfaceCapture * CVE-2026-9962: Use after free in WebRTC * CVE-2026-9963: Uninitialized Use in iOS * CVE-2026-9964: Use after free in Bluetooth * CVE-2026-9965: Out of bounds write in ANGLE * CVE-2026-9966: Integer overflow in XML * CVE-2026-9967: Out of bounds write in GPU * CVE-2026-9968: Integer overflow in V8 * CVE-2026-9969: Insufficient validation of untrusted input in ANGLE * CVE-2026-9970: Use after free in WebGL * CVE-2026-9971: Inappropriate implementation in iOS * CVE-2026-9972: Uninitialized Use in Gamepad * CVE-2026-9973: Out of bounds write in V8 * CVE-2026-9974: Out of bounds write in GPU * CVE-2026-9975: Out of bounds read and write in ANGLE * CVE-2026-9976: Inappropriate implementation in USB * CVE-2026-9977: Insufficient validation of untrusted input in WebShare * CVE-2026-9978: Use after free in Glic * CVE-2026-9979: Insufficient validation of untrusted input in Input * CVE-2026-9980: Insufficient validation of untrusted input in Printing * CVE-2026-9981: Inappropriate implementation in Skia * CVE-2026-9982: Insufficient validation of untrusted input in ANGLE * CVE-2026-9983: Type Confusion in Skia * CVE-2026-9984: Use after free in UI * CVE-2026-9985: Insufficient validation of untrusted input in Media * CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide * CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-9988: Use after free in WebRTC * CVE-2026-9989: Inappropriate implementation in Media * CVE-2026-9990: Use after free in WebAppInstalls * CVE-2026-9991: Inappropriate implementation in Media * CVE-2026-9992: Use after free in Network * CVE-2026-9993: Use after free in Views * CVE-2026-9994: Use after free in Core * CVE-2026-9995: Use after free in WebXR * CVE-2026-9996: Out of bounds read in WebRTC * CVE-2026-9997: Use after free in Input * CVE-2026-9998: Integer overflow in Skia * CVE-2026-9999: Inappropriate implementation in ANGLE * CVE-2026-10000: Use after free in Passwords * CVE-2026-10001: Use after free in PerformanceManager * CVE-2026-10002: Use after free in PDFium * CVE-2026-10003: Use after free in Views * CVE-2026-10004: Insufficient validation of untrusted input in Passwords * CVE-2026-10005: Use after free in WebAppInstalls * CVE-2026-10006: Race in WebAudio * CVE-2026-10007: Use after free in SVG * CVE-2026-10008: Uninitialized Use in GPU * CVE-2026-10009: Integer overflow in Skia * CVE-2026-10010: Inappropriate implementation in Input * CVE-2026-10011: Inappropriate implementation in Skia * CVE-2026-10012: Use after free in Skia * CVE-2026-10013: Use after free in WebCodecs * CVE-2026-10014: Use after free in WebMIDI * CVE-2026-10015: Integer overflow in WTF * CVE-2026-10016: Use after free in DOM * CVE-2026-10017: Out of bounds read in Headless * CVE-2026-10018: Integer overflow in ANGLE * CVE-2026-10019: Integer overflow in ANGLE * CVE-2026-10020: Insufficient validation of untrusted input in Skia * CVE-2026-10021: Insufficient validation of untrusted input in USB * CVE-2026-10022: Type Confusion in V8 Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-279=1 Package List: - openSUSE Leap 16.0: chromedriver-148.0.7778.215-bp160.1.1 chromium-148.0.7778.215-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-10000.html * https://www.suse.com/security/cve/CVE-2026-10001.html * https://www.suse.com/security/cve/CVE-2026-10002.html * https://www.suse.com/security/cve/CVE-2026-10003.html * https://www.suse.com/security/cve/CVE-2026-10004.html * https://www.suse.com/security/cve/CVE-2026-10005.html * https://www.suse.com/security/cve/CVE-2026-10006.html * https://www.suse.com/security/cve/CVE-2026-10007.html * https://www.suse.com/security/cve/CVE-2026-10008.html * https://www.suse.com/security/cve/CVE-2026-10009.html * https://www.suse.com/security/cve/CVE-2026-10010.html * https://www.suse.com/security/cve/CVE-2026-10011.html * https://www.suse.com/security/cve/CVE-2026-10012.html * https://www.suse.com/security/cve/CVE-2026-10013.html * https://www.suse.com/security/cve/CVE-2026-10014.html * https://www.suse.com/security/cve/CVE-2026-10015.html * https://www.suse.com/security/cve/CVE-2026-10016.html * https://www.suse.com/security/cve/CVE-2026-10017.html * https://www.suse.com/security/cve/CVE-2026-10018.html * https://www.suse.com/security/cve/CVE-2026-10019.html * https://www.suse.com/security/cve/CVE-2026-10020.html * https://www.suse.com/security/cve/CVE-2026-10021.html * https://www.suse.com/security/cve/CVE-2026-10022.html * https://www.suse.com/security/cve/CVE-2026-9872.html * https://www.suse.com/security/cve/CVE-2026-9873.html * https://www.suse.com/security/cve/CVE-2026-9874.html * https://www.suse.com/security/cve/CVE-2026-9875.html * https://www.suse.com/security/cve/CVE-2026-9876.html * https://www.suse.com/security/cve/CVE-2026-9877.html * https://www.suse.com/security/cve/CVE-2026-9878.html * https://www.suse.com/security/cve/CVE-2026-9879.html * https://www.suse.com/security/cve/CVE-2026-9880.html * https://www.suse.com/security/cve/CVE-2026-9881.html * https://www.suse.com/security/cve/CVE-2026-9882.html * https://www.suse.com/security/cve/CVE-2026-9883.html * https://www.suse.com/security/cve/CVE-2026-9884.html * https://www.suse.com/security/cve/CVE-2026-9885.html * https://www.suse.com/security/cve/CVE-2026-9886.html * https://www.suse.com/security/cve/CVE-2026-9887.html * https://www.suse.com/security/cve/CVE-2026-9888.html * https://www.suse.com/security/cve/CVE-2026-9889.html * https://www.suse.com/security/cve/CVE-2026-9890.html * https://www.suse.com/security/cve/CVE-2026-9891.html * https://www.suse.com/security/cve/CVE-2026-9892.html * https://www.suse.com/security/cve/CVE-2026-9893.html * https://www.suse.com/security/cve/CVE-2026-9894.html * https://www.suse.com/security/cve/CVE-2026-9895.html * https://www.suse.com/security/cve/CVE-2026-9896.html * https://www.suse.com/security/cve/CVE-2026-9897.html * https://www.suse.com/security/cve/CVE-2026-9898.html * https://www.suse.com/security/cve/CVE-2026-9899.html * https://www.suse.com/security/cve/CVE-2026-9900.html * https://www.suse.com/security/cve/CVE-2026-9901.html * https://www.suse.com/security/cve/CVE-2026-9902.html * https://www.suse.com/security/cve/CVE-2026-9903.html * https://www.suse.com/security/cve/CVE-2026-9904.html * https://www.suse.com/security/cve/CVE-2026-9905.html * https://www.suse.com/security/cve/CVE-2026-9906.html * https://www.suse.com/security/cve/CVE-2026-9907.html * https://www.suse.com/security/cve/CVE-2026-9908.html * https://www.suse.com/security/cve/CVE-2026-9909.html * https://www.suse.com/security/cve/CVE-2026-9910.html * https://www.suse.com/security/cve/CVE-2026-9911.html * https://www.suse.com/security/cve/CVE-2026-9912.html * https://www.suse.com/security/cve/CVE-2026-9913.html * https://www.suse.com/security/cve/CVE-2026-9914.html * https://www.suse.com/security/cve/CVE-2026-9915.html * https://www.suse.com/security/cve/CVE-2026-9916.html * https://www.suse.com/security/cve/CVE-2026-9917.html * https://www.suse.com/security/cve/CVE-2026-9918.html * https://www.suse.com/security/cve/CVE-2026-9919.html * https://www.suse.com/security/cve/CVE-2026-9920.html * https://www.suse.com/security/cve/CVE-2026-9921.html * https://www.suse.com/security/cve/CVE-2026-9922.html * https://www.suse.com/security/cve/CVE-2026-9923.html * https://www.suse.com/security/cve/CVE-2026-9924.html * https://www.suse.com/security/cve/CVE-2026-9925.html * https://www.suse.com/security/cve/CVE-2026-9926.html * https://www.suse.com/security/cve/CVE-2026-9927.html * https://www.suse.com/security/cve/CVE-2026-9928.html * https://www.suse.com/security/cve/CVE-2026-9929.html * https://www.suse.com/security/cve/CVE-2026-9930.html * https://www.suse.com/security/cve/CVE-2026-9931.html * https://www.suse.com/security/cve/CVE-2026-9932.html * https://www.suse.com/security/cve/CVE-2026-9933.html * https://www.suse.com/security/cve/CVE-2026-9934.html * https://www.suse.com/security/cve/CVE-2026-9935.html * https://www.suse.com/security/cve/CVE-2026-9936.html * https://www.suse.com/security/cve/CVE-2026-9937.html * https://www.suse.com/security/cve/CVE-2026-9938.html * https://www.suse.com/security/cve/CVE-2026-9939.html * https://www.suse.com/security/cve/CVE-2026-9940.html * https://www.suse.com/security/cve/CVE-2026-9941.html * https://www.suse.com/security/cve/CVE-2026-9942.html * https://www.suse.com/security/cve/CVE-2026-9943.html * https://www.suse.com/security/cve/CVE-2026-9944.html * https://www.suse.com/security/cve/CVE-2026-9945.html * https://www.suse.com/security/cve/CVE-2026-9946.html * https://www.suse.com/security/cve/CVE-2026-9947.html * https://www.suse.com/security/cve/CVE-2026-9948.html * https://www.suse.com/security/cve/CVE-2026-9949.html * https://www.suse.com/security/cve/CVE-2026-9950.html * https://www.suse.com/security/cve/CVE-2026-9951.html * https://www.suse.com/security/cve/CVE-2026-9952.html * https://www.suse.com/security/cve/CVE-2026-9953.html * https://www.suse.com/security/cve/CVE-2026-9954.html * https://www.suse.com/security/cve/CVE-2026-9955.html * https://www.suse.com/security/cve/CVE-2026-9956.html * https://www.suse.com/security/cve/CVE-2026-9957.html * https://www.suse.com/security/cve/CVE-2026-9958.html * https://www.suse.com/security/cve/CVE-2026-9959.html * https://www.suse.com/security/cve/CVE-2026-9960.html * https://www.suse.com/security/cve/CVE-2026-9961.html * https://www.suse.com/security/cve/CVE-2026-9962.html * https://www.suse.com/security/cve/CVE-2026-9963.html * https://www.suse.com/security/cve/CVE-2026-9964.html * https://www.suse.com/security/cve/CVE-2026-9965.html * https://www.suse.com/security/cve/CVE-2026-9966.html * https://www.suse.com/security/cve/CVE-2026-9967.html * https://www.suse.com/security/cve/CVE-2026-9968.html * https://www.suse.com/security/cve/CVE-2026-9969.html * https://www.suse.com/security/cve/CVE-2026-9970.html * https://www.suse.com/security/cve/CVE-2026-9971.html * https://www.suse.com/security/cve/CVE-2026-9972.html * https://www.suse.com/security/cve/CVE-2026-9973.html * https://www.suse.com/security/cve/CVE-2026-9974.html * https://www.suse.com/security/cve/CVE-2026-9975.html * https://www.suse.com/security/cve/CVE-2026-9976.html * https://www.suse.com/security/cve/CVE-2026-9977.html * https://www.suse.com/security/cve/CVE-2026-9978.html * https://www.suse.com/security/cve/CVE-2026-9979.html * https://www.suse.com/security/cve/CVE-2026-9980.html * https://www.suse.com/security/cve/CVE-2026-9981.html * https://www.suse.com/security/cve/CVE-2026-9982.html * https://www.suse.com/security/cve/CVE-2026-9983.html * https://www.suse.com/security/cve/CVE-2026-9984.html * https://www.suse.com/security/cve/CVE-2026-9985.html * https://www.suse.com/security/cve/CVE-2026-9986.html * https://www.suse.com/security/cve/CVE-2026-9987.html * https://www.suse.com/security/cve/CVE-2026-9988.html * https://www.suse.com/security/cve/CVE-2026-9989.html * https://www.suse.com/security/cve/CVE-2026-9990.html * https://www.suse.com/security/cve/CVE-2026-9991.html * https://www.suse.com/security/cve/CVE-2026-9992.html * https://www.suse.com/security/cve/CVE-2026-9993.html * https://www.suse.com/security/cve/CVE-2026-9994.html * https://www.suse.com/security/cve/CVE-2026-9995.html * https://www.suse.com/security/cve/CVE-2026-9996.html * https://www.suse.com/security/cve/CVE-2026-9997.html * https://www.suse.com/security/cve/CVE-2026-9998.html * https://www.suse.com/security/cve/CVE-2026-9999.html
