rpm package
opensuse/chromium&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0
Vulnerabilities (353)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-0628 | — | < 143.0.7499.192-bp160.1.1 | 143.0.7499.192-bp160.1.1 | Jan 6, 2026 | Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High) | ||
| CVE-2025-14766 | — | < 143.0.7499.146-bp160.1.1 | 143.0.7499.146-bp160.1.1 | Dec 16, 2025 | Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-14765 | — | < 143.0.7499.146-bp160.1.1 | 143.0.7499.146-bp160.1.1 | Dec 16, 2025 | Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-14373 | — | < 143.0.7499.40-bp160.1.1 | 143.0.7499.40-bp160.1.1 | Dec 12, 2025 | Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-14372 | — | < 143.0.7499.40-bp160.1.1 | 143.0.7499.40-bp160.1.1 | Dec 12, 2025 | Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-14174 | — | KEV | < 143.0.7499.146-bp160.1.1 | 143.0.7499.146-bp160.1.1 | Dec 12, 2025 | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2025-13224 | — | < 142.0.7444.162-bp160.1.1 | 142.0.7444.162-bp160.1.1 | Nov 17, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-13223 | — | KEV | < 142.0.7444.162-bp160.1.1 | 142.0.7444.162-bp160.1.1 | Nov 17, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2025-12729 | — | < 142.0.7444.59-bp160.1.1 | 142.0.7444.59-bp160.1.1 | Nov 10, 2025 | Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-12728 | — | < 142.0.7444.59-bp160.1.1 | 142.0.7444.59-bp160.1.1 | Nov 10, 2025 | Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-12727 | — | < 142.0.7444.59-bp160.1.1 | 142.0.7444.59-bp160.1.1 | Nov 10, 2025 | Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-12726 | — | < 142.0.7444.59-bp160.1.1 | 142.0.7444.59-bp160.1.1 | Nov 10, 2025 | Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-12725 | — | < 142.0.7444.59-bp160.1.1 | 142.0.7444.59-bp160.1.1 | Nov 10, 2025 | Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-11460 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High) | ||
| CVE-2025-11458 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-11756 | — | < 141.0.7390.107-bp160.1.1 | 141.0.7390.107-bp160.1.1 | Nov 6, 2025 | Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-12036 | — | < 141.0.7390.122-bp160.1.1 | 141.0.7390.122-bp160.1.1 | Nov 6, 2025 | Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2025-11219 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low) | ||
| CVE-2025-11216 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7390.54 allowed a remote attacker to perform domain spoofing via a crafted video file. (Chromium security severity: Low) | ||
| CVE-2025-11215 | — | < 141.0.7390.76-bp160.1.1 | 141.0.7390.76-bp160.1.1 | Nov 6, 2025 | Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) |
- CVE-2026-0628Jan 6, 2026affected < 143.0.7499.192-bp160.1.1fixed 143.0.7499.192-bp160.1.1
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
- CVE-2025-14766Dec 16, 2025affected < 143.0.7499.146-bp160.1.1fixed 143.0.7499.146-bp160.1.1
Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-14765Dec 16, 2025affected < 143.0.7499.146-bp160.1.1fixed 143.0.7499.146-bp160.1.1
Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-14373Dec 12, 2025affected < 143.0.7499.40-bp160.1.1fixed 143.0.7499.40-bp160.1.1
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-14372Dec 12, 2025affected < 143.0.7499.40-bp160.1.1fixed 143.0.7499.40-bp160.1.1
Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
- affected < 143.0.7499.146-bp160.1.1fixed 143.0.7499.146-bp160.1.1
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-13224Nov 17, 2025affected < 142.0.7444.162-bp160.1.1fixed 142.0.7444.162-bp160.1.1
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 142.0.7444.162-bp160.1.1fixed 142.0.7444.162-bp160.1.1
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-12729Nov 10, 2025affected < 142.0.7444.59-bp160.1.1fixed 142.0.7444.59-bp160.1.1
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-12728Nov 10, 2025affected < 142.0.7444.59-bp160.1.1fixed 142.0.7444.59-bp160.1.1
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-12727Nov 10, 2025affected < 142.0.7444.59-bp160.1.1fixed 142.0.7444.59-bp160.1.1
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-12726Nov 10, 2025affected < 142.0.7444.59-bp160.1.1fixed 142.0.7444.59-bp160.1.1
Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-12725Nov 10, 2025affected < 142.0.7444.59-bp160.1.1fixed 142.0.7444.59-bp160.1.1
Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-11460Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)
- CVE-2025-11458Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-11756Nov 6, 2025affected < 141.0.7390.107-bp160.1.1fixed 141.0.7390.107-bp160.1.1
Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-12036Nov 6, 2025affected < 141.0.7390.122-bp160.1.1fixed 141.0.7390.122-bp160.1.1
Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-11219Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)
- CVE-2025-11216Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7390.54 allowed a remote attacker to perform domain spoofing via a crafted video file. (Chromium security severity: Low)
- CVE-2025-11215Nov 6, 2025affected < 141.0.7390.76-bp160.1.1fixed 141.0.7390.76-bp160.1.1
Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Page 17 of 18