rpm package
opensuse/chromium&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0
Vulnerabilities (353)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-11650 | Hig | 8.8 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-11649 | Hig | 8.8 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-11648 | Hig | 8.8 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-11647 | Hig | 8.3 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Printing in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-11646 | Hig | 8.8 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-11645 | Hig | 8.8 | KEV | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-11644 | Hig | 7.5 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical) | |
| CVE-2026-11643 | Hig | 8.1 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical) | |
| CVE-2026-11642 | Hig | 8.3 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-11641 | Hig | 7.5 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-11640 | Hig | 8.3 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-11639 | Hig | 7.5 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-11638 | Cri | 9.6 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-11637 | Hig | 8.8 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-11636 | Hig | 7.5 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-11635 | Hig | 8.3 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-11634 | Cri | 9.6 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-11633 | Hig | 8.8 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical) | |
| CVE-2026-11632 | Hig | 7.5 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-11631 | Hig | 8.3 | < 149.0.7827.102-bp160.1.1 | 149.0.7827.102-bp160.1.1 | Jun 9, 2026 | Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Printing in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
- affected < 149.0.7827.102-bp160.1.1fixed 149.0.7827.102-bp160.1.1
Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Page 5 of 18