VYPR

rpm package

opensuse/chromium&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed

Vulnerabilities (5,587)

  • CVE-2026-87438CriSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-87437MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87436MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-87435MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87434LowSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87433HigSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87432MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87431HigSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-87430HigSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87429MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-85053HigSep 3, 2026
    affected < 152.0.7977.82-1.1fixed 152.0.7977.82-1.1

    Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-85052LowSep 3, 2026
    affected < 152.0.7977.82-1.1fixed 152.0.7977.82-1.1

    Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-85051HigSep 3, 2026
    affected < 152.0.7977.82-1.1fixed 152.0.7977.82-1.1

    Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-85050CriSep 3, 2026
    affected < 152.0.7977.82-1.1fixed 152.0.7977.82-1.1

    Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-85049HigSep 3, 2026
    affected < 152.0.7977.82-1.1fixed 152.0.7977.82-1.1

    Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-85048HigSep 3, 2026
    affected < 152.0.7977.82-1.1fixed 152.0.7977.82-1.1

    Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-85047CriSep 3, 2026
    affected < 152.0.7977.82-1.1fixed 152.0.7977.82-1.1

    Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-85046HigKEVSep 3, 2026
    affected < 152.0.7977.82-1.1fixed 152.0.7977.82-1.1

    Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-85045HigSep 3, 2026
    affected < 152.0.7977.82-1.1fixed 152.0.7977.82-1.1

    Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-85044MedSep 3, 2026
    affected < 152.0.7977.82-1.1fixed 152.0.7977.82-1.1

    Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

Page 12 of 280