rpm package
opensuse/chromium&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed
Vulnerabilities (5,587)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-79136 | Med | 4.3 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79134 | Med | 6.5 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Incorrect authorization in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79133 | Med | 6.5 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Incorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2026-79132 | Hig | 8.3 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79131 | Cri | 9.6 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79130 | Cri | 9.6 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79129 | Cri | 9.6 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium) | |
| CVE-2026-79128 | Cri | 9.6 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79127 | Hig | 8.8 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79126 | Med | 5.9 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially obtain sensitive information via crafted network traffic. (Chromium security severity: Low) | |
| CVE-2026-79125 | Med | 6.5 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2026-79124 | Med | 6.5 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2026-79123 | Med | 6.5 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2026-79122 | Med | 5.9 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium) | |
| CVE-2026-79121 | Hig | 8.3 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-79120 | Med | 6.5 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79119 | Hig | 8.8 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: Low) | |
| CVE-2026-79118 | Med | 4.3 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79117 | Med | 4.3 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High) | |
| CVE-2026-79116 | Med | 4.3 | < 152.0.7977.64-1.1 | 152.0.7977.64-1.1 | Aug 25, 2026 | Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) |
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Incorrect authorization in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Incorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially obtain sensitive information via crafted network traffic. (Chromium security severity: Low)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: Low)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High)
- affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1
Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Page 21 of 280