VYPR

rpm package

opensuse/chromium&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed

Vulnerabilities (5,587)

  • CVE-2026-78944HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-78943LowAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78942MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-78941LowAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Information leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78940MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78939CriAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78938HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78937CriAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78936LowAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)

  • CVE-2026-78935CriAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-78934HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78915HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Low)

  • CVE-2026-78914MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78913HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-78912MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78911HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severit

  • CVE-2026-78910HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78909CriAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78908MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78907MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Page 29 of 280