VYPR

rpm package

opensuse/chromium&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed

Vulnerabilities (5,587)

  • CVE-2026-78906HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78905HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78904CriAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78903LowAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78901HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78900CriAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78899HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78898MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78897MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)

  • CVE-2026-78896MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-78895MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-78894LowAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78893MedAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78892HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)

  • CVE-2026-78891HigAug 25, 2026
    affected < 152.0.7977.64-1.1fixed 152.0.7977.64-1.1

    Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-76023HigAug 20, 2026
    affected < 151.0.7922.173-1.1fixed 151.0.7922.173-1.1

    Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-76022HigAug 20, 2026
    affected < 151.0.7922.173-1.1fixed 151.0.7922.173-1.1

    Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-76021HigAug 20, 2026
    affected < 151.0.7922.173-1.1fixed 151.0.7922.173-1.1

    Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-76020HigAug 20, 2026
    affected < 151.0.7922.173-1.1fixed 151.0.7922.173-1.1

    Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-76019HigAug 20, 2026
    affected < 151.0.7922.173-1.1fixed 151.0.7922.173-1.1

    Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

Page 30 of 280