VYPR

rpm package

opensuse/chromium&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed

Vulnerabilities (5,587)

  • CVE-2026-87538MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87537HigSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-87536HigSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-87535MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87534CriSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-87533HigSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

  • CVE-2026-87532MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87531LowSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87530HigSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

  • CVE-2026-87529CriSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87528CriSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87527CriSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-87526CriSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)

  • CVE-2026-87525LowSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (Chromium security severity: High)

  • CVE-2026-87524HigSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-87523MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87522MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)

  • CVE-2026-87521LowSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87520CriSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-87519MedSep 9, 2026
    affected < 153.0.8010.36-1.1fixed 153.0.8010.36-1.1

    Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Page 7 of 280