openSUSE-SU-2026:0238-1: important: Security update for chromium

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for chromium
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0238-1
Rating:             important
References:         #1271093 
Cross-References:   CVE-2026-15107 CVE-2026-15108 CVE-2026-15109
                    CVE-2026-15110 CVE-2026-15111 CVE-2026-15112
                    CVE-2026-15113 CVE-2026-15114 CVE-2026-15115
                    CVE-2026-15116 CVE-2026-15117 CVE-2026-15118
                    CVE-2026-15119 CVE-2026-15120 CVE-2026-15121
                    CVE-2026-15122 CVE-2026-15123 CVE-2026-15124
                    CVE-2026-15125 CVE-2026-15126 CVE-2026-15127
                    CVE-2026-15128 CVE-2026-15129 CVE-2026-15130
                    CVE-2026-15131 CVE-2026-15132 CVE-2026-15133
                   
Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes 27 vulnerabilities is now available.

Description:

   This update for chromium fixes the following issues:

   - Chromium 150.0.7871.114 (boo#1271093):
     * CVE-2026-15112: Use after free in Ozone
     * CVE-2026-15129: Use after free in Views
     * CVE-2026-15132: Uninitialized Use in V8
     * CVE-2026-15133: Use after free in InterestGroups
     * CVE-2026-15108: Integer overflow in Extensions API
     * CVE-2026-15109: Uninitialized Use in ANGLE
     * CVE-2026-15110: Use after free in Extensions
     * CVE-2026-15111: Use after free in Views
     * CVE-2026-15113: Use after free in Autofill
     * CVE-2026-15114: Out of bounds read and write in Codecs
     * CVE-2026-15115: Insufficient validation of untrusted input in
       WebAppInstalls
     * CVE-2026-15116: Use after free in Actor
     * CVE-2026-15117: Use after free in Payments
     * CVE-2026-15118: Use after free in Input
     * CVE-2026-15119: Inappropriate implementation in GetUserMedia
     * CVE-2026-15120: Use after free in Core
     * CVE-2026-15121: Use after free in WebRTC
     * CVE-2026-15122: Insufficient validation of untrusted input in Codecs
     * CVE-2026-15123: Insufficient data validation in DOM
     * CVE-2026-15124: Insufficient policy enforcement in Passwords
     * CVE-2026-15125: Inappropriate implementation in Forms
     * CVE-2026-15126: Use after free in Forms
     * CVE-2026-15127: Inappropriate implementation in WebGL
     * CVE-2026-15128: Inappropriate implementation in Forms
     * CVE-2026-15130: Insufficient policy enforcement in Navigation
     * CVE-2026-15107: Use after free in IndexedDB
     * CVE-2026-15131: Insufficient data validation in Navigation

   - Chromium 150.0.7871.100:
     * stability improvements, no further information available


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-238=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le x86_64):

      chromedriver-150.0.7871.114-bp157.2.184.1
      chromium-150.0.7871.114-bp157.2.184.1


References:

   https://www.suse.com/security/cve/CVE-2026-15107.html
   https://www.suse.com/security/cve/CVE-2026-15108.html
   https://www.suse.com/security/cve/CVE-2026-15109.html
   https://www.suse.com/security/cve/CVE-2026-15110.html
   https://www.suse.com/security/cve/CVE-2026-15111.html
   https://www.suse.com/security/cve/CVE-2026-15112.html
   https://www.suse.com/security/cve/CVE-2026-15113.html
   https://www.suse.com/security/cve/CVE-2026-15114.html
   https://www.suse.com/security/cve/CVE-2026-15115.html
   https://www.suse.com/security/cve/CVE-2026-15116.html
   https://www.suse.com/security/cve/CVE-2026-15117.html
   https://www.suse.com/security/cve/CVE-2026-15118.html
   https://www.suse.com/security/cve/CVE-2026-15119.html
   https://www.suse.com/security/cve/CVE-2026-15120.html
   https://www.suse.com/security/cve/CVE-2026-15121.html
   https://www.suse.com/security/cve/CVE-2026-15122.html
   https://www.suse.com/security/cve/CVE-2026-15123.html
   https://www.suse.com/security/cve/CVE-2026-15124.html
   https://www.suse.com/security/cve/CVE-2026-15125.html
   https://www.suse.com/security/cve/CVE-2026-15126.html
   https://www.suse.com/security/cve/CVE-2026-15127.html
   https://www.suse.com/security/cve/CVE-2026-15128.html
   https://www.suse.com/security/cve/CVE-2026-15129.html
   https://www.suse.com/security/cve/CVE-2026-15130.html
   https://www.suse.com/security/cve/CVE-2026-15131.html
   https://www.suse.com/security/cve/CVE-2026-15132.html
   https://www.suse.com/security/cve/CVE-2026-15133.html
   https://bugzilla.suse.com/1271093
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.