openSUSE-SU-2026:21453-1: important: Security update for chromium

[email protected] Tue, 28 Jul 2026 17:53:18 +0200 (CEST)
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for chromium
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21453-1
Rating: important
References:

  * bsc#1272460



Cross-References:

  * CVE-2026-16804
  * CVE-2026-16805
  * CVE-2026-16806
  * CVE-2026-16807



Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 4 vulnerabilities and has one bug fix can now be installed.

Description:

This update for chromium fixes the following issues:

Changes in chromium:

- Chromium 150.0.7871.186 (boo#1272460):
  * CVE-2026-16807: Out of bounds write in Codecs
  * CVE-2026-16806: Use after free in WebMCP
  * CVE-2026-16805: Use after free in Blink
  * CVE-2026-16804: Use after free in Input


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-openSUSE_Backports_SLE-16.0__patchinfo.20260724162718479796.93181000773252=1

Package List:

- openSUSE Leap 16.0:

  chromedriver-150.0.7871.186-bp160.1.1
  chromium-150.0.7871.186-bp160.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-16804.html
  * https://www.suse.com/security/cve/CVE-2026-16805.html
  * https://www.suse.com/security/cve/CVE-2026-16806.html
  * https://www.suse.com/security/cve/CVE-2026-16807.html