{"id":"openSUSE-SU-2026:20422-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChanges in chromium:\n\n- Chromium 146.0.7680.153 (boo#1259964):\n  * CVE-2026-4439: Out of bounds memory access in WebGL\n  * CVE-2026-4440: Out of bounds read and write in WebGL\n  * CVE-2026-4441: Use after free in Base\n  * CVE-2026-4442: Heap buffer overflow in CSS\n  * CVE-2026-4443: Heap buffer overflow in WebAudio\n  * CVE-2026-4444: Stack buffer overflow in WebRTC\n  * CVE-2026-4445: Use after free in WebRTC\n  * CVE-2026-4446: Use after free in WebRTC\n  * CVE-2026-4447: Inappropriate implementation in V8\n  * CVE-2026-4448: Heap buffer overflow in ANGLE\n  * CVE-2026-4449: Use after free in Blink\n  * CVE-2026-4450: Out of bounds write in V8\n  * CVE-2026-4451: Insufficient validation of untrusted input in Navigation\n  * CVE-2026-4452: Integer overflow in ANGLE\n  * CVE-2026-4453: Integer overflow in Dawn\n  * CVE-2026-4454: Use after free in Network\n  * CVE-2026-4455: Heap buffer overflow in PDFium\n  * CVE-2026-4456: Use after free in Digital Credentials API\n  * CVE-2026-4457: Type Confusion in V8\n  * CVE-2026-4458: Use after free in Extensions\n  * CVE-2026-4459: Out of bounds read and write in WebAudio\n  * CVE-2026-4460: Out of bounds read in Skia\n  * CVE-2026-4461: Inappropriate implementation in V8\n  * CVE-2026-4462: Out of bounds read in Blink\n  * CVE-2026-4463: Heap buffer overflow in WebRTC\n  * CVE-2026-4464: Integer overflow in ANGLE\n","modified":"2026-09-02T14:00:15.848414833Z","published":"2026-03-24T07:22:02Z","withdrawn":"2026-09-02T14:00:15.848414674Z","related":["CVE-2026-4439","CVE-2026-4440","CVE-2026-4441","CVE-2026-4442","CVE-2026-4443","CVE-2026-4444","CVE-2026-4445","CVE-2026-4446","CVE-2026-4447","CVE-2026-4448","CVE-2026-4449","CVE-2026-4450","CVE-2026-4451","CVE-2026-4452","CVE-2026-4453","CVE-2026-4454","CVE-2026-4455","CVE-2026-4456","CVE-2026-4457","CVE-2026-4458","CVE-2026-4459","CVE-2026-4460","CVE-2026-4461","CVE-2026-4462","CVE-2026-4463","CVE-2026-4464"],"upstream":["CVE-2026-4439","CVE-2026-4440","CVE-2026-4441","CVE-2026-4442","CVE-2026-4443","CVE-2026-4444","CVE-2026-4445","CVE-2026-4446","CVE-2026-4447","CVE-2026-4448","CVE-2026-4449","CVE-2026-4450","CVE-2026-4451","CVE-2026-4452","CVE-2026-4453","CVE-2026-4454","CVE-2026-4455","CVE-2026-4456","CVE-2026-4457","CVE-2026-4458","CVE-2026-4459","CVE-2026-4460","CVE-2026-4461","CVE-2026-4462","CVE-2026-4463","CVE-2026-4464"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259964"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4439"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4440"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4442"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4443"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4444"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4445"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4446"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4447"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4449"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4450"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4451"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4452"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4453"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4454"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4455"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4456"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4457"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4458"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4459"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4460"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4461"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4462"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4463"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4464"}],"affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"146.0.7680.153-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"146.0.7680.153-bp160.1.1","chromium":"146.0.7680.153-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20422-1.json"}}],"schema_version":"1.7.5"}