{"id":"openSUSE-SU-2026:20944-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChanges in chromium:\n\n- Chromium 149.0.7827.102 (boo#1267911):\n  * CVE-2026-11628: Use after free in Ozone\n  * CVE-2026-11629: Use after free in Ozone\n  * CVE-2026-11630: Use after free in File Input\n  * CVE-2026-11631: Use after free in Aura\n  * CVE-2026-11632: Use after free in TabStrip\n  * CVE-2026-11633: Use after free in Bluetooth\n  * CVE-2026-11634: Use after free in Gamepad\n  * CVE-2026-11635: Use after free in Bluetooth\n  * CVE-2026-11636: Use after free in Autofill\n  * CVE-2026-11637: Use after free in Views\n  * CVE-2026-11638: Use after free in Printing\n  * CVE-2026-11639: Use after free in Compositing\n  * CVE-2026-11640: Integer overflow in libyuv\n  * CVE-2026-11641: Use after free in Bluetooth\n  * CVE-2026-11642: Use after free in Web Apps\n  * CVE-2026-11643: Use after free in Proxy\n  * CVE-2026-11644: Use after free in Views\n  * CVE-2026-11645: Out of bounds memory access in V8\n  * CVE-2026-11646: Use after free in ViewTransitions\n  * CVE-2026-11647: Use after free in Printing\n  * CVE-2026-11648: Use after free in FullScreen\n  * CVE-2026-11649: Use after free in V8\n  * CVE-2026-11650: Use after free in V8\n  * CVE-2026-11651: Use after free in Network\n  * CVE-2026-11652: Use after free in Extensions\n  * CVE-2026-11653: Insufficient validation of untrusted input in Extensions\n  * CVE-2026-11654: Use after free in CameraCapture\n  * CVE-2026-11655: Integer overflow in Media\n  * CVE-2026-11656: Use after free in ServiceWorker\n  * CVE-2026-11657: Use after free in Payments\n  * CVE-2026-11658: Insufficient validation of untrusted input in Extensions\n  * CVE-2026-11659: Insufficient validation of untrusted input in UI\n  * CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page\n  * CVE-2026-11661: Use after free in Views\n  * CVE-2026-11662: Type Confusion in Bindings\n  * CVE-2026-11663: Use after free in Skia\n  * CVE-2026-11664: Use after free in Payments\n  * CVE-2026-11665: Out of bounds read in Dawn\n  * CVE-2026-11666: Insufficient validation of untrusted input in Input\n  * CVE-2026-11667: Out of bounds read in WebRTC\n  * CVE-2026-11668: Uninitialized Use in Codecs\n  * CVE-2026-11669: Integer overflow in Media\n  * CVE-2026-11670: Use after free in PDF\n  * CVE-2026-11671: Use after free in Navigation\n  * CVE-2026-11672: Out of bounds write in GPU\n  * CVE-2026-11673: Use after free in InterestGroups\n  * CVE-2026-11674: Use after free in Guest View\n  * CVE-2026-11675: Insufficient validation of untrusted input in Skia\n  * CVE-2026-11676: Insufficient validation of untrusted input in Dawn\n  * CVE-2026-11677: Race in Network\n  * CVE-2026-11678: Integer overflow in libyuv\n  * CVE-2026-11679: Use after free in Codecs\n  * CVE-2026-11680: Use after free in Media\n  * CVE-2026-11681: Use after free in Ozone\n  * CVE-2026-11682: Insufficient validation of untrusted input in Views\n  * CVE-2026-11683: Use after free in WebCodecs\n  * CVE-2026-11684: Insufficient policy enforcement in Network\n  * CVE-2026-11685: Insufficient data validation in MediaCapture\n  * CVE-2026-11686: Insufficient validation of untrusted input in Dawn\n  * CVE-2026-11687: Use after free in Dawn\n  * CVE-2026-11688: Object lifecycle issue in SVG\n  * CVE-2026-11689: Insufficient validation of untrusted input in Passwords\n  * CVE-2026-11690: Out of bounds read and write in Media\n  * CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page\n  * CVE-2026-11692: Use after free in Read Anything\n  * CVE-2026-11693: Inappropriate implementation in Plugins\n  * CVE-2026-11694: Use after free in ServiceWorker\n  * CVE-2026-11695: Inappropriate implementation in Passwords\n  * CVE-2026-11696: Uninitialized Use in Video\n  * CVE-2026-11697: Insufficient validation of untrusted input in UI\n  * CVE-2026-11698: Use after free in Bluetooth\n  * CVE-2026-11699: Use after free in Bluetooth\n  * CVE-2026-11700: Use after free in Tracing\n  * CVE-2026-11701: Insufficient validation of untrusted input in Guest View\n","modified":"2026-09-02T14:00:12.683196943Z","published":"2026-06-12T00:59:39Z","withdrawn":"2026-09-02T14:00:12.683196816Z","related":["CVE-2026-11628","CVE-2026-11629","CVE-2026-11630","CVE-2026-11631","CVE-2026-11632","CVE-2026-11633","CVE-2026-11634","CVE-2026-11635","CVE-2026-11636","CVE-2026-11637","CVE-2026-11638","CVE-2026-11639","CVE-2026-11640","CVE-2026-11641","CVE-2026-11642","CVE-2026-11643","CVE-2026-11644","CVE-2026-11645","CVE-2026-11646","CVE-2026-11647","CVE-2026-11648","CVE-2026-11649","CVE-2026-11650","CVE-2026-11651","CVE-2026-11652","CVE-2026-11653","CVE-2026-11654","CVE-2026-11655","CVE-2026-11656","CVE-2026-11657","CVE-2026-11658","CVE-2026-11659","CVE-2026-11660","CVE-2026-11661","CVE-2026-11662","CVE-2026-11663","CVE-2026-11664","CVE-2026-11665","CVE-2026-11666","CVE-2026-11667","CVE-2026-11668","CVE-2026-11669","CVE-2026-11670","CVE-2026-11671","CVE-2026-11672","CVE-2026-11673","CVE-2026-11674","CVE-2026-11675","CVE-2026-11676","CVE-2026-11677","CVE-2026-11678","CVE-2026-11679","CVE-2026-11680","CVE-2026-11681","CVE-2026-11682","CVE-2026-11683","CVE-2026-11684","CVE-2026-11685","CVE-2026-11686","CVE-2026-11687","CVE-2026-11688","CVE-2026-11689","CVE-2026-11690","CVE-2026-11691","CVE-2026-11692","CVE-2026-11693","CVE-2026-11694","CVE-2026-11695","CVE-2026-11696","CVE-2026-11697","CVE-2026-11698","CVE-2026-11699","CVE-2026-11700","CVE-2026-11701"],"upstream":["CVE-2026-11628","CVE-2026-11629","CVE-2026-11630","CVE-2026-11631","CVE-2026-11632","CVE-2026-11633","CVE-2026-11634","CVE-2026-11635","CVE-2026-11636","CVE-2026-11637","CVE-2026-11638","CVE-2026-11639","CVE-2026-11640","CVE-2026-11641","CVE-2026-11642","CVE-2026-11643","CVE-2026-11644","CVE-2026-11645","CVE-2026-11646","CVE-2026-11647","CVE-2026-11648","CVE-2026-11649","CVE-2026-11650","CVE-2026-11651","CVE-2026-11652","CVE-2026-11653","CVE-2026-11654","CVE-2026-11655","CVE-2026-11656","CVE-2026-11657","CVE-2026-11658","CVE-2026-11659","CVE-2026-11660","CVE-2026-11661","CVE-2026-11662","CVE-2026-11663","CVE-2026-11664","CVE-2026-11665","CVE-2026-11666","CVE-2026-11667","CVE-2026-11668","CVE-2026-11669","CVE-2026-11670","CVE-2026-11671","CVE-2026-11672","CVE-2026-11673","CVE-2026-11674","CVE-2026-11675","CVE-2026-11676","CVE-2026-11677","CVE-2026-11678","CVE-2026-11679","CVE-2026-11680","CVE-2026-11681","CVE-2026-11682","CVE-2026-11683","CVE-2026-11684","CVE-2026-11685","CVE-2026-11686","CVE-2026-11687","CVE-2026-11688","CVE-2026-11689","CVE-2026-11690","CVE-2026-11691","CVE-2026-11692","CVE-2026-11693","CVE-2026-11694","CVE-2026-11695","CVE-2026-11696","CVE-2026-11697","CVE-2026-11698","CVE-2026-11699","CVE-2026-11700","CVE-2026-11701"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267911"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11628"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11629"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11630"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11632"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11633"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11634"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11635"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11636"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11637"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11638"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11639"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11640"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11641"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11642"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11643"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11644"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11645"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11646"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11647"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11648"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11649"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11650"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11651"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11652"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11653"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11654"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11655"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11656"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11657"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11658"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11659"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11660"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11661"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11663"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11664"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11665"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11666"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11667"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11668"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11669"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11670"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11671"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11672"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11673"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11674"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11675"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11679"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11682"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11683"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11684"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11685"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11686"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11687"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11688"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11689"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11690"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11691"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11692"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11693"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11695"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11696"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11697"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11698"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11699"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11700"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11701"}],"affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"149.0.7827.102-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"chromium":"149.0.7827.102-bp160.1.1","chromedriver":"149.0.7827.102-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20944-1.json"}}],"schema_version":"1.7.5"}