{"id":"openSUSE-SU-2026:20980-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChanges in chromium:\n\nChromium 149.0.7827.114 (boo#1268158):\n\n  * CVE-2026-12007: Use after free  Core\n  * CVE-2026-12008: Use after free  DigitalCredentials\n  * CVE-2026-12009: Insufficient validation of untrusted input  Accessibility\n  * CVE-2026-12010: Heap buffer overflow  GPU\n  * CVE-2026-12011: Use after free  WebMIDI\n  * CVE-2026-12012: Use after free  Network\n  * CVE-2026-12013: Use after free  Media\n  * CVE-2026-12014: Use after free  Cast\n  * CVE-2026-12015: Use after free  Autofill\n  * CVE-2026-12016: Insufficient validation of untrusted input  DevTools\n  * CVE-2026-12017: Insufficient validation of untrusted input  Extensions\n  * CVE-2026-12018: Inappropriate implementation  Mojo\n  * CVE-2026-12019: Out of bounds write  Codecs\n  * CVE-2026-12020: Use after free  Autofill\n  * CVE-2026-12022: Race  Safe Browsing\n  * CVE-2026-12023: Use after free  GPU\n  * CVE-2026-12024: Insufficient policy enforcement  DevTools\n  * CVE-2026-12025: Insufficient validation of untrusted input  Network\n  * CVE-2026-12026: Out of bounds read  Video\n  * CVE-2026-12027: Insufficient policy enforcement  Headless\n  * CVE-2026-12028: Use after free  GPU\n  * CVE-2026-12029: Use after free  Video\n  * CVE-2026-12030: Heap buffer overflow  GPU\n  * CVE-2026-12031: Inappropriate implementation  Views\n  * CVE-2026-12032: Inappropriate implementation  Passwords\n  * CVE-2026-12033: Out of bounds read  VideoCapture\n  * CVE-2026-12034: Insufficient validation of untrusted input  Linux Toolkit Theming\n  * CVE-2026-12035: Use after free  Views\n","modified":"2026-09-02T14:00:12.687396995Z","published":"2026-06-16T06:31:46Z","withdrawn":"2026-09-02T14:00:12.687396805Z","related":["CVE-2026-12007","CVE-2026-12008","CVE-2026-12009","CVE-2026-12010","CVE-2026-12011","CVE-2026-12012","CVE-2026-12013","CVE-2026-12014","CVE-2026-12015","CVE-2026-12016","CVE-2026-12017","CVE-2026-12018","CVE-2026-12019","CVE-2026-12020","CVE-2026-12022","CVE-2026-12023","CVE-2026-12024","CVE-2026-12025","CVE-2026-12026","CVE-2026-12027","CVE-2026-12028","CVE-2026-12029","CVE-2026-12030","CVE-2026-12031","CVE-2026-12032","CVE-2026-12033","CVE-2026-12034","CVE-2026-12035"],"upstream":["CVE-2026-12007","CVE-2026-12008","CVE-2026-12009","CVE-2026-12010","CVE-2026-12011","CVE-2026-12012","CVE-2026-12013","CVE-2026-12014","CVE-2026-12015","CVE-2026-12016","CVE-2026-12017","CVE-2026-12018","CVE-2026-12019","CVE-2026-12020","CVE-2026-12022","CVE-2026-12023","CVE-2026-12024","CVE-2026-12025","CVE-2026-12026","CVE-2026-12027","CVE-2026-12028","CVE-2026-12029","CVE-2026-12030","CVE-2026-12031","CVE-2026-12032","CVE-2026-12033","CVE-2026-12034","CVE-2026-12035"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268158"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12008"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12009"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12011"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12012"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12014"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12016"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12017"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12018"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12020"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12022"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12024"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12025"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12026"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12027"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12028"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12029"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12030"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12031"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12032"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12033"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12034"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12035"}],"affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"149.0.7827.114-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"chromium":"149.0.7827.114-bp160.1.1","chromedriver":"149.0.7827.114-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20980-1.json"}}],"schema_version":"1.7.5"}