{"id":"openSUSE-SU-2026:21799-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChanges in chromium:\n\n- Chromium 152.0.7977.82 (boo#1278683):\n  * CVE-2026-85046: Type confusion in V8\n  * CVE-2026-85052: Out of bounds read in CrashReporting\n  * CVE-2026-85043: Incomplete cleanup in Network\n  * CVE-2026-85048: Use after free in Compositing\n  * CVE-2026-85045: Race condition in V8\n  * CVE-2026-85050: Out of bounds write in WebGL\n  * CVE-2026-85053: Improper resource exposure in CacheStorage\n  * CVE-2026-85042: Use after free in DevTools\n  * CVE-2026-85049: Use after free in Skia\n  * CVE-2026-85051: Type confusion in Compositing\n  * CVE-2026-85047: Improper input validation in Transactions Platform\n  * CVE-2026-85044: Use of released resource in Mobile\n\n- Chromium 152.0.7977.75 (boo#1278072):\n  * CVE-2026-84353: Use after free in Shared Tab Groups\n  * CVE-2026-84352: Use after free in WebGL\n  * CVE-2026-84354: Incorrect authorization in FileSystem\n  * CVE-2026-84359: Information leak in Skia\n  * CVE-2026-84357: Improper input validation in Omnibox\n  * CVE-2026-84324: Use after free in Proxy\n  * CVE-2026-84349: Use after free in Browser\n  * CVE-2026-84326: Uninitialized resource in V8\n  * CVE-2026-84333: Use after free in Dawn\n  * CVE-2026-84351: Buffer overflow in GPU\n  * CVE-2026-84325: Improper input validation in DataTransfer\n  * CVE-2026-84328: Missing authorization in FileSystem\n  * CVE-2026-84347: Use after free in WebRTC\n  * CVE-2026-84323: Missing authorization in FileSystem\n  * CVE-2026-84355: Incorrect authorization in Navigation\n  * CVE-2026-84358: Improper privilege management in Downloads\n  * CVE-2026-84332: Incorrect authorization in SiteSettings\n  * CVE-2026-84330: UI misrepresentation in FullScreen\n  * CVE-2026-84334: Incorrect authorization in Chromoting\n  * CVE-2026-84348: Information leak in MediaCapture\n  * CVE-2026-84335: Incorrect authorization in TabStrip\n  * CVE-2026-84327: Incorrect authorization in Autofill\n  * CVE-2026-84329: Confused deputy in CredentialProvider\n  * CVE-2026-84356: UI misrepresentation in FullScreen\n  * CVE-2026-84350: Use after free in TabStrip\n  * CVE-2026-84331: Incorrect authorization in Actor\n\n- Disabled EULA dialog to use preferences instead of a hardcoded return\n","modified":"2026-09-09T18:23:16.183585781Z","published":"2026-09-05T23:43:46Z","related":["CVE-2026-84323","CVE-2026-84324","CVE-2026-84325","CVE-2026-84326","CVE-2026-84327","CVE-2026-84328","CVE-2026-84329","CVE-2026-84330","CVE-2026-84331","CVE-2026-84332","CVE-2026-84333","CVE-2026-84334","CVE-2026-84335","CVE-2026-84347","CVE-2026-84348","CVE-2026-84349","CVE-2026-84350","CVE-2026-84351","CVE-2026-84352","CVE-2026-84353","CVE-2026-84354","CVE-2026-84355","CVE-2026-84356","CVE-2026-84357","CVE-2026-84358","CVE-2026-84359","CVE-2026-85042","CVE-2026-85043","CVE-2026-85044","CVE-2026-85045","CVE-2026-85046","CVE-2026-85047","CVE-2026-85048","CVE-2026-85049","CVE-2026-85050","CVE-2026-85051","CVE-2026-85052","CVE-2026-85053"],"upstream":["CVE-2026-84323","CVE-2026-84324","CVE-2026-84325","CVE-2026-84326","CVE-2026-84327","CVE-2026-84328","CVE-2026-84329","CVE-2026-84330","CVE-2026-84331","CVE-2026-84332","CVE-2026-84333","CVE-2026-84334","CVE-2026-84335","CVE-2026-84347","CVE-2026-84348","CVE-2026-84349","CVE-2026-84350","CVE-2026-84351","CVE-2026-84352","CVE-2026-84353","CVE-2026-84354","CVE-2026-84355","CVE-2026-84356","CVE-2026-84357","CVE-2026-84358","CVE-2026-84359","CVE-2026-85042","CVE-2026-85043","CVE-2026-85044","CVE-2026-85045","CVE-2026-85046","CVE-2026-85047","CVE-2026-85048","CVE-2026-85049","CVE-2026-85050","CVE-2026-85051","CVE-2026-85052","CVE-2026-85053"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278072"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278683"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84323"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84324"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84326"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84328"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84329"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84330"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84331"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84332"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84333"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84334"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84335"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84347"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84348"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84349"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84350"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84351"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84352"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84353"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84354"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84358"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84359"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85042"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85044"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85047"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85048"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85050"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85051"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85053"}],"affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"152.0.7977.82-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"152.0.7977.82-bp160.1.1","chromium":"152.0.7977.82-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21799-1.json"}}],"schema_version":"1.9.0"}