{"id":"openSUSE-SU-2026:21921-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChanges in chromium:\n\n- Chromium 153.0.8010.52 (boo#1281123):\n  * CVE-2026-93374: Use after free in Dawn\n  * CVE-2026-93372: Buffer overflow in WebGL\n  * CVE-2026-93375: Incorrect reference resolution in Tracing\n  * CVE-2026-93382: Use after free in PDFium\n  * CVE-2026-93387: Improper state validation in Skia\n  * CVE-2026-93373: Use after free in Extensions\n  * CVE-2026-93381: Buffer overflow in PDFium\n  * CVE-2026-93379: Incorrect authorization in ORB\n  * CVE-2026-93377: Type confusion in V8\n  * CVE-2026-93380: Race condition in FileSystem\n  * CVE-2026-93384: Server-side request forgery in Omnibox\n  * CVE-2026-93383: Information leak in Permissions\n  * CVE-2026-93376: Out of bounds read in DataTransfer\n  * CVE-2026-93378: Missing authorization in Storage\n  * CVE-2026-93385: Information leak in Paint\n  * CVE-2026-93386: UI misrepresentation in WebAppInstalls\n","modified":"2026-09-25T18:23:13.360411533Z","published":"2026-09-20T05:23:04Z","related":["CVE-2026-93372","CVE-2026-93373","CVE-2026-93374","CVE-2026-93375","CVE-2026-93376","CVE-2026-93377","CVE-2026-93378","CVE-2026-93379","CVE-2026-93380","CVE-2026-93381","CVE-2026-93382","CVE-2026-93383","CVE-2026-93384","CVE-2026-93385","CVE-2026-93386","CVE-2026-93387"],"upstream":["CVE-2026-93372","CVE-2026-93373","CVE-2026-93374","CVE-2026-93375","CVE-2026-93376","CVE-2026-93377","CVE-2026-93378","CVE-2026-93379","CVE-2026-93380","CVE-2026-93381","CVE-2026-93382","CVE-2026-93383","CVE-2026-93384","CVE-2026-93385","CVE-2026-93386","CVE-2026-93387"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281123"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93372"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93374"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93376"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93381"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93383"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93384"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93385"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93386"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93387"}],"affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.0.8010.52-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"153.0.8010.52-bp160.1.1","chromium":"153.0.8010.52-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21921-1.json"}}],"schema_version":"1.9.0"}