{"id":"openSUSE-SU-2026:21987-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChanges in chromium:\n\n- Chromium 154.0.8037.57 (boo#1282334):\n  * CVE-2026-95350: Buffer overflow in ANGLE\n  * CVE-2026-95357: Out of bounds write in GPU\n  * CVE-2026-95339: Use after free in ServiceWorker\n  * CVE-2026-95281: Buffer overflow in ANGLE\n  * CVE-2026-95313: Use after free in Fullscreen\n  * CVE-2026-95349: Buffer overflow in WebGL\n  * CVE-2026-95284: Buffer overflow in ANGLE\n  * CVE-2026-95322: Out of bounds write in GPU\n  * CVE-2026-95329: Out of bounds write in WebGL\n  * CVE-2026-95356: Use after free in WindowDialog\n  * CVE-2026-95310: Use after free in AdFilter\n  * CVE-2026-95301: Missing authorization in Extensions\n  * CVE-2026-95291: UI misrepresentation in SecurityIndicators\n  * CVE-2026-95355: Incorrect authorization in Navigation\n  * CVE-2026-95315: Use after free in Aura\n  * CVE-2026-95298: Use after free in Browser\n  * CVE-2026-95372: Use after free in Chromecast\n  * CVE-2026-95324: Uninitialized resource in GPU\n  * CVE-2026-95283: Buffer overflow in Tint\n  * CVE-2026-95293: Uninitialized resource in GPU\n  * CVE-2026-95274: Improper output encoding in DevTools\n  * CVE-2026-95282: Use after free in Platform\n  * CVE-2026-95373: Use after free in DevTools\n  * CVE-2026-95277: Use after free in Views\n  * CVE-2026-95348: Use after free in Bluetooth\n  * CVE-2026-95335: Use after free in HID\n  * CVE-2026-95338: Use after free in PDFium\n  * CVE-2026-95318: Buffer overflow in Video\n  * CVE-2026-95286: Type confusion in Bindings\n  * CVE-2026-95365: Type confusion in IndexedDB\n  * CVE-2026-95343: Use after free in WebAudio\n  * CVE-2026-95280: Race condition in V8\n  * CVE-2026-95304: Out of bounds write in V8\n  * CVE-2026-95306: Type confusion in V8\n  * CVE-2026-95299: Use after free in GPU\n  * CVE-2026-95351: Use after free in Views\n  * CVE-2026-95287: Missing authorization in Navigation\n  * CVE-2026-95366: Use of released resource in Core\n  * CVE-2026-95382: Improper input validation in Auth\n  * CVE-2026-95381: Improper input validation in Printing\n  * CVE-2026-95331: Out of bounds write in ANGLE\n  * CVE-2026-95297: Missing authorization in Contextual Tasks\n  * CVE-2026-95375: Incorrect authorization in BrowserTag\n  * CVE-2026-95302: Incorrect authorization in WebAPKs\n  * CVE-2026-95362: Cross-site request forgery in DevTools\n  * CVE-2026-95369: Inappropriate implementation in XML\n  * CVE-2026-95376: Externally controlled reference in DevTools\n  * CVE-2026-95359: Uninitialized resource in GPU\n  * CVE-2026-95294: UI misrepresentation in Browser\n  * CVE-2026-95337: UI misrepresentation in Messages\n  * CVE-2026-95346: UI misrepresentation in Chromoting\n  * CVE-2026-95320: Missing authorization in Navigation\n  * CVE-2026-95317: Incorrect authorization in MediaCapture\n  * CVE-2026-95345: Use after free in Actor\n  * CVE-2026-95330: Improper state validation in Downloads\n  * CVE-2026-95370: Inappropriate implementation in NFC\n  * CVE-2026-95303: Incomplete cleanup in SmartCard\n  * CVE-2026-95360: Race condition in Editing\n  * CVE-2026-95295: Information leak in Mobile\n  * CVE-2026-95276: Improper input validation in Themes\n  * CVE-2026-95314: Incorrect authorization in HID\n  * CVE-2026-95371: Missing authorization in Views\n  * CVE-2026-95353: Use after free in Bindings\n  * CVE-2026-95363: UI misrepresentation in FileSystem\n  * CVE-2026-95341: Improper input validation in Desktop\n  * CVE-2026-95354: Use after free in Verifier\n  * CVE-2026-95384: Race condition in Transactions Platform\n  * CVE-2026-95336: Information leak in Transactions Platform\n  * CVE-2026-95290: Missing authorization in NFC\n  * CVE-2026-95325: Use after free in ANGLE\n  * CVE-2026-95275: Incorrect reference resolution in MediaStream\n  * CVE-2026-95374: Incorrect authorization in Network\n  * CVE-2026-95300: Missing authorization in DevTools\n  * CVE-2026-95321: UI misrepresentation in Payments\n  * CVE-2026-95323: UI misrepresentation in Chromium\n  * CVE-2026-95332: Use of uninitialized variable in Tint\n  * CVE-2026-95312: Information leak in Passwords\n  * CVE-2026-95344: Race condition in DevTools\n  * CVE-2026-95289: Incorrect authorization in Scroll\n  * CVE-2026-95347: Use after free in Updater\n  * CVE-2026-95311: Free of non-heap memory in Fonts\n  * CVE-2026-95358: Incorrect authorization in Mobile\n  * CVE-2026-95333: Use after free in Metrics\n  * CVE-2026-95307: UI misrepresentation in ExtensionsMenu\n  * CVE-2026-95285: Missing authorization in WebView\n  * CVE-2026-95278: Missing authorization in WakeLock\n  * CVE-2026-95327: Information leak in Networking\n  * CVE-2026-95334: Incorrect reference resolution in WebProtect\n  * CVE-2026-95308: Integer overflow in Metrics\n  * CVE-2026-95292: Incorrect authorization in Safebrowsing\n  * CVE-2026-95352: Incorrect authorization in DevTools\n  * CVE-2026-95279: UI misrepresentation in Omnibox\n  * CVE-2026-95367: Information leak in DataTransfer\n  * CVE-2026-95385: Inappropriate implementation in PlatformIntegration\n  * CVE-2026-95368: Incorrect authorization in DevTools\n  * CVE-2026-95319: Use after free in Printing\n  * CVE-2026-95326: Incomplete cleanup in Bluetooth\n  * CVE-2026-95309: UI misrepresentation in Mobile\n  * CVE-2026-95361: Confused deputy in DevTools\n  * CVE-2026-95288: UI misrepresentation in Mobile\n  * CVE-2026-95380: Type confusion in V8\n  * CVE-2026-95342: Missing authorization in V8\n  * CVE-2026-95296: Missing authorization in Core\n  * CVE-2026-95316: Unchecked return value in Performance\n  * CVE-2026-95328: Confused deputy in Mobile\n  * CVE-2026-95340: Incorrect authorization in PictureInPicture\n  * CVE-2026-95364: Improper input validation in Passwords\n  * CVE-2026-95305: UI misrepresentation in Chromoting\n","modified":"2026-10-01T18:23:10.958660038Z","published":"2026-09-26T10:45:43Z","related":["CVE-2026-95274","CVE-2026-95275","CVE-2026-95276","CVE-2026-95277","CVE-2026-95278","CVE-2026-95279","CVE-2026-95280","CVE-2026-95281","CVE-2026-95282","CVE-2026-95283","CVE-2026-95284","CVE-2026-95285","CVE-2026-95286","CVE-2026-95287","CVE-2026-95288","CVE-2026-95289","CVE-2026-95290","CVE-2026-95291","CVE-2026-95292","CVE-2026-95293","CVE-2026-95294","CVE-2026-95295","CVE-2026-95296","CVE-2026-95297","CVE-2026-95298","CVE-2026-95299","CVE-2026-95300","CVE-2026-95301","CVE-2026-95302","CVE-2026-95303","CVE-2026-95304","CVE-2026-95305","CVE-2026-95306","CVE-2026-95307","CVE-2026-95308","CVE-2026-95309","CVE-2026-95310","CVE-2026-95311","CVE-2026-95312","CVE-2026-95313","CVE-2026-95314","CVE-2026-95315","CVE-2026-95316","CVE-2026-95317","CVE-2026-95318","CVE-2026-95319","CVE-2026-95320","CVE-2026-95321","CVE-2026-95322","CVE-2026-95323","CVE-2026-95324","CVE-2026-95325","CVE-2026-95326","CVE-2026-95327","CVE-2026-95328","CVE-2026-95329","CVE-2026-95330","CVE-2026-95331","CVE-2026-95332","CVE-2026-95333","CVE-2026-95334","CVE-2026-95335","CVE-2026-95336","CVE-2026-95337","CVE-2026-95338","CVE-2026-95339","CVE-2026-95340","CVE-2026-95341","CVE-2026-95342","CVE-2026-95343","CVE-2026-95344","CVE-2026-95345","CVE-2026-95346","CVE-2026-95347","CVE-2026-95348","CVE-2026-95349","CVE-2026-95350","CVE-2026-95351","CVE-2026-95352","CVE-2026-95353","CVE-2026-95354","CVE-2026-95355","CVE-2026-95356","CVE-2026-95357","CVE-2026-95358","CVE-2026-95359","CVE-2026-95360","CVE-2026-95361","CVE-2026-95362","CVE-2026-95363","CVE-2026-95364","CVE-2026-95365","CVE-2026-95366","CVE-2026-95367","CVE-2026-95368","CVE-2026-95369","CVE-2026-95370","CVE-2026-95371","CVE-2026-95372","CVE-2026-95373","CVE-2026-95374","CVE-2026-95375","CVE-2026-95376","CVE-2026-95380","CVE-2026-95381","CVE-2026-95382","CVE-2026-95384","CVE-2026-95385"],"upstream":["CVE-2026-95274","CVE-2026-95275","CVE-2026-95276","CVE-2026-95277","CVE-2026-95278","CVE-2026-95279","CVE-2026-95280","CVE-2026-95281","CVE-2026-95282","CVE-2026-95283","CVE-2026-95284","CVE-2026-95285","CVE-2026-95286","CVE-2026-95287","CVE-2026-95288","CVE-2026-95289","CVE-2026-95290","CVE-2026-95291","CVE-2026-95292","CVE-2026-95293","CVE-2026-95294","CVE-2026-95295","CVE-2026-95296","CVE-2026-95297","CVE-2026-95298","CVE-2026-95299","CVE-2026-95300","CVE-2026-95301","CVE-2026-95302","CVE-2026-95303","CVE-2026-95304","CVE-2026-95305","CVE-2026-95306","CVE-2026-95307","CVE-2026-95308","CVE-2026-95309","CVE-2026-95310","CVE-2026-95311","CVE-2026-95312","CVE-2026-95313","CVE-2026-95314","CVE-2026-95315","CVE-2026-95316","CVE-2026-95317","CVE-2026-95318","CVE-2026-95319","CVE-2026-95320","CVE-2026-95321","CVE-2026-95322","CVE-2026-95323","CVE-2026-95324","CVE-2026-95325","CVE-2026-95326","CVE-2026-95327","CVE-2026-95328","CVE-2026-95329","CVE-2026-95330","CVE-2026-95331","CVE-2026-95332","CVE-2026-95333","CVE-2026-95334","CVE-2026-95335","CVE-2026-95336","CVE-2026-95337","CVE-2026-95338","CVE-2026-95339","CVE-2026-95340","CVE-2026-95341","CVE-2026-95342","CVE-2026-95343","CVE-2026-95344","CVE-2026-95345","CVE-2026-95346","CVE-2026-95347","CVE-2026-95348","CVE-2026-95349","CVE-2026-95350","CVE-2026-95351","CVE-2026-95352","CVE-2026-95353","CVE-2026-95354","CVE-2026-95355","CVE-2026-95356","CVE-2026-95357","CVE-2026-95358","CVE-2026-95359","CVE-2026-95360","CVE-2026-95361","CVE-2026-95362","CVE-2026-95363","CVE-2026-95364","CVE-2026-95365","CVE-2026-95366","CVE-2026-95367","CVE-2026-95368","CVE-2026-95369","CVE-2026-95370","CVE-2026-95371","CVE-2026-95372","CVE-2026-95373","CVE-2026-95374","CVE-2026-95375","CVE-2026-95376","CVE-2026-95380","CVE-2026-95381","CVE-2026-95382","CVE-2026-95384","CVE-2026-95385"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282334"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95274"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95275"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95276"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95277"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95278"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95279"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95280"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95281"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95282"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95283"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95284"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95285"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95286"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95287"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95289"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95290"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95291"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95292"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95293"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95294"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95295"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95296"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95297"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95298"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95299"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95300"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95301"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95302"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95303"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95304"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95305"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95306"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95307"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95308"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95309"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95310"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95311"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95312"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95313"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95314"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95315"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95316"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95317"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95318"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95319"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95320"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95321"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95322"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95323"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95324"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95326"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95328"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95329"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95330"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95331"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95332"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95333"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95334"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95335"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95336"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95337"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95338"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95339"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95340"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95341"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95342"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95343"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95344"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95345"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95346"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95347"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95348"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95349"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95350"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95351"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95352"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95353"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95354"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95358"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95359"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95361"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95362"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95363"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95364"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95365"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95367"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95368"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95369"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95370"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95371"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95372"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95374"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95376"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95381"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95384"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-95385"}],"affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"154.0.8037.57-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"chromium":"154.0.8037.57-bp160.1.1","chromedriver":"154.0.8037.57-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21987-1.json"}}],"schema_version":"1.9.0"}