{"id":"openSUSE-SU-2025:20032-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChromium 141.0.7390.122:\n\n  * CVE-2025-12036: Inappropriate implementation in V8 (boo#1252402)\n\nChromium 141.0.7390.107:\n\n* CVE-2025-11756: Use after free in Safe Browsing (boo#1252013)\n\nChromium 141.0.7390.76:\n\n* Do not send URLs as AIM input. This is to resolve a privacy\n  concern, around passing urls to AI Mode.\n\nChromium 141.0.7390.65 (boo#1251334):\n\n* CVE-2025-11458: Heap buffer overflow in Sync\n* CVE-2025-11460: Use after free in Storage\n* CVE-2025-11211: Out of bounds read in WebCodecs\n\nChromium 141.0.7390.54 (stable released 2025-09-30) (boo#1250780)\n\n* CVE-2025-11205: Heap buffer overflow in WebGPU\n* CVE-2025-11206: Heap buffer overflow in Video\n* CVE-2025-11207: Side-channel information leakage in Storage\n* CVE-2025-11208: Inappropriate implementation in Media\n* CVE-2025-11209: Inappropriate implementation in Omnibox\n* CVE-2025-11210: Side-channel information leakage in Tab\n* CVE-2025-11211: Out of bounds read in Media\n* CVE-2025-11212: Inappropriate implementation in Media\n* CVE-2025-11213: Inappropriate implementation in Omnibox\n* CVE-2025-11215: Off by one error in V8\n* CVE-2025-11216: Inappropriate implementation in Storage\n* CVE-2025-11219: Use after free in V8\n* Various fixes from internal audits, fuzzing and other initiatives\n\nChromium 141.0.7390.37 (beta released 2025-09-24)\n\nChromium 140.0.7339.207 (boo#1250472)\n\n* CVE-2025-10890: Side-channel information leakage in V8\n* CVE-2025-10891: Integer overflow in V8\n* CVE-2025-10892: Integer overflow in V8\n","modified":"2026-09-06T18:27:18.756063957Z","published":"2026-08-31T08:39:29Z","related":["CVE-2025-10890","CVE-2025-10891","CVE-2025-10892","CVE-2025-11205","CVE-2025-11206","CVE-2025-11207","CVE-2025-11208","CVE-2025-11209","CVE-2025-11210","CVE-2025-11211","CVE-2025-11212","CVE-2025-11213","CVE-2025-11215","CVE-2025-11216","CVE-2025-11219","CVE-2025-11458","CVE-2025-11460","CVE-2025-11756","CVE-2025-12036"],"upstream":["CVE-2025-10890","CVE-2025-10891","CVE-2025-10892","CVE-2025-11205","CVE-2025-11206","CVE-2025-11207","CVE-2025-11208","CVE-2025-11209","CVE-2025-11210","CVE-2025-11211","CVE-2025-11212","CVE-2025-11213","CVE-2025-11215","CVE-2025-11216","CVE-2025-11219","CVE-2025-11458","CVE-2025-11460","CVE-2025-11756","CVE-2025-12036"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250472"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250780"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251334"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252013"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252402"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-10890"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-10891"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-10892"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11205"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11206"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11207"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11208"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11209"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11210"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11211"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11212"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11215"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11458"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11460"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11756"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-12036"}],"affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"141.0.7390.122-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"chromium":"141.0.7390.122-bp160.1.1","chromedriver":"141.0.7390.122-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2025:20032-1.json"}}],"schema_version":"1.9.0"}