{"id":"openSUSE-SU-2026:20183-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChanges in chromium:\n\n- Chromium 144.0.7559.132 (boo#1257650)\n  * CVE-2026-1861: Heap buffer overflow in libvpx in Google Chrome\n    prior to 144.0.7559.132 allowed a remote attacker to potentially\n    exploit heap corruption via a crafted HTML page.\n  * CVE-2026-1862: Type Confusion in V8 in Google Chrome prior to\n    144.0.7559.132 allowed a remote attacker to potentially exploit\n    heap corruption via a crafted HTML page.\n\n- Chromium 144.0.7559.109 (boo#1257404)\n  * CVE-2026-1504: Inappropriate implementation in Background Fetch API\n\n- Chromium 144.0.7559.96 (boo#1257011)\n  * CVE-2026-1220: Race in V8\n- update INSTALL.sh to handle the addded tags in the desktop file (boo#1256938)\n\n- Chromium 144.0.7559.59 (boo#1256614)\n  * CVE-2026-0899: Out of bounds memory access in V8\n  * CVE-2026-0900: Inappropriate implementation in V8\n  * CVE-2026-0901: Inappropriate implementation in Blink\n  * CVE-2026-0902: Inappropriate implementation in V8\n  * CVE-2026-0903: Insufficient validation of untrusted input in Downloads\n  * CVE-2026-0904: Incorrect security UI in Digital Credentials\n  * CVE-2026-0905: Insufficient policy enforcement in Network\n  * CVE-2026-0906: Incorrect security UI\n  * CVE-2026-0907: Incorrect security UI in Split View\n  * CVE-2026-0908: Use after free in ANGLE\n- use noopenh264 where available\n","modified":"2026-09-02T18:27:35.654187319Z","published":"2026-08-31T08:39:48Z","related":["CVE-2026-0899","CVE-2026-0900","CVE-2026-0901","CVE-2026-0902","CVE-2026-0903","CVE-2026-0904","CVE-2026-0905","CVE-2026-0906","CVE-2026-0907","CVE-2026-0908","CVE-2026-1220","CVE-2026-1504","CVE-2026-1861","CVE-2026-1862"],"upstream":["CVE-2026-0899","CVE-2026-0900","CVE-2026-0901","CVE-2026-0902","CVE-2026-0903","CVE-2026-0904","CVE-2026-0905","CVE-2026-0906","CVE-2026-0907","CVE-2026-0908","CVE-2026-1220","CVE-2026-1504","CVE-2026-1861","CVE-2026-1862"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256614"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256938"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257011"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257404"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257650"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0899"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0900"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0901"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0902"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0903"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0904"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0905"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0906"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0907"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0908"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1220"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1504"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1862"}],"affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"144.0.7559.132-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"144.0.7559.132-bp160.1.1","chromium":"144.0.7559.132-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20183-1.json"}}],"schema_version":"1.9.0"}