openSUSE-SU-2026:20020-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20020-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:20020-1
Upstream
CVE (19)
Related
Published
2026-08-31T08:39:47Z
Modified
2026-09-02T18:27:37Z
Summary
Security update for chromium
Details

This update for chromium fixes the following issues:

Changes in chromium:

  • Chromium 143.0.7499.192 (boo#1256067):

    • CVE-2026-0628: Insufficient policy enforcement in WebView tag
  • Chromium 143.0.7499.169 (stable released 2025-12-18)

    • no cve listed yet

Chromium 143.0.7499.146 (boo#1255115):

  • CVE-2025-14765: Use after free in WebGPU
  • CVE-2025-14766: Out of bounds read and write in V8
  • CVE-2025-14174: Out of bounds memory access in ANGLE
  • Chromium 143.0.7499.109 (boo#1254776):
    • CVE-2025-14372: Use after free in Password Manager
    • CVE-2025-14373: Inappropriate implementation in Toolbar
    • third issue with an exploit is known to exist in the wild

Chromium 143.0.7499.40 (boo#1254429):

  • CVE-2025-13630: Type Confusion in V8
  • CVE-2025-13631: Inappropriate implementation in Google Updater
  • CVE-2025-13632: Inappropriate implementation in DevTools
  • CVE-2025-13633: Use after free in Digital Credentials
  • CVE-2025-13634: Inappropriate implementation in Downloads
  • CVE-2025-13720: Bad cast in Loader
  • CVE-2025-13721: Race in v8
  • CVE-2025-13635: Inappropriate implementation in Downloads
  • CVE-2025-13636: Inappropriate implementation in Split View
  • CVE-2025-13637: Inappropriate implementation in Downloads
  • CVE-2025-13638: Use after free in Media Stream
  • CVE-2025-13639: Inappropriate implementation in WebRTC
  • CVE-2025-13640: Inappropriate implementation in Passwords
References

Affected packages

openSUSE:Leap 16.0 / chromium

Package

Name
chromium
Purl
pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
143.0.7499.192-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "chromedriver":  "143.0.7499.192-bp160.1.1",
            "chromium":  "143.0.7499.192-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20020-1.json"