Update Info

SUSE-PackageHub-16.0-packagehub-1


Security update for chromium


Type: security
Severity: critical
Issued: 2025-10-15
Description:
This update for chromium fixes the following issues:

Chromium 141.0.7390.76:

  * Do not send URLs as AIM input. This is to resolve a privacy
    concern, around passing urls to AI Mode.

Chromium 141.0.7390.65 (boo#1251334):

  * CVE-2025-11458: Heap buffer overflow in Sync
  * CVE-2025-11460: Use after free in Storage
  * CVE-2025-11211: Out of bounds read in WebCodecs

Chromium 141.0.7390.54 (stable released 2025-09-30) (boo#1250780)

  * CVE-2025-11205: Heap buffer overflow in WebGPU
  * CVE-2025-11206: Heap buffer overflow in Video
  * CVE-2025-11207: Side-channel information leakage in Storage
  * CVE-2025-11208: Inappropriate implementation in Media
  * CVE-2025-11209: Inappropriate implementation in Omnibox
  * CVE-2025-11210: Side-channel information leakage in Tab
  * CVE-2025-11211: Out of bounds read in Media
  * CVE-2025-11212: Inappropriate implementation in Media
  * CVE-2025-11213: Inappropriate implementation in Omnibox
  * CVE-2025-11215: Off by one error in V8
  * CVE-2025-11216: Inappropriate implementation in Storage
  * CVE-2025-11219: Use after free in V8
  * Various fixes from internal audits, fuzzing and other initiatives

Chromium 141.0.7390.37 (beta released 2025-09-24)

Chromium 140.0.7339.207 (boo#1250472)

  * CVE-2025-10890: Side-channel information leakage in V8
  * CVE-2025-10891: Integer overflow in V8
  * CVE-2025-10892: Integer overflow in V8



              

Packages