OPENSUSE-SU-2026:20575-1
Vulnerability from csaf_opensuse - Published: 2026-04-12 20:14 - Updated: 2026-04-12 20:14Summary
Security update for chromium
Severity
Moderate
Notes
Title of the patch: Security update for chromium
Description of the patch: This update for chromium fixes the following issues:
Chromium 147.0.7727.55 (boo#1261758):
* CVE-2026-5858: Heap buffer overflow in WebML
* CVE-2026-5859: Integer overflow in WebML
* CVE-2026-5860: Use after free in WebRTC
* CVE-2026-5861: Use after free in V8
* CVE-2026-5862: Inappropriate implementation in V8
* CVE-2026-5863: Inappropriate implementation in V8
* CVE-2026-5864: Heap buffer overflow in WebAudio
* CVE-2026-5865: Type Confusion in V8
* CVE-2026-5866: Use after free in Media
* CVE-2026-5867: Heap buffer overflow in WebML
* CVE-2026-5868: Heap buffer overflow in ANGLE
* CVE-2026-5869: Heap buffer overflow in WebML
* CVE-2026-5870: Integer overflow in Skia
* CVE-2026-5871: Type Confusion in V8
* CVE-2026-5872: Use after free in Blink
* CVE-2026-5873: Out of bounds read and write in V8
* CVE-2026-5874: Use after free in PrivateAI
* CVE-2026-5875: Policy bypass in Blink
* CVE-2026-5876: Side-channel information leakage in Navigation
* CVE-2026-5877: Use after free in Navigation
* CVE-2026-5878: Incorrect security UI in Blink
* CVE-2026-5879: Insufficient validation of untrusted input in ANGLE
* CVE-2026-5880: Incorrect security UI in browser UI
* CVE-2026-5881: Policy bypass in LocalNetworkAccess
* CVE-2026-5882: Incorrect security UI in Fullscreen
* CVE-2026-5883: Use after free in Media
* CVE-2026-5884: Insufficient validation of untrusted input in Media
* CVE-2026-5885: Insufficient validation of untrusted input in WebML
* CVE-2026-5886: Out of bounds read in WebAudio
* CVE-2026-5887: Insufficient validation of untrusted input in Downloads
* CVE-2026-5888: Uninitialized Use in WebCodecs
* CVE-2026-5889: Cryptographic Flaw in PDFium
* CVE-2026-5890: Race in WebCodecs
* CVE-2026-5891: Insufficient policy enforcement in browser UI
* CVE-2026-5892: Insufficient policy enforcement in PWAs
* CVE-2026-5893: Race in V8
* CVE-2026-5894: Inappropriate implementation in PDF
* CVE-2026-5895: Incorrect security UI in Omnibox
* CVE-2026-5896: Policy bypass in Audio
* CVE-2026-5897: Incorrect security UI in Downloads
* CVE-2026-5898: Incorrect security UI in Omnibox
* CVE-2026-5899: Incorrect security UI in History Navigation
* CVE-2026-5900: Policy bypass in Downloads
* CVE-2026-5901: Policy bypass in DevTools
* CVE-2026-5902: Race in Media
* CVE-2026-5903: Policy bypass in IFrameSandbox
* CVE-2026-5904: Use after free in V8
* CVE-2026-5905: Incorrect security UI in Permissions
* CVE-2026-5906: Incorrect security UI in Omnibox
* CVE-2026-5907: Insufficient data validation in Media
* CVE-2026-5908: Integer overflow in Media
* CVE-2026-5909: Integer overflow in Media
* CVE-2026-5910: Integer overflow in Media
* CVE-2026-5911: Policy bypass in ServiceWorkers
* CVE-2026-5912: Integer overflow in WebRTC
* CVE-2026-5913: Out of bounds read in Blink
* CVE-2026-5914: Type Confusion in CSS
* CVE-2026-5915: Insufficient validation of untrusted input in WebML
* CVE-2026-5918: Inappropriate implementation in Navigation
* CVE-2026-5919: Insufficient validation of untrusted input in WebSockets
* enforce a number of new Local Area Network (LAN) restrictions
* New Web Printing API
* vertical tabs support (trial)
- new in 147 (for developers):
* Element-scoped view transitions exposes startViewTransition on arbitrary HTML elements.
* CSS contrast-color() helps meet accessibility requirements
* The CSS border-shape property lets you create non-rectangular borders
* CVE-2025-4096: Heap buffer overflow in HTML
* CVE-2025-4050: Out of bounds memory access in DevTools
* CVE-2025-4051: Insufficient data validation in DevTools
* CVE-2025-4052: Inappropriate implementation in DevTools
* CVE-2024-7000: Use after free in CSS
* CVE-2024-3834: Use after free in Downloads
* CVE-2020-6465: Use after free in reader mode
* CVE-2020-6466: Use after free in media
* CVE-2020-6467: Use after free in WebRTC
* CVE-2020-6468: Type Confusion in V8
* CVE-2020-6469: Insufficient policy enforcement in developer tools
* CVE-2020-6470: Insufficient validation of untrusted input in clipboard
* CVE-2020-6471: Insufficient policy enforcement in developer tools
* CVE-2020-6472: Insufficient policy enforcement in developer tools
* CVE-2020-6473: Insufficient policy enforcement in Blink
* CVE-2020-6474: Use after free in Blink
* CVE-2020-6475: Incorrect security UI in full screen
* CVE-2020-6476: Insufficient policy enforcement in tab strip
* CVE-2020-6477: Inappropriate implementation in installer
* CVE-2020-6478: Inappropriate implementation in full screen
* CVE-2020-6479: Inappropriate implementation in sharing
* CVE-2020-6480: Insufficient policy enforcement in enterprise
* CVE-2020-6481: Insufficient policy enforcement in URL formatting
* CVE-2020-6482: Insufficient policy enforcement in developer tools
* CVE-2020-6483: Insufficient policy enforcement in payments
* CVE-2020-6484: Insufficient data validation in ChromeDriver
* CVE-2020-6485: Insufficient data validation in media router
* CVE-2020-6486: Insufficient policy enforcement in navigations
* CVE-2020-6487: Insufficient policy enforcement in downloads
* CVE-2020-6488: Insufficient policy enforcement in downloads
* CVE-2020-6489: Inappropriate implementation in developer tools
* CVE-2020-6490: Insufficient data validation in loader
* CVE-2020-6491: Incorrect security UI in site information
* CVE-2019-5754: Inappropriate implementation in QUIC Networking
* CVE-2019-5782: Inappropriate implementation in V8
* CVE-2019-5755: Inappropriate implementation in V8
* CVE-2019-5756: Use after free in PDFium
* CVE-2019-5757: Type Confusion in SVG
* CVE-2019-5758: Use after free in Blink
* CVE-2019-5759: Use after free in HTML select elements
* CVE-2019-5760: Use after free in WebRTC
* CVE-2019-5761: Use after free in SwiftShader
* CVE-2019-5762: Use after free in PDFium
* CVE-2019-5763: Insufficient validation of untrusted input in V8
* CVE-2019-5764: Use after free in WebRTC
* CVE-2019-5765: Insufficient policy enforcement in the browser
* CVE-2019-5766: Insufficient policy enforcement in Canvas
* CVE-2019-5767: Incorrect security UI in WebAPKs
* CVE-2019-5768: Insufficient policy enforcement in DevTools
* CVE-2019-5769: Insufficient validation of untrusted input in Blink
* CVE-2019-5770: Heap buffer overflow in WebGL
* CVE-2019-5771: Heap buffer overflow in SwiftShader
* CVE-2019-5772: Use after free in PDFium
* CVE-2019-5773: Insufficient data validation in IndexedDB
* CVE-2019-5774: Insufficient validation of untrusted input in SafeBrowsing
* CVE-2019-5775: Insufficient policy enforcement in Omnibox
* CVE-2019-5776: Insufficient policy enforcement in Omnibox
* CVE-2019-5777: Insufficient policy enforcement in Omnibox
* CVE-2019-5778: Insufficient policy enforcement in Extensions
* CVE-2019-5779: Insufficient policy enforcement in ServiceWorker
* CVE-2019-5780: Insufficient policy enforcement
* CVE-2019-5781: Insufficient policy enforcement in Omnibox
* High CVE-2018-6031: Use after free in PDFium
* High CVE-2018-6032: Same origin bypass in Shared Worker
* High CVE-2018-6033: Race when opening downloaded files
* Medium CVE-2018-6034: Integer overflow in Blink
* Medium CVE-2018-6035: Insufficient isolation of devtools from extensions
* Medium CVE-2018-6036: Integer underflow in WebAssembly
* Medium CVE-2018-6037: Insufficient user gesture requirements in autofill
* Medium CVE-2018-6038: Heap buffer overflow in WebGL
* Medium CVE-2018-6039: XSS in DevTools
* Medium CVE-2018-6040: Content security policy bypass
* Medium CVE-2018-6041: URL spoof in Navigation
* Medium CVE-2018-6042: URL spoof in OmniBox
* Medium CVE-2018-6043: Insufficient escaping with external URL handlers
* Medium CVE-2018-6045: Insufficient isolation of devtools from extensions
* Medium CVE-2018-6046: Insufficient isolation of devtools from extensions
* Medium CVE-2018-6047: Cross origin URL leak in WebGL
* Low CVE-2018-6048: Referrer policy bypass in Blink
* Low CVE-2017-15420: URL spoofing in Omnibox
* Low CVE-2018-6049: UI spoof in Permissions
* Low CVE-2018-6050: URL spoof in OmniBox
* Low CVE-2018-6051: Referrer leak in XSS Auditor
* Low CVE-2018-6052: Incomplete no-referrer policy implementation
* Low CVE-2018-6053: Leak of page thumbnails in New Tab Page
* Low CVE-2018-6054: Use after free in WebUI
* CVE-2017-5070: Type confusion in V8
* CVE-2017-5071: Out of bounds read in V8
* CVE-2017-5072: Address spoofing in Omnibox
* CVE-2017-5073: Use after free in print preview
* CVE-2017-5074: Use after free in Apps Bluetooth
* CVE-2017-5075: Information leak in CSP reporting
* CVE-2017-5086: Address spoofing in Omnibox
* CVE-2017-5076: Address spoofing in Omnibox
* CVE-2017-5077: Heap buffer overflow in Skia
* CVE-2017-5078: Possible command injection in mailto handling
* CVE-2017-5079: UI spoofing in Blink
* CVE-2017-5080: Use after free in credit card autofill
* CVE-2017-5081: Extension verification bypass
* CVE-2017-5082: Insufficient hardening in credit card editor
* CVE-2017-5083: UI spoofing in Blink
* CVE-2017-5085: Inappropriate javascript execution on WebUI pages
- CVE-2016-1663: Use-after-free in Blink's V8 bindings
* CVE-2013-6643: Unprompted sync with an attacker's
* Use Google's online spellchecker to identify misspelled words
Patchnames: openSUSE-Leap-16.0-packagehub-193
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Affected products
Recommended
6 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64 | — |
Vendor Fix
|
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
8.8 (High)
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
5.3 (Medium)
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
Affected products
Recommended
6 products, the same list as for
CVE-2026-5858
Threats
Impact
critical
References
183 references
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "moderate"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "Security update for chromium",
"title": "Title of the patch"
},
{
"category": "description",
"text": "This update for chromium fixes the following issues:\n\nChromium 147.0.7727.55 (boo#1261758):\n\n * CVE-2026-5858: Heap buffer overflow in WebML\n * CVE-2026-5859: Integer overflow in WebML\n * CVE-2026-5860: Use after free in WebRTC\n * CVE-2026-5861: Use after free in V8\n * CVE-2026-5862: Inappropriate implementation in V8\n * CVE-2026-5863: Inappropriate implementation in V8\n * CVE-2026-5864: Heap buffer overflow in WebAudio\n * CVE-2026-5865: Type Confusion in V8\n * CVE-2026-5866: Use after free in Media\n * CVE-2026-5867: Heap buffer overflow in WebML\n * CVE-2026-5868: Heap buffer overflow in ANGLE\n * CVE-2026-5869: Heap buffer overflow in WebML\n * CVE-2026-5870: Integer overflow in Skia\n * CVE-2026-5871: Type Confusion in V8\n * CVE-2026-5872: Use after free in Blink\n * CVE-2026-5873: Out of bounds read and write in V8\n * CVE-2026-5874: Use after free in PrivateAI\n * CVE-2026-5875: Policy bypass in Blink\n * CVE-2026-5876: Side-channel information leakage in Navigation\n * CVE-2026-5877: Use after free in Navigation\n * CVE-2026-5878: Incorrect security UI in Blink\n * CVE-2026-5879: Insufficient validation of untrusted input in ANGLE\n * CVE-2026-5880: Incorrect security UI in browser UI\n * CVE-2026-5881: Policy bypass in LocalNetworkAccess\n * CVE-2026-5882: Incorrect security UI in Fullscreen\n * CVE-2026-5883: Use after free in Media\n * CVE-2026-5884: Insufficient validation of untrusted input in Media\n * CVE-2026-5885: Insufficient validation of untrusted input in WebML\n * CVE-2026-5886: Out of bounds read in WebAudio\n * CVE-2026-5887: Insufficient validation of untrusted input in Downloads\n * CVE-2026-5888: Uninitialized Use in WebCodecs\n * CVE-2026-5889: Cryptographic Flaw in PDFium\n * CVE-2026-5890: Race in WebCodecs\n * CVE-2026-5891: Insufficient policy enforcement in browser UI\n * CVE-2026-5892: Insufficient policy enforcement in PWAs\n * CVE-2026-5893: Race in V8\n * CVE-2026-5894: Inappropriate implementation in PDF\n * CVE-2026-5895: Incorrect security UI in Omnibox\n * CVE-2026-5896: Policy bypass in Audio\n * CVE-2026-5897: Incorrect security UI in Downloads\n * CVE-2026-5898: Incorrect security UI in Omnibox\n * CVE-2026-5899: Incorrect security UI in History Navigation\n * CVE-2026-5900: Policy bypass in Downloads\n * CVE-2026-5901: Policy bypass in DevTools\n * CVE-2026-5902: Race in Media\n * CVE-2026-5903: Policy bypass in IFrameSandbox\n * CVE-2026-5904: Use after free in V8\n * CVE-2026-5905: Incorrect security UI in Permissions\n * CVE-2026-5906: Incorrect security UI in Omnibox\n * CVE-2026-5907: Insufficient data validation in Media\n * CVE-2026-5908: Integer overflow in Media\n * CVE-2026-5909: Integer overflow in Media\n * CVE-2026-5910: Integer overflow in Media\n * CVE-2026-5911: Policy bypass in ServiceWorkers\n * CVE-2026-5912: Integer overflow in WebRTC\n * CVE-2026-5913: Out of bounds read in Blink\n * CVE-2026-5914: Type Confusion in CSS\n * CVE-2026-5915: Insufficient validation of untrusted input in WebML\n * CVE-2026-5918: Inappropriate implementation in Navigation\n * CVE-2026-5919: Insufficient validation of untrusted input in WebSockets\n * enforce a number of new Local Area Network (LAN) restrictions\n * New Web Printing API\n * vertical tabs support (trial)\n\n- new in 147 (for developers):\n\n * Element-scoped view transitions exposes startViewTransition on arbitrary HTML elements.\n * CSS contrast-color() helps meet accessibility requirements\n * The CSS border-shape property lets you create non-rectangular borders\n\n * CVE-2025-4096: Heap buffer overflow in HTML\n * CVE-2025-4050: Out of bounds memory access in DevTools\n * CVE-2025-4051: Insufficient data validation in DevTools\n * CVE-2025-4052: Inappropriate implementation in DevTools\n * CVE-2024-7000: Use after free in CSS\n * CVE-2024-3834: Use after free in Downloads\n * CVE-2020-6465: Use after free in reader mode\n * CVE-2020-6466: Use after free in media\n * CVE-2020-6467: Use after free in WebRTC\n * CVE-2020-6468: Type Confusion in V8\n * CVE-2020-6469: Insufficient policy enforcement in developer tools\n * CVE-2020-6470: Insufficient validation of untrusted input in clipboard\n * CVE-2020-6471: Insufficient policy enforcement in developer tools\n * CVE-2020-6472: Insufficient policy enforcement in developer tools\n * CVE-2020-6473: Insufficient policy enforcement in Blink\n * CVE-2020-6474: Use after free in Blink\n * CVE-2020-6475: Incorrect security UI in full screen\n * CVE-2020-6476: Insufficient policy enforcement in tab strip\n * CVE-2020-6477: Inappropriate implementation in installer\n * CVE-2020-6478: Inappropriate implementation in full screen\n * CVE-2020-6479: Inappropriate implementation in sharing\n * CVE-2020-6480: Insufficient policy enforcement in enterprise\n * CVE-2020-6481: Insufficient policy enforcement in URL formatting\n * CVE-2020-6482: Insufficient policy enforcement in developer tools\n * CVE-2020-6483: Insufficient policy enforcement in payments\n * CVE-2020-6484: Insufficient data validation in ChromeDriver\n * CVE-2020-6485: Insufficient data validation in media router\n * CVE-2020-6486: Insufficient policy enforcement in navigations\n * CVE-2020-6487: Insufficient policy enforcement in downloads\n * CVE-2020-6488: Insufficient policy enforcement in downloads\n * CVE-2020-6489: Inappropriate implementation in developer tools\n * CVE-2020-6490: Insufficient data validation in loader\n * CVE-2020-6491: Incorrect security UI in site information\n * CVE-2019-5754: Inappropriate implementation in QUIC Networking\n * CVE-2019-5782: Inappropriate implementation in V8\n * CVE-2019-5755: Inappropriate implementation in V8\n * CVE-2019-5756: Use after free in PDFium\n * CVE-2019-5757: Type Confusion in SVG\n * CVE-2019-5758: Use after free in Blink\n * CVE-2019-5759: Use after free in HTML select elements\n * CVE-2019-5760: Use after free in WebRTC\n * CVE-2019-5761: Use after free in SwiftShader\n * CVE-2019-5762: Use after free in PDFium\n * CVE-2019-5763: Insufficient validation of untrusted input in V8\n * CVE-2019-5764: Use after free in WebRTC\n * CVE-2019-5765: Insufficient policy enforcement in the browser\n * CVE-2019-5766: Insufficient policy enforcement in Canvas\n * CVE-2019-5767: Incorrect security UI in WebAPKs\n * CVE-2019-5768: Insufficient policy enforcement in DevTools\n * CVE-2019-5769: Insufficient validation of untrusted input in Blink\n * CVE-2019-5770: Heap buffer overflow in WebGL\n * CVE-2019-5771: Heap buffer overflow in SwiftShader\n * CVE-2019-5772: Use after free in PDFium\n * CVE-2019-5773: Insufficient data validation in IndexedDB\n * CVE-2019-5774: Insufficient validation of untrusted input in SafeBrowsing\n * CVE-2019-5775: Insufficient policy enforcement in Omnibox\n * CVE-2019-5776: Insufficient policy enforcement in Omnibox\n * CVE-2019-5777: Insufficient policy enforcement in Omnibox\n * CVE-2019-5778: Insufficient policy enforcement in Extensions\n * CVE-2019-5779: Insufficient policy enforcement in ServiceWorker\n * CVE-2019-5780: Insufficient policy enforcement\n * CVE-2019-5781: Insufficient policy enforcement in Omnibox\n * High CVE-2018-6031: Use after free in PDFium\n * High CVE-2018-6032: Same origin bypass in Shared Worker\n * High CVE-2018-6033: Race when opening downloaded files\n * Medium CVE-2018-6034: Integer overflow in Blink\n * Medium CVE-2018-6035: Insufficient isolation of devtools from extensions\n * Medium CVE-2018-6036: Integer underflow in WebAssembly\n * Medium CVE-2018-6037: Insufficient user gesture requirements in autofill\n * Medium CVE-2018-6038: Heap buffer overflow in WebGL\n * Medium CVE-2018-6039: XSS in DevTools\n * Medium CVE-2018-6040: Content security policy bypass\n * Medium CVE-2018-6041: URL spoof in Navigation\n * Medium CVE-2018-6042: URL spoof in OmniBox\n * Medium CVE-2018-6043: Insufficient escaping with external URL handlers\n * Medium CVE-2018-6045: Insufficient isolation of devtools from extensions\n * Medium CVE-2018-6046: Insufficient isolation of devtools from extensions\n * Medium CVE-2018-6047: Cross origin URL leak in WebGL\n * Low CVE-2018-6048: Referrer policy bypass in Blink\n * Low CVE-2017-15420: URL spoofing in Omnibox\n * Low CVE-2018-6049: UI spoof in Permissions\n * Low CVE-2018-6050: URL spoof in OmniBox\n * Low CVE-2018-6051: Referrer leak in XSS Auditor\n * Low CVE-2018-6052: Incomplete no-referrer policy implementation\n * Low CVE-2018-6053: Leak of page thumbnails in New Tab Page\n * Low CVE-2018-6054: Use after free in WebUI\n * CVE-2017-5070: Type confusion in V8\n * CVE-2017-5071: Out of bounds read in V8\n * CVE-2017-5072: Address spoofing in Omnibox\n * CVE-2017-5073: Use after free in print preview\n * CVE-2017-5074: Use after free in Apps Bluetooth\n * CVE-2017-5075: Information leak in CSP reporting\n * CVE-2017-5086: Address spoofing in Omnibox\n * CVE-2017-5076: Address spoofing in Omnibox\n * CVE-2017-5077: Heap buffer overflow in Skia\n * CVE-2017-5078: Possible command injection in mailto handling\n * CVE-2017-5079: UI spoofing in Blink\n * CVE-2017-5080: Use after free in credit card autofill\n * CVE-2017-5081: Extension verification bypass\n * CVE-2017-5082: Insufficient hardening in credit card editor\n * CVE-2017-5083: UI spoofing in Blink\n * CVE-2017-5085: Inappropriate javascript execution on WebUI pages\n - CVE-2016-1663: Use-after-free in Blink\u0027s V8 bindings\n * CVE-2013-6643: Unprompted sync with an attacker\u0027s\n * Use Google\u0027s online spellchecker to identify misspelled words\n",
"title": "Description of the patch"
},
{
"category": "details",
"text": "openSUSE-Leap-16.0-packagehub-193",
"title": "Patchnames"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "SUSE ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "self",
"summary": "URL of this CSAF notice",
"url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_20575-1.json"
},
{
"category": "self",
"summary": "SUSE Bug 1261758",
"url": "https://bugzilla.suse.com/1261758"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5858 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5858/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5859 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5859/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5860 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5860/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5861 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5861/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5862 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5862/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5863 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5863/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5864 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5864/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5865 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5865/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5866 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5866/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5867 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5867/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5868 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5868/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5869 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5869/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5870 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5870/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5871 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5871/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5872 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5872/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5873 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5873/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5874 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5874/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5875 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5875/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5876 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5876/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5877 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5877/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5878 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5878/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5879 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5879/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5880 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5880/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5881 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5881/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5882 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5882/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5883 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5883/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5884 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5884/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5885 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5885/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5886 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5886/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5887 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5887/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5888 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5888/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5889 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5889/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5890 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5890/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5891 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5891/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5892 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5892/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5893 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5893/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5894 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5894/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5895 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5895/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5896 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5896/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5897 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5897/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5898 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5898/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5899 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5899/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5900 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5900/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5901 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5901/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5902 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5902/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5903 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5903/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5904 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5904/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5905 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5905/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5906 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5906/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5907 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5907/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5908 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5908/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5909 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5909/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5910 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5910/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5911 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5911/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5912 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5912/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5913 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5913/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5914 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5914/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5915 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5915/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5918 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5918/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-5919 page",
"url": "https://www.suse.com/security/cve/CVE-2026-5919/"
}
],
"title": "Security update for chromium",
"tracking": {
"current_release_date": "2026-04-12T20:14:42Z",
"generator": {
"date": "2026-04-12T20:14:42Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf.pl",
"version": "1"
}
},
"id": "openSUSE-SU-2026:20575-1",
"initial_release_date": "2026-04-12T20:14:42Z",
"revision_history": [
{
"date": "2026-04-12T20:14:42Z",
"number": "1",
"summary": "Current version"
}
],
"status": "final",
"version": "1"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"product": {
"name": "chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"product_id": "chromedriver-147.0.7727.55-bp160.1.1.aarch64"
}
},
{
"category": "product_version",
"name": "chromium-147.0.7727.55-bp160.1.1.aarch64",
"product": {
"name": "chromium-147.0.7727.55-bp160.1.1.aarch64",
"product_id": "chromium-147.0.7727.55-bp160.1.1.aarch64"
}
}
],
"category": "architecture",
"name": "aarch64"
},
{
"branches": [
{
"category": "product_version",
"name": "chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"product": {
"name": "chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"product_id": "chromedriver-147.0.7727.55-bp160.1.1.ppc64le"
}
},
{
"category": "product_version",
"name": "chromium-147.0.7727.55-bp160.1.1.ppc64le",
"product": {
"name": "chromium-147.0.7727.55-bp160.1.1.ppc64le",
"product_id": "chromium-147.0.7727.55-bp160.1.1.ppc64le"
}
}
],
"category": "architecture",
"name": "ppc64le"
},
{
"branches": [
{
"category": "product_version",
"name": "chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"product": {
"name": "chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"product_id": "chromedriver-147.0.7727.55-bp160.1.1.x86_64"
}
},
{
"category": "product_version",
"name": "chromium-147.0.7727.55-bp160.1.1.x86_64",
"product": {
"name": "chromium-147.0.7727.55-bp160.1.1.x86_64",
"product_id": "chromium-147.0.7727.55-bp160.1.1.x86_64"
}
}
],
"category": "architecture",
"name": "x86_64"
},
{
"branches": [
{
"category": "product_name",
"name": "openSUSE Leap 16.0",
"product": {
"name": "openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0"
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "chromedriver-147.0.7727.55-bp160.1.1.aarch64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64"
},
"product_reference": "chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "chromedriver-147.0.7727.55-bp160.1.1.ppc64le as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le"
},
"product_reference": "chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "chromedriver-147.0.7727.55-bp160.1.1.x86_64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64"
},
"product_reference": "chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "chromium-147.0.7727.55-bp160.1.1.aarch64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64"
},
"product_reference": "chromium-147.0.7727.55-bp160.1.1.aarch64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "chromium-147.0.7727.55-bp160.1.1.ppc64le as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le"
},
"product_reference": "chromium-147.0.7727.55-bp160.1.1.ppc64le",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "chromium-147.0.7727.55-bp160.1.1.x86_64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
},
"product_reference": "chromium-147.0.7727.55-bp160.1.1.x86_64",
"relates_to_product_reference": "openSUSE Leap 16.0"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-5858",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5858"
}
],
"notes": [
{
"category": "general",
"text": "Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5858",
"url": "https://www.suse.com/security/cve/CVE-2026-5858"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5858",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5858"
},
{
"cve": "CVE-2026-5859",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5859"
}
],
"notes": [
{
"category": "general",
"text": "Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5859",
"url": "https://www.suse.com/security/cve/CVE-2026-5859"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5859",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5859"
},
{
"cve": "CVE-2026-5860",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5860"
}
],
"notes": [
{
"category": "general",
"text": "Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5860",
"url": "https://www.suse.com/security/cve/CVE-2026-5860"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5860",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5860"
},
{
"cve": "CVE-2026-5861",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5861"
}
],
"notes": [
{
"category": "general",
"text": "Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5861",
"url": "https://www.suse.com/security/cve/CVE-2026-5861"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5861",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5861"
},
{
"cve": "CVE-2026-5862",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5862"
}
],
"notes": [
{
"category": "general",
"text": "Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5862",
"url": "https://www.suse.com/security/cve/CVE-2026-5862"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5862",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5862"
},
{
"cve": "CVE-2026-5863",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5863"
}
],
"notes": [
{
"category": "general",
"text": "Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5863",
"url": "https://www.suse.com/security/cve/CVE-2026-5863"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5863",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5863"
},
{
"cve": "CVE-2026-5864",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5864"
}
],
"notes": [
{
"category": "general",
"text": "Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5864",
"url": "https://www.suse.com/security/cve/CVE-2026-5864"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5864",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5864"
},
{
"cve": "CVE-2026-5865",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5865"
}
],
"notes": [
{
"category": "general",
"text": "Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5865",
"url": "https://www.suse.com/security/cve/CVE-2026-5865"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5865",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5865"
},
{
"cve": "CVE-2026-5866",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5866"
}
],
"notes": [
{
"category": "general",
"text": "Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5866",
"url": "https://www.suse.com/security/cve/CVE-2026-5866"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5866",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5866"
},
{
"cve": "CVE-2026-5867",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5867"
}
],
"notes": [
{
"category": "general",
"text": "Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5867",
"url": "https://www.suse.com/security/cve/CVE-2026-5867"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5867",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5867"
},
{
"cve": "CVE-2026-5868",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5868"
}
],
"notes": [
{
"category": "general",
"text": "Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5868",
"url": "https://www.suse.com/security/cve/CVE-2026-5868"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5868",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5868"
},
{
"cve": "CVE-2026-5869",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5869"
}
],
"notes": [
{
"category": "general",
"text": "Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5869",
"url": "https://www.suse.com/security/cve/CVE-2026-5869"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5869",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5869"
},
{
"cve": "CVE-2026-5870",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5870"
}
],
"notes": [
{
"category": "general",
"text": "Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5870",
"url": "https://www.suse.com/security/cve/CVE-2026-5870"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5870",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5870"
},
{
"cve": "CVE-2026-5871",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5871"
}
],
"notes": [
{
"category": "general",
"text": "Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5871",
"url": "https://www.suse.com/security/cve/CVE-2026-5871"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5871",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5871"
},
{
"cve": "CVE-2026-5872",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5872"
}
],
"notes": [
{
"category": "general",
"text": "Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5872",
"url": "https://www.suse.com/security/cve/CVE-2026-5872"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5872",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5872"
},
{
"cve": "CVE-2026-5873",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5873"
}
],
"notes": [
{
"category": "general",
"text": "Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5873",
"url": "https://www.suse.com/security/cve/CVE-2026-5873"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5873",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5873"
},
{
"cve": "CVE-2026-5874",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5874"
}
],
"notes": [
{
"category": "general",
"text": "Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5874",
"url": "https://www.suse.com/security/cve/CVE-2026-5874"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5874",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5874"
},
{
"cve": "CVE-2026-5875",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5875"
}
],
"notes": [
{
"category": "general",
"text": "Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5875",
"url": "https://www.suse.com/security/cve/CVE-2026-5875"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5875",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5875"
},
{
"cve": "CVE-2026-5876",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5876"
}
],
"notes": [
{
"category": "general",
"text": "Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5876",
"url": "https://www.suse.com/security/cve/CVE-2026-5876"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5876",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5876"
},
{
"cve": "CVE-2026-5877",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5877"
}
],
"notes": [
{
"category": "general",
"text": "Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5877",
"url": "https://www.suse.com/security/cve/CVE-2026-5877"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5877",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5877"
},
{
"cve": "CVE-2026-5878",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5878"
}
],
"notes": [
{
"category": "general",
"text": "Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5878",
"url": "https://www.suse.com/security/cve/CVE-2026-5878"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5878",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5878"
},
{
"cve": "CVE-2026-5879",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5879"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5879",
"url": "https://www.suse.com/security/cve/CVE-2026-5879"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5879",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5879"
},
{
"cve": "CVE-2026-5880",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5880"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5880",
"url": "https://www.suse.com/security/cve/CVE-2026-5880"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5880",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5880"
},
{
"cve": "CVE-2026-5881",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5881"
}
],
"notes": [
{
"category": "general",
"text": "Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5881",
"url": "https://www.suse.com/security/cve/CVE-2026-5881"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5881",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5881"
},
{
"cve": "CVE-2026-5882",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5882"
}
],
"notes": [
{
"category": "general",
"text": "Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5882",
"url": "https://www.suse.com/security/cve/CVE-2026-5882"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5882",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5882"
},
{
"cve": "CVE-2026-5883",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5883"
}
],
"notes": [
{
"category": "general",
"text": "Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5883",
"url": "https://www.suse.com/security/cve/CVE-2026-5883"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5883",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5883"
},
{
"cve": "CVE-2026-5884",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5884"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient validation of untrusted input in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5884",
"url": "https://www.suse.com/security/cve/CVE-2026-5884"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5884",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5884"
},
{
"cve": "CVE-2026-5885",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5885"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5885",
"url": "https://www.suse.com/security/cve/CVE-2026-5885"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5885",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5885"
},
{
"cve": "CVE-2026-5886",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5886"
}
],
"notes": [
{
"category": "general",
"text": "Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5886",
"url": "https://www.suse.com/security/cve/CVE-2026-5886"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5886",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5886"
},
{
"cve": "CVE-2026-5887",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5887"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5887",
"url": "https://www.suse.com/security/cve/CVE-2026-5887"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5887",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5887"
},
{
"cve": "CVE-2026-5888",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5888"
}
],
"notes": [
{
"category": "general",
"text": "Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5888",
"url": "https://www.suse.com/security/cve/CVE-2026-5888"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5888",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5888"
},
{
"cve": "CVE-2026-5889",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5889"
}
],
"notes": [
{
"category": "general",
"text": "Cryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an attacker to read potentially sensitive information from encrypted PDFs via a brute-force attack. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5889",
"url": "https://www.suse.com/security/cve/CVE-2026-5889"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5889",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5889"
},
{
"cve": "CVE-2026-5890",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5890"
}
],
"notes": [
{
"category": "general",
"text": "Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5890",
"url": "https://www.suse.com/security/cve/CVE-2026-5890"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5890",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5890"
},
{
"cve": "CVE-2026-5891",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5891"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5891",
"url": "https://www.suse.com/security/cve/CVE-2026-5891"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5891",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5891"
},
{
"cve": "CVE-2026-5892",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5892"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to install a PWA without user consent via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5892",
"url": "https://www.suse.com/security/cve/CVE-2026-5892"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5892",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5892"
},
{
"cve": "CVE-2026-5893",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5893"
}
],
"notes": [
{
"category": "general",
"text": "Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5893",
"url": "https://www.suse.com/security/cve/CVE-2026-5893"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5893",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5893"
},
{
"cve": "CVE-2026-5894",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5894"
}
],
"notes": [
{
"category": "general",
"text": "Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5894",
"url": "https://www.suse.com/security/cve/CVE-2026-5894"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5894",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5894"
},
{
"cve": "CVE-2026-5895",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5895"
}
],
"notes": [
{
"category": "general",
"text": "Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5895",
"url": "https://www.suse.com/security/cve/CVE-2026-5895"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5895",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5895"
},
{
"cve": "CVE-2026-5896",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5896"
}
],
"notes": [
{
"category": "general",
"text": "Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5896",
"url": "https://www.suse.com/security/cve/CVE-2026-5896"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5896",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5896"
},
{
"cve": "CVE-2026-5897",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5897"
}
],
"notes": [
{
"category": "general",
"text": "Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5897",
"url": "https://www.suse.com/security/cve/CVE-2026-5897"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5897",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5897"
},
{
"cve": "CVE-2026-5898",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5898"
}
],
"notes": [
{
"category": "general",
"text": "Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5898",
"url": "https://www.suse.com/security/cve/CVE-2026-5898"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5898",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5898"
},
{
"cve": "CVE-2026-5899",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5899"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5899",
"url": "https://www.suse.com/security/cve/CVE-2026-5899"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5899",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5899"
},
{
"cve": "CVE-2026-5900",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5900"
}
],
"notes": [
{
"category": "general",
"text": "Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5900",
"url": "https://www.suse.com/security/cve/CVE-2026-5900"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5900",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5900"
},
{
"cve": "CVE-2026-5901",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5901"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Chrome Extension. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5901",
"url": "https://www.suse.com/security/cve/CVE-2026-5901"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5901",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5901"
},
{
"cve": "CVE-2026-5902",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5902"
}
],
"notes": [
{
"category": "general",
"text": "Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5902",
"url": "https://www.suse.com/security/cve/CVE-2026-5902"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5902",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5902"
},
{
"cve": "CVE-2026-5903",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5903"
}
],
"notes": [
{
"category": "general",
"text": "Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5903",
"url": "https://www.suse.com/security/cve/CVE-2026-5903"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5903",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5903"
},
{
"cve": "CVE-2026-5904",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5904"
}
],
"notes": [
{
"category": "general",
"text": "Determined a bug and not a vulnerability",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5904",
"url": "https://www.suse.com/security/cve/CVE-2026-5904"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5904",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5904"
},
{
"cve": "CVE-2026-5905",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5905"
}
],
"notes": [
{
"category": "general",
"text": "Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5905",
"url": "https://www.suse.com/security/cve/CVE-2026-5905"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5905",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5905"
},
{
"cve": "CVE-2026-5906",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5906"
}
],
"notes": [
{
"category": "general",
"text": "Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5906",
"url": "https://www.suse.com/security/cve/CVE-2026-5906"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5906",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5906"
},
{
"cve": "CVE-2026-5907",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5907"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5907",
"url": "https://www.suse.com/security/cve/CVE-2026-5907"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5907",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5907"
},
{
"cve": "CVE-2026-5908",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5908"
}
],
"notes": [
{
"category": "general",
"text": "Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5908",
"url": "https://www.suse.com/security/cve/CVE-2026-5908"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5908",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5908"
},
{
"cve": "CVE-2026-5909",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5909"
}
],
"notes": [
{
"category": "general",
"text": "Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5909",
"url": "https://www.suse.com/security/cve/CVE-2026-5909"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5909",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5909"
},
{
"cve": "CVE-2026-5910",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5910"
}
],
"notes": [
{
"category": "general",
"text": "Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5910",
"url": "https://www.suse.com/security/cve/CVE-2026-5910"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5910",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5910"
},
{
"cve": "CVE-2026-5911",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5911"
}
],
"notes": [
{
"category": "general",
"text": "Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5911",
"url": "https://www.suse.com/security/cve/CVE-2026-5911"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5911",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5911"
},
{
"cve": "CVE-2026-5912",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5912"
}
],
"notes": [
{
"category": "general",
"text": "Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5912",
"url": "https://www.suse.com/security/cve/CVE-2026-5912"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5912",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5912"
},
{
"cve": "CVE-2026-5913",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5913"
}
],
"notes": [
{
"category": "general",
"text": "Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5913",
"url": "https://www.suse.com/security/cve/CVE-2026-5913"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5913",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5913"
},
{
"cve": "CVE-2026-5914",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5914"
}
],
"notes": [
{
"category": "general",
"text": "Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5914",
"url": "https://www.suse.com/security/cve/CVE-2026-5914"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5914",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5914"
},
{
"cve": "CVE-2026-5915",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5915"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5915",
"url": "https://www.suse.com/security/cve/CVE-2026-5915"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5915",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5915"
},
{
"cve": "CVE-2026-5918",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5918"
}
],
"notes": [
{
"category": "general",
"text": "Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5918",
"url": "https://www.suse.com/security/cve/CVE-2026-5918"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5918",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5918"
},
{
"cve": "CVE-2026-5919",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-5919"
}
],
"notes": [
{
"category": "general",
"text": "Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-5919",
"url": "https://www.suse.com/security/cve/CVE-2026-5919"
},
{
"category": "external",
"summary": "SUSE Bug 1261758 for CVE-2026-5919",
"url": "https://bugzilla.suse.com/1261758"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromedriver-147.0.7727.55-bp160.1.1.x86_64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.aarch64",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:chromium-147.0.7727.55-bp160.1.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-04-12T20:14:42Z",
"details": "critical"
}
],
"title": "CVE-2026-5919"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…