Bug 1267911 (CVE-2026-11628, CVE-2026-11629, CVE-2026-11630, CVE-2026-11631, CVE-2026-11632, CVE-2026-11633, CVE-2026-11634, CVE-2026-11635, CVE-2026-11636, CVE-2026-11637, CVE-2026-11638, CVE-2026-11639, CVE-2026-11640, CVE-2026-11641, CVE-2026-11642, CVE-2026-11643, CVE-2026-11644, CVE-2026-11645, CVE-2026-11646, CVE-2026-11647, CVE-2026-11648, CVE-2026-11649, CVE-2026-11650, CVE-2026-11651, CVE-2026-11652, CVE-2026-11653, CVE-2026-11654, CVE-2026-11655, CVE-2026-11656, CVE-2026-11657, CVE-2026-11658, CVE-2026-11659, CVE-2026-11660, CVE-2026-11661, CVE-2026-11662, CVE-2026-11663, CVE-2026-11664, CVE-2026-11665, CVE-2026-11666, CVE-2026-11667, CVE-2026-11668, CVE-2026-11669, CVE-2026-11670, CVE-2026-11671, CVE-2026-11672, CVE-2026-11673, CVE-2026-11674, CVE-2026-11675, CVE-2026-11676, CVE-2026-11677, CVE-2026-11678, CVE-2026-11679, CVE-2026-11680, CVE-2026-11681, CVE-2026-11682, CVE-2026-11683, CVE-2026-11684, CVE-2026-11685, CVE-2026-11686, CVE-2026-11687, CVE-2026-11688, CVE-2026-11689, CVE-2026-11690, CVE-2026-11691, CVE-2026-11692, CVE-2026-11693, CVE-2026-11694, CVE-2026-11695, CVE-2026-11696, CVE-2026-11697, CVE-2026-11698, CVE-2026-11699, CVE-2026-11700, CVE-2026-11701) - VUL-0: chromium: security fixes in 149.0.7827.102
Summary: VUL-0: chromium: security fixes in 149.0.7827.102
Status: RESOLVED FIXED
Alias: CVE-2026-11628, CVE-2026-11629, CVE-2026-11630, CVE-2026-11631, CVE-2026-11632, CVE-2026-11633, CVE-2026-11634, CVE-2026-11635, CVE-2026-11636, CVE-2026-11637, CVE-2026-11638, CVE-2026-11639, CVE-2026-11640, CVE-2026-11641, CVE-2026-11642, CVE-2026-11643, CVE-2026-11644, CVE-2026-11645, CVE-2026-11646, CVE-2026-11647, CVE-2026-11648, CVE-2026-11649, CVE-2026-11650, CVE-2026-11651, CVE-2026-11652, CVE-2026-11653, CVE-2026-11654, CVE-2026-11655, CVE-2026-11656, CVE-2026-11657, CVE-2026-11658, CVE-2026-11659, CVE-2026-11660, CVE-2026-11661, CVE-2026-11662, CVE-2026-11663, CVE-2026-11664, CVE-2026-11665, CVE-2026-11666, CVE-2026-11667, CVE-2026-11668, CVE-2026-11669, CVE-2026-11670, CVE-2026-11671, CVE-2026-11672, CVE-2026-11673, CVE-2026-11674, CVE-2026-11675, CVE-2026-11676, CVE-2026-11677, CVE-2026-11678, CVE-2026-11679, CVE-2026-11680, CVE-2026-11681, CVE-2026-11682, CVE-2026-11683, CVE-2026-11684, CVE-2026-11685, CVE-2026-11686, CVE-2026-11687, CVE-2026-11688, CVE-2026-11689, CVE-2026-11690, CVE-2026-11691, CVE-2026-11692, CVE-2026-11693, CVE-2026-11694, CVE-2026-11695, CVE-2026-11696, CVE-2026-11697, CVE-2026-11698, CVE-2026-11699, CVE-2026-11700, CVE-2026-11701
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 16.1
Hardware: Other Other
: P2 - High : Major (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2026-06-09 05:31 UTC by Andreas Stieger
Modified: 2026-06-12 17:54 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2026-06-09 05:31:41 UTC
Fixed in 49.0.7827.102...
Google is aware that an exploit for CVE-2026-11645 exists in the wild.
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html

CVE-2026-11628: Use after free in Ozone
CVE-2026-11629: Use after free in Ozone
CVE-2026-11630: Use after free in File Input
CVE-2026-11631: Use after free in Aura
CVE-2026-11632: Use after free in TabStrip
CVE-2026-11633: Use after free in Bluetooth
CVE-2026-11634: Use after free in Gamepad
CVE-2026-11635: Use after free in Bluetooth
CVE-2026-11636: Use after free in Autofill
CVE-2026-11637: Use after free in Views
CVE-2026-11638: Use after free in Printing
CVE-2026-11639: Use after free in Compositing
CVE-2026-11640: Integer overflow in libyuv
CVE-2026-11641: Use after free in Bluetooth
CVE-2026-11642: Use after free in Web Apps
CVE-2026-11643: Use after free in Proxy
CVE-2026-11644: Use after free in Views
CVE-2026-11645: Out of bounds memory access in V8
CVE-2026-11646: Use after free in ViewTransitions
CVE-2026-11647: Use after free in Printing
CVE-2026-11648: Use after free in FullScreen
CVE-2026-11649: Use after free in V8
CVE-2026-11650: Use after free in V8
CVE-2026-11651: Use after free in Network
CVE-2026-11652: Use after free in Extensions
CVE-2026-11653: Insufficient validation of untrusted input in Extensions
CVE-2026-11654: Use after free in CameraCapture
CVE-2026-11655: Integer overflow in Media
CVE-2026-11656: Use after free in ServiceWorker
CVE-2026-11657: Use after free in Payments
CVE-2026-11658: Insufficient validation of untrusted input in Extensions
CVE-2026-11659: Insufficient validation of untrusted input in UI
CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page
CVE-2026-11661: Use after free in Views
CVE-2026-11662: Type Confusion in Bindings
CVE-2026-11663: Use after free in Skia
CVE-2026-11664: Use after free in Payments
CVE-2026-11665: Out of bounds read in Dawn
CVE-2026-11666: Insufficient validation of untrusted input in Input
CVE-2026-11667: Out of bounds read in WebRTC
CVE-2026-11668: Uninitialized Use in Codecs
CVE-2026-11669: Integer overflow in Media
CVE-2026-11670: Use after free in PDF
CVE-2026-11671: Use after free in Navigation
CVE-2026-11672: Out of bounds write in GPU
CVE-2026-11673: Use after free in InterestGroups
CVE-2026-11674: Use after free in Guest View
CVE-2026-11675: Insufficient validation of untrusted input in Skia
CVE-2026-11676: Insufficient validation of untrusted input in Dawn
CVE-2026-11677: Race in Network
CVE-2026-11678: Integer overflow in libyuv
CVE-2026-11679: Use after free in Codecs
CVE-2026-11680: Use after free in Media
CVE-2026-11681: Use after free in Ozone
CVE-2026-11682: Insufficient validation of untrusted input in Views
CVE-2026-11683: Use after free in WebCodecs
CVE-2026-11684: Insufficient policy enforcement in Network
CVE-2026-11685: Insufficient data validation in MediaCapture
CVE-2026-11686: Insufficient validation of untrusted input in Dawn
CVE-2026-11687: Use after free in Dawn
CVE-2026-11688: Object lifecycle issue in SVG
CVE-2026-11689: Insufficient validation of untrusted input in Passwords
CVE-2026-11690: Out of bounds read and write in Media
CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page
CVE-2026-11692: Use after free in Read Anything
CVE-2026-11693: Inappropriate implementation in Plugins
CVE-2026-11694: Use after free in ServiceWorker
CVE-2026-11695: Inappropriate implementation in Passwords
CVE-2026-11696: Uninitialized Use in Video
CVE-2026-11697: Insufficient validation of untrusted input in UI
CVE-2026-11698: Use after free in Bluetooth
CVE-2026-11699: Use after free in Bluetooth
CVE-2026-11700: Use after free in Tracing
CVE-2026-11701: Insufficient validation of untrusted input in Guest View


https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html
Comment 2 OBSbugzilla Bot 2026-06-09 06:35:02 UTC
This is an autogenerated message for OBS integration:
This bug (1267911) was mentioned in
https://build.opensuse.org/request/show/1358111 Factory / chromium
https://build.opensuse.org/request/show/1358112 Backports:SLE-15-SP7 / chromium
Comment 3 Andreas Stieger 2026-06-12 09:25:54 UTC
done-ish