This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 144.0.7559.132 (boo#1257650)
* CVE-2026-1861: Heap buffer overflow in libvpx in Google Chrome
prior to 144.0.7559.132 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page.
* CVE-2026-1862: Type Confusion in V8 in Google Chrome prior to
144.0.7559.132 allowed a remote attacker to potentially exploit
heap corruption via a crafted HTML page.
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-112=1
- openSUSE Leap 16.0:
chromedriver-144.0.7559.132-bp160.1.1
chromium-144.0.7559.132-bp160.1.1
* bsc#1257650
References:
* https://www.suse.com/security/cve/CVE-2026-1861.html
* https://www.suse.com/security/cve/CVE-2026-1862.html
Get the latest Linux and open source security news straight to your inbox.