This update for chromium, gn fixes the following issues:
Changes in chromium:
- Chromium 135.0.7049.52 (stable release 2025-04-01) (boo#1240555)
* CVE-2025-3066: Use after free in Navigations
* CVE-2025-3067: Inappropriate implementation in Custom Tabs
* CVE-2025-3068: Inappropriate implementation in Intents
* CVE-2025-3069: Inappropriate implementation in Extensions
* CVE-2025-3070: Insufficient validation of untrusted input in Extensions
* CVE-2025-3071: Inappropriate implementation in Navigations
* CVE-2025-3072: Inappropriate implementation in Custom Tabs
* CVE-2025-3073: Inappropriate implementation in Autofill
* CVE-2025-3074: Inappropriate implementation in Downloads
Changes in gn:
- Update to version 0.20250306:
* Remove deps from rust executable to module's pcm files
* Update test for rust executable deps
* Add toolchain for cxx modules in TestWithScope
* Apply the latest clang-format
*...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP6:
zypper in -t patch openSUSE-2025-115=1
- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):
gn-0.20250306-bp156.2.6.1
gn-debuginfo-0.20250306-bp156.2.6.1
gn-debugsource-0.20250306-bp156.2.6.1
- openSUSE Backports SLE-15-SP6 (aarch64 x86_64):
chromedriver-135.0.7049.52-bp156.2.102.2
chromium-135.0.7049.52-bp156.2.102.2
https://www.suse.com/security/cve/CVE-2025-3066.html
https://www.suse.com/security/cve/CVE-2025-3067.html
https://www.suse.com/security/cve/CVE-2025-3068.html
https://www.suse.com/security/cve/CVE-2025-3069.html
https://www.suse.com/security/cve/CVE-2025-3070.html
https://www.suse.com/security/cve/CVE-2025-3071.html
https://www.suse.com/security/cve/CVE-2025-3072.html
https://www.suse.com/security/cve/CVE-2025-3073.html
https://www.suse.com/security/cve/CVE-2025-3074.html
https://bugzilla.suse.com/1240555
Get the latest Linux and open source security news straight to your inbox.