Explore top 10 tips to secure your open-source projects now. Read More
×High CVE-2025-1920: Type Confusion in V8. High CVE-2025-2135: Type Confusion in V8. High CVE-2025-24201: Out of bounds write in GPU on Mac. Medium CVE-2025-2136: Use after free in Inspector. Medium CVE-2025-2137: Out of bounds read in V8. . MGASA-2025-0104 - Updated chromium-browser-stable packages fix security vulnerabilities Publication date: 19 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0104.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-1920, CVE-2025-2135, CVE-2025-2136, CVE-2025-2137 High CVE-2025-1920: Type Confusion in V8. High CVE-2025-2135: Type Confusion in V8. High CVE-2025-24201: Out of bounds write in GPU on Mac. Medium CVE-2025-2136: Use after free in Inspector. Medium CVE-2025-2137: Out of bounds read in V8. References: - https://bugs.mageia.org/show_bug.cgi?id=34099 - https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_10.html - https://www.cve.org/CVERecord?id=CVE-2025-1920 - https://www.cve.org/CVERecord?id=CVE-2025-2135 - https://www.cve.org/CVERecord?id=CVE-2025-2136 - https://www.cve.org/CVERecord?id=CVE-2025-2137 SRPMS: - 9/tainted/chromium-browser-stable-134.0.6998.88-1.mga9.tainted . High and medium issues fixed in chromium-browser-stable for Mageia, affecting versions with critical type confusion vulnerabilities.. confusion, cve-2025-1920, cve-2025-2135, cve-2025-24. . LinuxSecurity.com Team
Use after free in Downloads. (CVE-2024-6988) Use after free in Loader. (CVE-2024-6989) Use after free in Dawn. (CVE-2024-6991) Heap buffer overflow in Layout. (CVE-2024-6994) Inappropriate implementation in Fullscreen. (CVE-2024-6995) . MGASA-2024-0321 - Updated chromium-browser-stable packages fix security vulnerabilities Publication date: 04 Oct 2024 URL: https://advisories.mageia.org/MGASA-2024-0321.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-6988, CVE-2024-6989, CVE-2024-6991, CVE-2024-6994, CVE-2024-6995, CVE-2024-6996, CVE-2024-6997, CVE-2024-6998, CVE-2024-6999, CVE-2024-7000, CVE-2024-7001, CVE-2024-7003, CVE-2024-7004, CVE-2024-7005 Use after free in Downloads. (CVE-2024-6988) Use after free in Loader. (CVE-2024-6989) Use after free in Dawn. (CVE-2024-6991) Heap buffer overflow in Layout. (CVE-2024-6994) Inappropriate implementation in Fullscreen. (CVE-2024-6995) Race in Frames. (CVE-2024-6996) Use after free in Tabs. (CVE-2024-6997) Use after free in User Education. (CVE-2024-6998) Inappropriate implementation in FedCM. (CVE-2024-6999) Use after free in CSS. (CVE-2024-7000) Inappropriate implementation in HTML. (CVE-2024-7001) Inappropriate implementation in FedCM. (CVE-2024-7003) Insufficient validation of untrusted input in Safe Browsing. (CVE-2024-7004) Insufficient validation of untrusted input in Safe Browsing. (CVE-2024-7005) Uninitialized Use in Dawn. (CVE-2024-6990) Out of bounds read in WebTransport. (CVE-2024-7255) Insufficient data validation in Dawn. (CVE-2024-7256) Out of bounds memory access in ANGLE. (CVE-2024-7532) Use after free in Sharing. (CVE-2024-7533) Type Confusion in V8. (CVE-2024-7550) Heap buffer overflow in Layout. (CVE-2024-7534) Inappropriate implementation in V8. (CVE-2024-7535) Use after free in WebAudio. (CVE-2024-7536) Use after free in Passwords. (CVE-2024-7964) Inappropriate implementation in V8. (CVE-2024-7965) Out of bounds memory access in Skia. (CVE-2024-7966) Heap bufferoverflow in Fonts. (CVE-2024-7967) Use after free in Autofill. (CVE-2024-7968) Type confusion in V8. (CVE-2024-7971) Inappropriate implementation in V8. (CVE-2024-7972) Heap buffer overflow in PDFium. (CVE-2024-7973) Insufficient data validation in V8 API. (CVE-2024-7974) Inappropriate implementation in Permissions. (CVE-2024-7975) Inappropriate implementation in FedCM. (CVE-2024-7976) Insufficient data validation in Installer. (CVE-2024-7977) Insufficient policy enforcement in Data Transfer. (CVE-2024-7978) Insufficient data validation in Installer. (CVE-2024-7979) Insufficient data validation in Installer. (CVE-2024-7980) Inappropriate implementation in Views. (CVE-2024-7981) Inappropriate implementation in WebApp Installs. (CVE-2024-8033) Inappropriate implementation in Custom Tabs. (CVE-2024-8034) Inappropriate implementation in Extensions. (CVE-2024-8035) Type Confusion in V8. (CVE-2024-7969) Heap buffer overflow in Skia. (CVE-2024-8193) Type Confusion in V8. (CVE-2024-8194) Heap buffer overflow in Skia. (CVE-2024-8198) Use after free in WebAudio. (CVE-2024-8362) Out of bounds write in V8. (CVE-2024-7970) Heap buffer overflow in Skia. (CVE-2024-8636) Use after free in Media Router. (CVE-2024-8637) Type Confusion in V8. (CVE-2024-8638) Use after free in Autofill. (CVE-2024-8639) Type Confusion in V8. (CVE-2024-8904) Inappropriate implementation in V8. (CVE-2024-8905) Incorrect security UI in Downloads. (CVE-2024-8906) Insufficient data validation in Omnibox. (CVE-2024-8907) Inappropriate implementation in Autofill. (CVE-2024-8908) Inappropriate implementation in UI. (CVE-2024-8909) Inappropriate implementation in V8. (CVE-2024-9121) Type Confusion in V8. (CVE-2024-9122) Integer overflow in Skia. (CVE-2024-9123) References: - https://bugs.mageia.org/show_bug.cgi?id=33443 - https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_24.html - https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html -https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_10.html - https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop.html - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_28.html - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_13.html - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html - https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_30.html - https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html - https://www.cve.org/CVERecord?id=CVE-2024-6988 - https://www.cve.org/CVERecord?id=CVE-2024-6989 - https://www.cve.org/CVERecord?id=CVE-2024-6991 - https://www.cve.org/CVERecord?id=CVE-2024-6994 - https://www.cve.org/CVERecord?id=CVE-2024-6995 - https://www.cve.org/CVERecord?id=CVE-2024-6996 - https://www.cve.org/CVERecord?id=CVE-2024-6997 - https://www.cve.org/CVERecord?id=CVE-2024-6998 - https://www.cve.org/CVERecord?id=CVE-2024-6999 - https://www.cve.org/CVERecord?id=CVE-2024-7000 - https://www.cve.org/CVERecord?id=CVE-2024-7001 - https://www.cve.org/CVERecord?id=CVE-2024-7003 - https://www.cve.org/CVERecord?id=CVE-2024-7004 - https://www.cve.org/CVERecord?id=CVE-2024-7005 SRPMS: - 9/tainted/chromium-browser-stable-128.0.6613.137-1.mga9.tainted . MGASA-2024-0322 addresses vulnerabilities in firefox for Mageia 9, ensuring user data remains protected with vital patches.. chromium-browser, Mageia, security advisory, updates, heap buffer overflow. . Severity: Critical. LinuxSecurity.com Team
Update to 123.0.6312.58 * High CVE-2024-2625: Object lifecycle issue in V8 * Medium CVE-2024-2626: Out of bounds read in Swiftshader * Medium CVE-2024-2627: Use after free in Canvas * Medium CVE-2024-2628: Inappropriate implementation in Downloads. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-f9eb1130c8 2024-03-25 00:14:43.995271 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 40 Version : 123.0.6312.58 Release : 1.fc40 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 123.0.6312.58 * High CVE-2024-2625: Object lifecycle issue in V8 * Medium CVE-2024-2626: Out of bounds read in Swiftshader * Medium CVE-2024-2627: Use after free in Canvas * Medium CVE-2024-2628: Inappropriate implementation in Downloads * Medium CVE-2024-2629: Incorrect security UI in iOS * Medium CVE-2024-2630: Inappropriate implementation in iOS * Low CVE-2024-2631: Inappropriate implementation in iOS -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 20 2024 Than Ngo - 123.0.6312.58-1 - update to 123.0.6312.58 * High CVE-2024-2625: Object lifecycle issue in V8 * Medium CVE-2024-2626: Out of bounds read in Swiftshader * Medium CVE-2024-2627: Use after free in Canvas * Medium CVE-2024-2628: Inappropriate implementation in Downloads * Medium CVE-2024-2629: Incorrect security UI in iOS * Medium CVE-2024-2630: Inappropriate implementation in iOS * Low CVE-2024-2631: Inappropriate implementation in iOS * Fri Mar 15 2024 Than Ngo - 123.0.6312.46-1 - update to123.0.6312.46 * Wed Mar 13 2024 Than Ngo - 122.0.6261.128-1 - upstream security release 122.0.6261.128 * High CVE-2024-2400: Use after free in Performance Manager * Mon Mar 11 2024 Than Ngo - 122.0.6261.111-2 - enable ppc64le build -------------------------------------------------------------------------------- References: [ 1 ] Bug #2270389 - CVE-2024-2626 CVE-2024-2627 CVE-2024-2628 CVE-2024-2629 CVE-2024-2630 CVE-2024-2631 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2270389 [ 2 ] Bug #2270393 - CVE-2024-2625 chromium: chromium-browser: Object lifecycle issue in V8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2270393 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f9eb1130c8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 123.0.6312.58 * High CVE-2024-2625: Object lifecycle issue in V8 * Medium CVE-2024-2626: Out of bounds read in Swiftshader * Medium CVE-2024-2627: Use after free in Canvas * Medium CVE-2024-2628: Inappropriate implementation in Downloads. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ec79868e3b 2024-03-22 01:15:00.283884 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 39 Version : 123.0.6312.58 Release : 1.fc39 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 123.0.6312.58 * High CVE-2024-2625: Object lifecycle issue in V8 * Medium CVE-2024-2626: Out of bounds read in Swiftshader * Medium CVE-2024-2627: Use after free in Canvas * Medium CVE-2024-2628: Inappropriate implementation in Downloads * Medium CVE-2024-2629: Incorrect security UI in iOS * Medium CVE-2024-2630: Inappropriate implementation in iOS * Low CVE-2024-2631: Inappropriate implementation in iOS -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 20 2024 Than Ngo - 123.0.6312.58-1 - update to 123.0.6312.58 * High CVE-2024-2625: Object lifecycle issue in V8 * Medium CVE-2024-2626: Out of bounds read in Swiftshader * Medium CVE-2024-2627: Use after free in Canvas * Medium CVE-2024-2628: Inappropriate implementation in Downloads * Medium CVE-2024-2629: Incorrect security UI in iOS * Medium CVE-2024-2630: Inappropriate implementation in iOS * Low CVE-2024-2631: Inappropriate implementation in iOS * Fri Mar 15 2024 Than Ngo - 123.0.6312.46-1 - update to123.0.6312.46 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2270389 - CVE-2024-2626 CVE-2024-2627 CVE-2024-2628 CVE-2024-2629 CVE-2024-2630 CVE-2024-2631 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2270389 [ 2 ] Bug #2270393 - CVE-2024-2625 chromium: chromium-browser: Object lifecycle issue in V8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2270393 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ec79868e3b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The chromium-browser-stable package has been updated to the 120.0.6099.216release. Together with 120.0.6099.199, 7 vulnerabilities are fixed; some of them are listed below: References: . MGASA-2024-0011 - Updated chromium-browser-stable packages fix security vulnerabilities Publication date: 14 Jan 2024 URL: https://advisories.mageia.org/MGASA-2024-0011.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-0333, CVE-2024-0222, CVE-2024-0223, CVE-2024-0224, CVE-2024-0225 The chromium-browser-stable package has been updated to the 120.0.6099.216release. Together with 120.0.6099.199, 7 vulnerabilities are fixed; some of them are listed below: References: - https://bugs.mageia.org/show_bug.cgi?id=32705 - https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_9.htmll?m=1 - https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop.html - https://www.cve.org/CVERecord?id=CVE-2024-0333 - https://www.cve.org/CVERecord?id=CVE-2024-0222 - https://www.cve.org/CVERecord?id=CVE-2024-0223 - https://www.cve.org/CVERecord?id=CVE-2024-0224 - https://www.cve.org/CVERecord?id=CVE-2024-0225 SRPMS: - 9/tainted/chromium-browser-stable-120.0.6099.216-1.mga9.tainted . Mageia enhances the chromium-browser-stable package to address vital security vulnerabilities. Ensure your safety by applying the newest updates.. Chromium Browser Update,Vulnerabilities Fixed,Mageia Security Advisory,Security Updates 2024. . LinuxSecurity.com Team
The chromium-browser-stable package has been updated to the 108.0.5359.124 release, fixing 8 vulnerabilities. Some of the security fixes are ... . MGASA-2022-0480 - Updated chromium-browser-stable packages fix security vulnerability Publication date: 24 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0480.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-4436, CVE-2022-4437, CVE-2022-4438, CVE-2022-4439, CVE-2022-4440 The chromium-browser-stable package has been updated to the 108.0.5359.124 release, fixing 8 vulnerabilities. Some of the security fixes are ... High CVE-2022-4436: Use after free in Blink Media. Reported by Anonymous on 2022-11-15 High CVE-2022-4437: Use after free in Mojo IPC. Reported by koocola(@alo_cook) and Guang Gong of 360 Vulnerability Research Institute on 2022-11-30 High CVE-2022-4438: Use after free in Blink Frames. Reported by Anonymous on 2022-11-07 High CVE-2022-4439: Use after free in Aura. Reported by Anonymous on 2022-11-22 Medium CVE-2022-4440: Use after free in Profiles. Reported by Anonymous on 2022-11-09 References: - https://bugs.mageia.org/show_bug.cgi?id=31288 - https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop_13.html - https://www.cve.org/CVERecord?id=CVE-2022-4436 - https://www.cve.org/CVERecord?id=CVE-2022-4437 - https://www.cve.org/CVERecord?id=CVE-2022-4438 - https://www.cve.org/CVERecord?id=CVE-2022-4439 - https://www.cve.org/CVERecord?id=CVE-2022-4440 SRPMS: - 8/core/chromium-browser-stable-108.0.5359.124-1.mga8 . Latest chromium-browser-stable updates resolve critical vulnerabilities with numerous enhancements and patches. Discover more information.. Chromium Browser, Mageia Update, Security Advisory, Software Fixes. . LinuxSecurity.com Team
CVE-2021-4052: Use after free in web apps. CVE-2021-4053: Use after free in UI. CVE-2021-4079: Out of bounds write in WebRTC. CVE-2021-4054: Incorrect security UI in autofill. CVE-2021-4078: Type confusion in V8. . MGASA-2021-0555 - Updated chromium-browser-stable packages fix security vulnerability Publication date: 10 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0555.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-4052, CVE-2021-4053, CVE-2021-4079, CVE-2021-4054, CVE-2021-4078, CVE-2021-4055, CVE-2021-4056, CVE-2021-4057, CVE-2021-4058, CVE-2021-4059, CVE-2021-4061, CVE-2021-4062, CVE-2021-4063, CVE-2021-4064, CVE-2021-4065, CVE-2021-4066, CVE-2021-4067, CVE-2021-4068 CVE-2021-4052: Use after free in web apps. CVE-2021-4053: Use after free in UI. CVE-2021-4079: Out of bounds write in WebRTC. CVE-2021-4054: Incorrect security UI in autofill. CVE-2021-4078: Type confusion in V8. CVE-2021-4055: Heap buffer overflow in extensions. CVE-2021-4056: Type Confusion in loader. CVE-2021-4057: Use after free in file API. CVE-2021-4058: Heap buffer overflow in ANGLE. CVE-2021-4059: Insufficient data validation in loader. CVE-2021-4061: Type Confusion in V8. CVE-2021-4062: Heap buffer overflow in BFCache. CVE-2021-4063: Use after free in developer tools. CVE-2021-4064: Use after free in screen capture. CVE-2021-4065: Use after free in autofill. CVE-2021-4066: Integer underflow in ANGLE. CVE-2021-4067: Use after free in window manager. CVE-2021-4068: Insufficient validation of untrusted input in new tab page. References: - https://bugs.mageia.org/show_bug.cgi?id=29744 - https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html - https://www.cve.org/CVERecord?id=CVE-2021-4052 - https://www.cve.org/CVERecord?id=CVE-2021-4053 - https://www.cve.org/CVERecord?id=CVE-2021-4079 - https://www.cve.org/CVERecord?id=CVE-2021-4054 - https://www.cve.org/CVERecord?id=CVE-2021-4078 -https://www.cve.org/CVERecord?id=CVE-2021-4055 - https://www.cve.org/CVERecord?id=CVE-2021-4056 - https://www.cve.org/CVERecord?id=CVE-2021-4057 - https://www.cve.org/CVERecord?id=CVE-2021-4058 - https://www.cve.org/CVERecord?id=CVE-2021-4059 - https://www.cve.org/CVERecord?id=CVE-2021-4061 - https://www.cve.org/CVERecord?id=CVE-2021-4062 - https://www.cve.org/CVERecord?id=CVE-2021-4063 - https://www.cve.org/CVERecord?id=CVE-2021-4064 - https://www.cve.org/CVERecord?id=CVE-2021-4065 - https://www.cve.org/CVERecord?id=CVE-2021-4066 - https://www.cve.org/CVERecord?id=CVE-2021-4067 - https://www.cve.org/CVERecord?id=CVE-2021-4068 SRPMS: - 8/core/chromium-browser-stable-96.0.4664.93-1.mga8 . MGASA-2021-0556 upgrades firefox to address critical vulnerabilities impacting user privacy and performance.. mageia security update, chromium browser patch, browser security fix. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities have been discovered in the chromium web browser. CVE-2021-30506 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4917-1
Get the latest Linux and open source security news straight to your inbox.