{"schema_version":"1.7.3","id":"openSUSE-SU-2022:10005-1","published":"2022-06-03T09:26:22Z","modified":"2026-02-04T03:54:49.256844Z","related":["CVE-2022-1853","CVE-2022-1854","CVE-2022-1855","CVE-2022-1856","CVE-2022-1857","CVE-2022-1858","CVE-2022-1859","CVE-2022-1860","CVE-2022-1861","CVE-2022-1862","CVE-2022-1863","CVE-2022-1864","CVE-2022-1865","CVE-2022-1866","CVE-2022-1867","CVE-2022-1868","CVE-2022-1869","CVE-2022-1870","CVE-2022-1871","CVE-2022-1872","CVE-2022-1873","CVE-2022-1874","CVE-2022-1875","CVE-2022-1876"],"upstream":["CVE-2022-1853","CVE-2022-1854","CVE-2022-1855","CVE-2022-1856","CVE-2022-1857","CVE-2022-1858","CVE-2022-1859","CVE-2022-1860","CVE-2022-1861","CVE-2022-1862","CVE-2022-1863","CVE-2022-1864","CVE-2022-1865","CVE-2022-1866","CVE-2022-1867","CVE-2022-1868","CVE-2022-1869","CVE-2022-1870","CVE-2022-1871","CVE-2022-1872","CVE-2022-1873","CVE-2022-1874","CVE-2022-1875","CVE-2022-1876"],"summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChromium 102.0.5001.61 (boo#1199893)\n\n* CVE-2022-1853: Use after free in Indexed DB\n* CVE-2022-1854: Use after free in ANGLE\n* CVE-2022-1855: Use after free in Messaging\n* CVE-2022-1856: Use after free in User Education\n* CVE-2022-1857: Insufficient policy enforcement in File System API\n* CVE-2022-1858: Out of bounds read in DevTools\n* CVE-2022-1859: Use after free in Performance Manager\n* CVE-2022-1860: Use after free in UI Foundations\n* CVE-2022-1861: Use after free in Sharing\n* CVE-2022-1862: Inappropriate implementation in Extensions\n* CVE-2022-1863: Use after free in Tab Groups\n* CVE-2022-1864: Use after free in WebApp Installs\n* CVE-2022-1865: Use after free in Bookmarks\n* CVE-2022-1866: Use after free in Tablet Mode\n* CVE-2022-1867: Insufficient validation of untrusted input in Data Transfer\n* CVE-2022-1868: Inappropriate implementation in Extensions API\n* CVE-2022-1869: Type Confusion in V8\n* CVE-2022-1870: Use after free in App Service\n* CVE-2022-1871: Insufficient policy enforcement in File System API\n* CVE-2022-1872: Insufficient policy enforcement in Extensions API\n* CVE-2022-1873: Insufficient policy enforcement in COOP\n* CVE-2022-1874: Insufficient policy enforcement in Safe Browsing\n* CVE-2022-1875: Inappropriate implementation in PDF\n* CVE-2022-1876: Heap buffer overflow in DevTools\n\n- Chromium 101.0.4951.67\n\n  * fixes for other platforms\n","affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 15 SP4","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.0.5005.61-bp154.2.5.3"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"102.0.5005.61-bp154.2.5.3","chromium":"102.0.5005.61-bp154.2.5.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10005-1.json"}},{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"102.0.5005.61-bp154.2.5.3"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"102.0.5005.61-bp154.2.5.3","chromium":"102.0.5005.61-bp154.2.5.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10005-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/JSMLLTNKJ3TPX4NE3EBN2DITMAJNWNB6/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1199893"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1853"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1858"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1860"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1865"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1866"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1867"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1868"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1871"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1872"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1873"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1875"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1876"}]}