{"schema_version":"1.7.3","id":"openSUSE-SU-2023:0234-1","published":"2023-08-21T09:53:00Z","modified":"2026-02-04T04:01:20.458426Z","related":["CVE-2023-2312","CVE-2023-4349","CVE-2023-4350","CVE-2023-4351","CVE-2023-4352","CVE-2023-4353","CVE-2023-4354","CVE-2023-4355","CVE-2023-4356","CVE-2023-4357","CVE-2023-4358","CVE-2023-4359","CVE-2023-4360","CVE-2023-4361","CVE-2023-4362","CVE-2023-4363","CVE-2023-4364","CVE-2023-4365","CVE-2023-4366","CVE-2023-4367","CVE-2023-4368"],"upstream":["CVE-2023-2312","CVE-2023-4349","CVE-2023-4350","CVE-2023-4351","CVE-2023-4352","CVE-2023-4353","CVE-2023-4354","CVE-2023-4355","CVE-2023-4356","CVE-2023-4357","CVE-2023-4358","CVE-2023-4359","CVE-2023-4360","CVE-2023-4361","CVE-2023-4362","CVE-2023-4363","CVE-2023-4364","CVE-2023-4365","CVE-2023-4366","CVE-2023-4367","CVE-2023-4368"],"summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChromium 116.0.5845.96\n\n* New CSS features: Motion Path, and 'display' and\n  'content-visibility' animations\n* Web APIs: AbortSignal.any(), BYOB support for Fetch, Back/\n  forward cache NotRestoredReason API, Document Picture-in-\n  Picture, Expanded Wildcards in Permissions Policy Origins,\n  FedCM bundle: Login Hint API, User Info API, and RP Context API,\n  Non-composed Mouse and Pointer enter/leave events, \n  Remove document.open sandbox inheritance, \n  Report Critical-CH caused restart in NavigationTiming\n\nThis update fixes a number of security issues (boo#1214301):\n\n  * CVE-2023-2312: Use after free in Offline\n  * CVE-2023-4349: Use after free in Device Trust Connectors\n  * CVE-2023-4350: Inappropriate implementation in Fullscreen\n  * CVE-2023-4351: Use after free in Network\n  * CVE-2023-4352: Type Confusion in V8\n  * CVE-2023-4353: Heap buffer overflow in ANGLE\n  * CVE-2023-4354: Heap buffer overflow in Skia\n  * CVE-2023-4355: Out of bounds memory access in V8\n  * CVE-2023-4356: Use after free in Audio\n  * CVE-2023-4357: Insufficient validation of untrusted input in XML\n  * CVE-2023-4358: Use after free in DNS\n  * CVE-2023-4359: Inappropriate implementation in App Launcher\n  * CVE-2023-4360: Inappropriate implementation in Color\n  * CVE-2023-4361: Inappropriate implementation in Autofill\n  * CVE-2023-4362: Heap buffer overflow in Mojom IDL\n  * CVE-2023-4363: Inappropriate implementation in WebShare\n  * CVE-2023-4364: Inappropriate implementation in Permission Prompts\n  * CVE-2023-4365: Inappropriate implementation in Fullscreen\n  * CVE-2023-4366: Use after free in Extensions\n  * CVE-2023-4367: Insufficient policy enforcement in Extensions API\n  * CVE-2023-4368: Insufficient policy enforcement in Extensions API\n\n- Fix crash with extensions (boo#1214003)\n\n","affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 15 SP4","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"116.0.5845.96-bp155.2.19.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"116.0.5845.96-bp155.2.19.1","chromium":"116.0.5845.96-bp155.2.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0234-1.json"}},{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 15 SP5","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"116.0.5845.96-bp155.2.19.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"116.0.5845.96-bp155.2.19.1","chromium":"116.0.5845.96-bp155.2.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0234-1.json"}},{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"116.0.5845.96-bp155.2.19.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"116.0.5845.96-bp155.2.19.1","chromium":"116.0.5845.96-bp155.2.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0234-1.json"}},{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"116.0.5845.96-bp155.2.19.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"116.0.5845.96-bp155.2.19.1","chromium":"116.0.5845.96-bp155.2.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0234-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/BHGOO7OFVF75LWZYDKQO5H6ZBGN5JVTX/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214003"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214301"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-2312"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4349"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4350"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4351"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4352"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4353"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4354"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4358"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4359"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4361"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4362"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4363"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4364"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4365"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4367"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4368"}]}