openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0058-1 Rating: important References: #1236806 Cross-References: CVE-2025-0444 CVE-2025-0445 CVE-2025-0451 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Chromium 133.0.6943.53 (stable released 2024-02-04) (boo#1236806) * CVE-2025-0444: Use after free in Skia * CVE-2025-0445: Use after free in V8 * CVE-2025-0451: Inappropriate implementation in Extensions API - Chromium 133.0.6943.35 (beta released 2025-01-29) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-58=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): chromedriver-133.0.6943.53-bp156.2.78.1 chromium-133.0.6943.53-bp156.2.78.1 References: https://www.suse.com/security/cve/CVE-2025-0444.html https://www.suse.com/security/cve/CVE-2025-0445.html https://www.suse.com/security/cve/CVE-2025-0451.html https://bugzilla.suse.com/1236806