openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0267-1 Rating: important References: #1246558 Cross-References: CVE-2025-6558 CVE-2025-7656 CVE-2025-7657 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Chromium 138.0.7204.157 (boo#1246558): * CVE-2025-7656: Integer overflow in V8 * CVE-2025-6558: Incorrect validation of untrusted input in ANGLE and GPU * CVE-2025-7657: Use after free in WebRTC - Chromium 138.0.7204.100: * tweaks to the Google services settings page Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-267=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 x86_64): chromedriver-138.0.7204.157-bp157.2.22.1 chromium-138.0.7204.157-bp157.2.22.1 References: https://www.suse.com/security/cve/CVE-2025-6558.html https://www.suse.com/security/cve/CVE-2025-7656.html https://www.suse.com/security/cve/CVE-2025-7657.html https://bugzilla.suse.com/1246558