ALT-PU-2025-5742-1
Package chromium updated to version 135.0.7049.95-alt0.port for branch sisyphus_loongarch64.
Closed vulnerabilities
                                                                                    Published: 2025-04-16
Modified: 2025-07-15
                                                                            Modified: 2025-07-15
CVE-2025-3619
Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
                                                                                        
                                                                                        
                                                                                            Severity: HIGH (8.8)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
                                                                                        
                                                                                        
                                                                                    
                                                                                References:
                                                                        
                                                                        
                                                                    
                                                                                    Published: 2025-04-16
Modified: 2025-04-23
                                                                            Modified: 2025-04-23
CVE-2025-3620
Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
                                                                                        
                                                                                        
                                                                                            Severity: HIGH (8.8)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
                                                                                        
                                                                                        
                                                                                    
                                                                                References:
                                                                        
                                                                        
                                                                    