ALT-PU-2025-11409-1

Обновление пакета chromium в ветке sisyphus_loongarch64

Версия140.0.7339.80-alt0.port
Задание#0
Опубликовано2025-09-05
Макс. серьёзностьHIGH
Серьёзность:

Закрытые проблемы (4)

CVE-2025-9864
NONE

Rejected reason: This CVE ID was assigned in error to a vulnerability that was both introduced and fixed before the code landed in the Stable channel of Chrome, and has been withdrawn.

Опубликовано: 2025-09-03Изменено: 2025-11-13
CVE-2025-9865
MEDIUM5.4

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

Опубликовано: 2025-09-03Изменено: 2025-09-04
CVSS 3.xСРЕДНЯЯ 5.4
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVE-2025-9866
HIGH8.8

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

Опубликовано: 2025-09-03Изменено: 2025-09-04
CVSS 3.xВЫСОКАЯ 8.8
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2025-9867
MEDIUM5.4

Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

Опубликовано: 2025-09-03Изменено: 2025-09-04
CVSS 3.xСРЕДНЯЯ 5.4
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N