Upstream information

CVE-2025-11209 at MITRE

Description

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

SUSE information

Overall state of this security issue: Revisit

This issue is currently rated as having moderate severity.

SUSE Bugzilla entry: 1250780 [IN_PROGRESS]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Package Hub 15 SP6
  • chromedriver >= 141.0.7390.54-bp156.2.176.1
  • chromium >= 141.0.7390.54-bp156.2.176.1
Patchnames:
openSUSE-2025-388
openSUSE Leap 15.6
  • chromedriver >= 141.0.7390.54-bp156.2.176.1
  • chromium >= 141.0.7390.54-bp156.2.176.1
Patchnames:
openSUSE-2025-388
openSUSE Leap 16.0
  • chromedriver >= 141.0.7390.76-bp160.1.1
  • chromium >= 141.0.7390.76-bp160.1.1
Patchnames:
openSUSE-Leap-16.0-packagehub-1
openSUSE Tumbleweed
  • chromedriver >= 141.0.7390.54-1.1
  • chromium >= 141.0.7390.54-1.1
Patchnames:
openSUSE-Tumbleweed-2025-15601


SUSE Timeline for this CVE

CVE page created: Wed Oct 1 19:15:09 2025
CVE page last modified: Fri Nov 7 12:48:17 2025