- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202507-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Chromium, Google Chrome, Microsoft Edge. Opera: Multiple Vulnerabilities Date: July 08, 2025 Bugs: #923966, #942503, #943403, #946723, #947700, #948135, #948983, #951155, #951688 ID: 202507-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution. Background ========== Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. Google Chrome is one fast, simple, and secure browser for all your devices. Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. Opera is a fast and secure web browser. Affected packages ================= Package Vulnerable Unaffected ------------------------- ---------------- ----------------- www-client/chromium < 134.0.6998.117 >= 134.0.6998.117 www-client/google-chrome < 134.0.6998.117 >= 134.0.6998.117 www-client/microsoft-edge < 134.0.3124.83 >= 134.0.3124.83 www-client/opera < 119.0.5497.12 >= 119.0.5497.12 Description =========== Multiple vulnerabilities have been discovered in Chromium and its derivatives. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Google Chrome users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-client/google-chrome-134.0.6998.117" All Chromium users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-client/chromium-134.0.6998.117" All Microsoft Edge users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-client/microsoft-edge-134.0.3124.83" All Oprea users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-client/opera-119.0.5497.12" References ========== [ 1 ] CVE-2024-1283 https://nvd.nist.gov/vuln/detail/CVE-2024-1283 [ 2 ] CVE-2024-1284 https://nvd.nist.gov/vuln/detail/CVE-2024-1284 [ 3 ] CVE-2024-10487 https://nvd.nist.gov/vuln/detail/CVE-2024-10487 [ 4 ] CVE-2024-10488 https://nvd.nist.gov/vuln/detail/CVE-2024-10488 [ 5 ] CVE-2024-11110 https://nvd.nist.gov/vuln/detail/CVE-2024-11110 [ 6 ] CVE-2024-11111 https://nvd.nist.gov/vuln/detail/CVE-2024-11111 [ 7 ] CVE-2024-11112 https://nvd.nist.gov/vuln/detail/CVE-2024-11112 [ 8 ] CVE-2024-11113 https://nvd.nist.gov/vuln/detail/CVE-2024-11113 [ 9 ] CVE-2024-11114 https://nvd.nist.gov/vuln/detail/CVE-2024-11114 [ 10 ] CVE-2024-11115 https://nvd.nist.gov/vuln/detail/CVE-2024-11115 [ 11 ] CVE-2024-11116 https://nvd.nist.gov/vuln/detail/CVE-2024-11116 [ 12 ] CVE-2024-11117 https://nvd.nist.gov/vuln/detail/CVE-2024-11117 [ 13 ] CVE-2024-12692 https://nvd.nist.gov/vuln/detail/CVE-2024-12692 [ 14 ] CVE-2024-12693 https://nvd.nist.gov/vuln/detail/CVE-2024-12693 [ 15 ] CVE-2024-12694 https://nvd.nist.gov/vuln/detail/CVE-2024-12694 [ 16 ] CVE-2024-12695 https://nvd.nist.gov/vuln/detail/CVE-2024-12695 [ 17 ] CVE-2025-0291 https://nvd.nist.gov/vuln/detail/CVE-2025-0291 [ 18 ] CVE-2025-0434 https://nvd.nist.gov/vuln/detail/CVE-2025-0434 [ 19 ] CVE-2025-0435 https://nvd.nist.gov/vuln/detail/CVE-2025-0435 [ 20 ] CVE-2025-0436 https://nvd.nist.gov/vuln/detail/CVE-2025-0436 [ 21 ] CVE-2025-0437 https://nvd.nist.gov/vuln/detail/CVE-2025-0437 [ 22 ] CVE-2025-0438 https://nvd.nist.gov/vuln/detail/CVE-2025-0438 [ 23 ] CVE-2025-0439 https://nvd.nist.gov/vuln/detail/CVE-2025-0439 [ 24 ] CVE-2025-0440 https://nvd.nist.gov/vuln/detail/CVE-2025-0440 [ 25 ] CVE-2025-0441 https://nvd.nist.gov/vuln/detail/CVE-2025-0441 [ 26 ] CVE-2025-0442 https://nvd.nist.gov/vuln/detail/CVE-2025-0442 [ 27 ] CVE-2025-0443 https://nvd.nist.gov/vuln/detail/CVE-2025-0443 [ 28 ] CVE-2025-0446 https://nvd.nist.gov/vuln/detail/CVE-2025-0446 [ 29 ] CVE-2025-0447 https://nvd.nist.gov/vuln/detail/CVE-2025-0447 [ 30 ] CVE-2025-0448 https://nvd.nist.gov/vuln/detail/CVE-2025-0448 [ 31 ] CVE-2025-0762 https://nvd.nist.gov/vuln/detail/CVE-2025-0762 [ 32 ] CVE-2025-1920 https://nvd.nist.gov/vuln/detail/CVE-2025-1920 [ 33 ] CVE-2025-2135 https://nvd.nist.gov/vuln/detail/CVE-2025-2135 [ 34 ] CVE-2025-2136 https://nvd.nist.gov/vuln/detail/CVE-2025-2136 [ 35 ] CVE-2025-2137 https://nvd.nist.gov/vuln/detail/CVE-2025-2137 [ 36 ] CVE-2025-2476 https://nvd.nist.gov/vuln/detail/CVE-2025-2476 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202507-07 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2025 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5