-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1e015b5959 2026-09-27 00:56:07.318404+00:00 --------------------------------------------------------------------------------
Name : chromium Product : Fedora 44 Version : 154.0.8037.57 Release : 1.fc44 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 154.0.8037.57 CVE-2026-95274: Improper output encoding in DevTools CVE-2026-95275: Incorrect reference resolution in MediaStream CVE-2026-95276: Improper input validation in Themes CVE-2026-95277: Use after free in Views CVE-2026-95278: Missing authorization in WakeLock CVE-2026-95279: UI misrepresentation in Omnibox CVE-2026-95280: Race condition in V8 CVE-2026-95281: Buffer overflow in ANGLE CVE-2026-95282: Use after free in Platform CVE-2026-95283: Buffer overflow in Tint CVE-2026-95284: Buffer overflow in ANGLE CVE-2026-95285: Missing authorization in WebView CVE-2026-95286: Type confusion in Bindings CVE-2026-95287: Missing authorization in Navigation CVE-2026-95288: UI misrepresentation in Mobile CVE-2026-95289: Incorrect authorization in Scroll CVE-2026-95290: Missing authorization in NFC CVE-2026-95291: UI misrepresentation in SecurityIndicators CVE-2026-95292: Incorrect authorization in Safebrowsing CVE-2026-95293: Uninitialized resource in GPU CVE-2026-95294: UI misrepresentation in Browser CVE-2026-95295: Information leak in Mobile CVE-2026-95296: Missing authorization in Core CVE-2026-95297: Missing authorization in Contextual Tasks CVE-2026-95298: Use after free in Browser CVE-2026-95299: Use after free in GPU CVE-2026-95300: Missing authorization in DevTools CVE-2026-95301: Missing authorization in Extensions CVE-2026-95302: Incorrect authorization in WebAPKs CVE-2026-95303: Incomplete cleanup in SmartCard CVE-2026-95304: Out of bounds write in V8 CVE-2026-95305: UI misrepresentation in Chromoting CVE-2026-95306: Type confusion in V8 CVE-2026-95307: UI misrepresentation in ExtensionsMenu CVE-2026-95308: Integer overflow in Metrics CVE-2026-95309: UI misrepresentation in Mobile CVE-2026-95310: Use after free in AdFilter CVE-2026-95311: Free of non-heap memory in Fonts CVE-2026-95312: Information leak in Passwords CVE-2026-95313: Use after free in Fullscreen CVE-2026-95314: Incorrect authorization in HID CVE-2026-95315: Use after free in Aura CVE-2026-95316: Unchecked return value in Performance CVE-2026-95317: Incorrect authorization in MediaCapture CVE-2026-95318: Buffer overflow in Video CVE-2026-95319: Use after free in Printing CVE-2026-95320: Missing authorization in Navigation CVE-2026-95321: UI misrepresentation in Payments CVE-2026-95322: Out of bounds write in GPU CVE-2026-95323: UI misrepresentation in Chromium CVE-2026-95324: Uninitialized resource in GPU CVE-2026-95325: Use after free in ANGLE CVE-2026-95326: Incomplete cleanup in Bluetooth CVE-2026-95327: Information leak in Networking CVE-2026-95328: Confused deputy in Mobile CVE-2026-95329: Out of bounds write in WebGL CVE-2026-95330: Improper state validation in Downloads CVE-2026-95331: Out of bounds write in ANGLE CVE-2026-95332: Use of uninitialized variable in Tint CVE-2026-95333: Use after free in Metrics CVE-2026-95334: Incorrect reference resolution in WebProtect CVE-2026-95335: Use after free in HID CVE-2026-95336: Information leak in Transactions Platform CVE-2026-95337: UI misrepresentation in Messages CVE-2026-95338: Use after free in PDFium CVE-2026-95339: Use after free in ServiceWorker CVE-2026-95340: Incorrect authorization in PictureInPicture CVE-2026-95341: Improper input validation in Desktop CVE-2026-95342: Missing authorization in V8 CVE-2026-95343: Use after free in WebAudio CVE-2026-95344: Race condition in DevTools CVE-2026-95345: Use after free in Actor CVE-2026-95346: UI misrepresentation in Chromoting CVE-2026-95347: Use after free in Updater CVE-2026-95348: Use after free in Bluetooth CVE-2026-95349: Buffer overflow in WebGL CVE-2026-95350: Buffer overflow in ANGLE CVE-2026-95351: Use after free in Views CVE-2026-95352: Incorrect authorization in DevTools CVE-2026-95353: Use after free in Bindings CVE-2026-95354: Use after free in Verifier CVE-2026-95355: Incorrect authorization in Navigation CVE-2026-95356: Use after free in WindowDialog CVE-2026-95357: Out of bounds write in GPU CVE-2026-95358: Incorrect authorization in Mobile CVE-2026-95359: Uninitialized resource in GPU CVE-2026-95360: Race condition in Editing CVE-2026-95361: Confused deputy in DevTools CVE-2026-95362: Cross-site request forgery in DevTools CVE-2026-95363: UI misrepresentation in FileSystem CVE-2026-95364: Improper input validation in Passwords CVE-2026-95365: Type confusion in IndexedDB CVE-2026-95366: Use of released resource in Core CVE-2026-95367: Information leak in DataTransfer CVE-2026-95368: Incorrect authorization in DevTools CVE-2026-95369: Inappropriate implementation in XML CVE-2026-95370: Inappropriate implementation in NFC CVE-2026-95371: Missing authorization in Views CVE-2026-95372: Use after free in Chromecast CVE-2026-95373: Use after free in DevTools CVE-2026-95374: Incorrect authorization in Network CVE-2026-95375: Incorrect authorization in BrowserTag CVE-2026-95376: Externally controlled reference in DevTools CVE-2026-95380: Type confusion in V8 CVE-2026-95381: Improper input validation in Printing CVE-2026-95382: Improper input validation in Auth CVE-2026-95384: Race condition in Transactions Platform CVE-2026-95385: Inappropriate implementation in PlatformIntegration -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 23 2026 Than Ngo <[email protected]> - 154.0.8037.57-1 - Update to 154.0.8037.57 * CVE-2026-95274: Improper output encoding in DevTools * CVE-2026-95275: Incorrect reference resolution in MediaStream * CVE-2026-95276: Improper input validation in Themes * CVE-2026-95277: Use after free in Views * CVE-2026-95278: Missing authorization in WakeLock * CVE-2026-95279: UI misrepresentation in Omnibox * CVE-2026-95280: Race condition in V8 * CVE-2026-95281: Buffer overflow in ANGLE * CVE-2026-95282: Use after free in Platform * CVE-2026-95283: Buffer overflow in Tint * CVE-2026-95284: Buffer overflow in ANGLE * CVE-2026-95285: Missing authorization in WebView * CVE-2026-95286: Type confusion in Bindings * CVE-2026-95287: Missing authorization in Navigation * CVE-2026-95288: UI misrepresentation in Mobile * CVE-2026-95289: Incorrect authorization in Scroll * CVE-2026-95290: Missing authorization in NFC * CVE-2026-95291: UI misrepresentation in SecurityIndicators * CVE-2026-95292: Incorrect authorization in Safebrowsing * CVE-2026-95293: Uninitialized resource in GPU * CVE-2026-95294: UI misrepresentation in Browser * CVE-2026-95295: Information leak in Mobile * CVE-2026-95296: Missing authorization in Core * CVE-2026-95297: Missing authorization in Contextual Tasks * CVE-2026-95298: Use after free in Browser * CVE-2026-95299: Use after free in GPU * CVE-2026-95300: Missing authorization in DevTools * CVE-2026-95301: Missing authorization in Extensions * CVE-2026-95302: Incorrect authorization in WebAPKs * CVE-2026-95303: Incomplete cleanup in SmartCard * CVE-2026-95304: Out of bounds write in V8 * CVE-2026-95305: UI misrepresentation in Chromoting * CVE-2026-95306: Type confusion in V8 * CVE-2026-95307: UI misrepresentation in ExtensionsMenu * CVE-2026-95308: Integer overflow in Metrics * CVE-2026-95309: UI misrepresentation in Mobile * CVE-2026-95310: Use after free in AdFilter * CVE-2026-95311: Free of non-heap memory in Fonts * CVE-2026-95312: Information leak in Passwords * CVE-2026-95313: Use after free in Fullscreen * CVE-2026-95314: Incorrect authorization in HID * CVE-2026-95315: Use after free in Aura * CVE-2026-95316: Unchecked return value in Performance * CVE-2026-95317: Incorrect authorization in MediaCapture * CVE-2026-95318: Buffer overflow in Video * CVE-2026-95319: Use after free in Printing * CVE-2026-95320: Missing authorization in Navigation * CVE-2026-95321: UI misrepresentation in Payments * CVE-2026-95322: Out of bounds write in GPU * CVE-2026-95323: UI misrepresentation in Chromium * CVE-2026-95324: Uninitialized resource in GPU * CVE-2026-95325: Use after free in ANGLE * CVE-2026-95326: Incomplete cleanup in Bluetooth * CVE-2026-95327: Information leak in Networking * CVE-2026-95328: Confused deputy in Mobile * CVE-2026-95329: Out of bounds write in WebGL * CVE-2026-95330: Improper state validation in Downloads * CVE-2026-95331: Out of bounds write in ANGLE * CVE-2026-95332: Use of uninitialized variable in Tint * CVE-2026-95333: Use after free in Metrics * CVE-2026-95334: Incorrect reference resolution in WebProtect * CVE-2026-95335: Use after free in HID * CVE-2026-95336: Information leak in Transactions Platform * CVE-2026-95337: UI misrepresentation in Messages * CVE-2026-95338: Use after free in PDFium * CVE-2026-95339: Use after free in ServiceWorker * CVE-2026-95340: Incorrect authorization in PictureInPicture * CVE-2026-95341: Improper input validation in Desktop * CVE-2026-95342: Missing authorization in V8 * CVE-2026-95343: Use after free in WebAudio * CVE-2026-95344: Race condition in DevTools * CVE-2026-95345: Use after free in Actor * CVE-2026-95346: UI misrepresentation in Chromoting * CVE-2026-95347: Use after free in Updater * CVE-2026-95348: Use after free in Bluetooth * CVE-2026-95349: Buffer overflow in WebGL * CVE-2026-95350: Buffer overflow in ANGLE * CVE-2026-95351: Use after free in Views * CVE-2026-95352: Incorrect authorization in DevTools * CVE-2026-95353: Use after free in Bindings * CVE-2026-95354: Use after free in Verifier * CVE-2026-95355: Incorrect authorization in Navigation * CVE-2026-95356: Use after free in WindowDialog * CVE-2026-95357: Out of bounds write in GPU * CVE-2026-95358: Incorrect authorization in Mobile * CVE-2026-95359: Uninitialized resource in GPU * CVE-2026-95360: Race condition in Editing * CVE-2026-95361: Confused deputy in DevTools * CVE-2026-95362: Cross-site request forgery in DevTools * CVE-2026-95363: UI misrepresentation in FileSystem * CVE-2026-95364: Improper input validation in Passwords * CVE-2026-95365: Type confusion in IndexedDB * CVE-2026-95366: Use of released resource in Core * CVE-2026-95367: Information leak in DataTransfer * CVE-2026-95368: Incorrect authorization in DevTools * CVE-2026-95369: Inappropriate implementation in XML * CVE-2026-95370: Inappropriate implementation in NFC * CVE-2026-95371: Missing authorization in Views * CVE-2026-95372: Use after free in Chromecast * CVE-2026-95373: Use after free in DevTools * CVE-2026-95374: Incorrect authorization in Network * CVE-2026-95375: Incorrect authorization in BrowserTag * CVE-2026-95376: Externally controlled reference in DevTools * CVE-2026-95380: Type confusion in V8 * CVE-2026-95381: Improper input validation in Printing * CVE-2026-95382: Improper input validation in Auth * CVE-2026-95384: Race condition in Transactions Platform * CVE-2026-95385: Inappropriate implementation in PlatformIntegration -------------------------------------------------------------------------------- References: [ 1 ] Bug #2540919 - CVE-2026-17770 CVE-2026-17795 CVE-2026-18006 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2540919 [ 2 ] Bug #2540920 - CVE-2026-17770 CVE-2026-17795 CVE-2026-18006 chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2540920 [ 3 ] Bug #2540923 - CVE-2026-79246 CVE-2026-79247 CVE-2026-79248 CVE-2026-79249 CVE-2026-79250 CVE-2026-79251 CVE-2026-79252 CVE-2026-79253 CVE-2026-79254 CVE-2026-79255 CVE-2026-79257 CVE-2026-79258 CVE-2026-79259 CVE-2026-79260 ... chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2540923 [ 4 ] Bug #2540924 - CVE-2026-79046 CVE-2026-79047 CVE-2026-79048 CVE-2026-79049 CVE-2026-79050 CVE-2026-79134 CVE-2026-79136 CVE-2026-79191 CVE-2026-79192 CVE-2026-79193 CVE-2026-79194 CVE-2026-79218 CVE-2026-79221 CVE-2026-79222 ... chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2540924 [ 5 ] Bug #2540926 - CVE-2026-79046 CVE-2026-79047 CVE-2026-79048 CVE-2026-79049 CVE-2026-79050 CVE-2026-79134 CVE-2026-79136 CVE-2026-79191 CVE-2026-79192 CVE-2026-79193 CVE-2026-79194 CVE-2026-79218 CVE-2026-79221 CVE-2026-79222 ... chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2540926 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1e015b5959' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
