--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8729b61cd3
2026-09-29 00:43:42.230063+00:00
--------------------------------------------------------------------------------

Name        : chromium
Product     : Fedora 43
Version     : 154.0.8037.57
Release     : 1.fc43
URL         : http://www.chromium.org/Home
Summary     : A WebKit (Blink) powered web browser that Google doesn't want you 
to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

Update to 154.0.8037.57
CVE-2026-95274: Improper output encoding in DevTools
CVE-2026-95275: Incorrect reference resolution in MediaStream
CVE-2026-95276: Improper input validation in Themes
CVE-2026-95277: Use after free in Views
CVE-2026-95278: Missing authorization in WakeLock
CVE-2026-95279: UI misrepresentation in Omnibox
CVE-2026-95280: Race condition in V8
CVE-2026-95281: Buffer overflow in ANGLE
CVE-2026-95282: Use after free in Platform
CVE-2026-95283: Buffer overflow in Tint
CVE-2026-95284: Buffer overflow in ANGLE
CVE-2026-95285: Missing authorization in WebView
CVE-2026-95286: Type confusion in Bindings
CVE-2026-95287: Missing authorization in Navigation
CVE-2026-95288: UI misrepresentation in Mobile
CVE-2026-95289: Incorrect authorization in Scroll
CVE-2026-95290: Missing authorization in NFC
CVE-2026-95291: UI misrepresentation in SecurityIndicators
CVE-2026-95292: Incorrect authorization in Safebrowsing
CVE-2026-95293: Uninitialized resource in GPU
CVE-2026-95294: UI misrepresentation in Browser
CVE-2026-95295: Information leak in Mobile
CVE-2026-95296: Missing authorization in Core
CVE-2026-95297: Missing authorization in Contextual Tasks
CVE-2026-95298: Use after free in Browser
CVE-2026-95299: Use after free in GPU
CVE-2026-95300: Missing authorization in DevTools
CVE-2026-95301: Missing authorization in Extensions
CVE-2026-95302: Incorrect authorization in WebAPKs
CVE-2026-95303: Incomplete cleanup in SmartCard
CVE-2026-95304: Out of bounds write in V8
CVE-2026-95305: UI misrepresentation in Chromoting
CVE-2026-95306: Type confusion in V8
CVE-2026-95307: UI misrepresentation in ExtensionsMenu
CVE-2026-95308: Integer overflow in Metrics
CVE-2026-95309: UI misrepresentation in Mobile
CVE-2026-95310: Use after free in AdFilter
CVE-2026-95311: Free of non-heap memory in Fonts
CVE-2026-95312: Information leak in Passwords
CVE-2026-95313: Use after free in Fullscreen
CVE-2026-95314: Incorrect authorization in HID
CVE-2026-95315: Use after free in Aura
CVE-2026-95316: Unchecked return value in Performance
CVE-2026-95317: Incorrect authorization in MediaCapture
CVE-2026-95318: Buffer overflow in Video
CVE-2026-95319: Use after free in Printing
CVE-2026-95320: Missing authorization in Navigation
CVE-2026-95321: UI misrepresentation in Payments
CVE-2026-95322: Out of bounds write in GPU
CVE-2026-95323: UI misrepresentation in Chromium
CVE-2026-95324: Uninitialized resource in GPU
CVE-2026-95325: Use after free in ANGLE
CVE-2026-95326: Incomplete cleanup in Bluetooth
CVE-2026-95327: Information leak in Networking
CVE-2026-95328: Confused deputy in Mobile
CVE-2026-95329: Out of bounds write in WebGL
CVE-2026-95330: Improper state validation in Downloads
CVE-2026-95331: Out of bounds write in ANGLE
CVE-2026-95332: Use of uninitialized variable in Tint
CVE-2026-95333: Use after free in Metrics
CVE-2026-95334: Incorrect reference resolution in WebProtect
CVE-2026-95335: Use after free in HID
CVE-2026-95336: Information leak in Transactions Platform
CVE-2026-95337: UI misrepresentation in Messages
CVE-2026-95338: Use after free in PDFium
CVE-2026-95339: Use after free in ServiceWorker
CVE-2026-95340: Incorrect authorization in PictureInPicture
CVE-2026-95341: Improper input validation in Desktop
CVE-2026-95342: Missing authorization in V8
CVE-2026-95343: Use after free in WebAudio
CVE-2026-95344: Race condition in DevTools
CVE-2026-95345: Use after free in Actor
CVE-2026-95346: UI misrepresentation in Chromoting
CVE-2026-95347: Use after free in Updater
CVE-2026-95348: Use after free in Bluetooth
CVE-2026-95349: Buffer overflow in WebGL
CVE-2026-95350: Buffer overflow in ANGLE
CVE-2026-95351: Use after free in Views
CVE-2026-95352: Incorrect authorization in DevTools
CVE-2026-95353: Use after free in Bindings
CVE-2026-95354: Use after free in Verifier
CVE-2026-95355: Incorrect authorization in Navigation
CVE-2026-95356: Use after free in WindowDialog
CVE-2026-95357: Out of bounds write in GPU
CVE-2026-95358: Incorrect authorization in Mobile
CVE-2026-95359: Uninitialized resource in GPU
CVE-2026-95360: Race condition in Editing
CVE-2026-95361: Confused deputy in DevTools
CVE-2026-95362: Cross-site request forgery in DevTools
CVE-2026-95363: UI misrepresentation in FileSystem
CVE-2026-95364: Improper input validation in Passwords
CVE-2026-95365: Type confusion in IndexedDB
CVE-2026-95366: Use of released resource in Core
CVE-2026-95367: Information leak in DataTransfer
CVE-2026-95368: Incorrect authorization in DevTools
CVE-2026-95369: Inappropriate implementation in XML
CVE-2026-95370: Inappropriate implementation in NFC
CVE-2026-95371: Missing authorization in Views
CVE-2026-95372: Use after free in Chromecast
CVE-2026-95373: Use after free in DevTools
CVE-2026-95374: Incorrect authorization in Network
CVE-2026-95375: Incorrect authorization in BrowserTag
CVE-2026-95376: Externally controlled reference in DevTools
CVE-2026-95380: Type confusion in V8
CVE-2026-95381: Improper input validation in Printing
CVE-2026-95382: Improper input validation in Auth
CVE-2026-95384: Race condition in Transactions Platform
CVE-2026-95385: Inappropriate implementation in PlatformIntegration
--------------------------------------------------------------------------------
ChangeLog:

* Wed Sep 23 2026 Than Ngo <[email protected]> - 154.0.8037.57-1
- Update to 154.0.8037.57
  * CVE-2026-95274: Improper output encoding in DevTools
  * CVE-2026-95275: Incorrect reference resolution in MediaStream
  * CVE-2026-95276: Improper input validation in Themes
  * CVE-2026-95277: Use after free in Views
  * CVE-2026-95278: Missing authorization in WakeLock
  * CVE-2026-95279: UI misrepresentation in Omnibox
  * CVE-2026-95280: Race condition in V8
  * CVE-2026-95281: Buffer overflow in ANGLE
  * CVE-2026-95282: Use after free in Platform
  * CVE-2026-95283: Buffer overflow in Tint
  * CVE-2026-95284: Buffer overflow in ANGLE
  * CVE-2026-95285: Missing authorization in WebView
  * CVE-2026-95286: Type confusion in Bindings
  * CVE-2026-95287: Missing authorization in Navigation
  * CVE-2026-95288: UI misrepresentation in Mobile
  * CVE-2026-95289: Incorrect authorization in Scroll
  * CVE-2026-95290: Missing authorization in NFC
  * CVE-2026-95291: UI misrepresentation in SecurityIndicators
  * CVE-2026-95292: Incorrect authorization in Safebrowsing
  * CVE-2026-95293: Uninitialized resource in GPU
  * CVE-2026-95294: UI misrepresentation in Browser
  * CVE-2026-95295: Information leak in Mobile
  * CVE-2026-95296: Missing authorization in Core
  * CVE-2026-95297: Missing authorization in Contextual Tasks
  * CVE-2026-95298: Use after free in Browser
  * CVE-2026-95299: Use after free in GPU
  * CVE-2026-95300: Missing authorization in DevTools
  * CVE-2026-95301: Missing authorization in Extensions
  * CVE-2026-95302: Incorrect authorization in WebAPKs
  * CVE-2026-95303: Incomplete cleanup in SmartCard
  * CVE-2026-95304: Out of bounds write in V8
  * CVE-2026-95305: UI misrepresentation in Chromoting
  * CVE-2026-95306: Type confusion in V8
  * CVE-2026-95307: UI misrepresentation in ExtensionsMenu
  * CVE-2026-95308: Integer overflow in Metrics
  * CVE-2026-95309: UI misrepresentation in Mobile
  * CVE-2026-95310: Use after free in AdFilter
  * CVE-2026-95311: Free of non-heap memory in Fonts
  * CVE-2026-95312: Information leak in Passwords
  * CVE-2026-95313: Use after free in Fullscreen
  * CVE-2026-95314: Incorrect authorization in HID
  * CVE-2026-95315: Use after free in Aura
  * CVE-2026-95316: Unchecked return value in Performance
  * CVE-2026-95317: Incorrect authorization in MediaCapture
  * CVE-2026-95318: Buffer overflow in Video
  * CVE-2026-95319: Use after free in Printing
  * CVE-2026-95320: Missing authorization in Navigation
  * CVE-2026-95321: UI misrepresentation in Payments
  * CVE-2026-95322: Out of bounds write in GPU
  * CVE-2026-95323: UI misrepresentation in Chromium
  * CVE-2026-95324: Uninitialized resource in GPU
  * CVE-2026-95325: Use after free in ANGLE
  * CVE-2026-95326: Incomplete cleanup in Bluetooth
  * CVE-2026-95327: Information leak in Networking
  * CVE-2026-95328: Confused deputy in Mobile
  * CVE-2026-95329: Out of bounds write in WebGL
  * CVE-2026-95330: Improper state validation in Downloads
  * CVE-2026-95331: Out of bounds write in ANGLE
  * CVE-2026-95332: Use of uninitialized variable in Tint
  * CVE-2026-95333: Use after free in Metrics
  * CVE-2026-95334: Incorrect reference resolution in WebProtect
  * CVE-2026-95335: Use after free in HID
  * CVE-2026-95336: Information leak in Transactions Platform
  * CVE-2026-95337: UI misrepresentation in Messages
  * CVE-2026-95338: Use after free in PDFium
  * CVE-2026-95339: Use after free in ServiceWorker
  * CVE-2026-95340: Incorrect authorization in PictureInPicture
  * CVE-2026-95341: Improper input validation in Desktop
  * CVE-2026-95342: Missing authorization in V8
  * CVE-2026-95343: Use after free in WebAudio
  * CVE-2026-95344: Race condition in DevTools
  * CVE-2026-95345: Use after free in Actor
  * CVE-2026-95346: UI misrepresentation in Chromoting
  * CVE-2026-95347: Use after free in Updater
  * CVE-2026-95348: Use after free in Bluetooth
  * CVE-2026-95349: Buffer overflow in WebGL
  * CVE-2026-95350: Buffer overflow in ANGLE
  * CVE-2026-95351: Use after free in Views
  * CVE-2026-95352: Incorrect authorization in DevTools
  * CVE-2026-95353: Use after free in Bindings
  * CVE-2026-95354: Use after free in Verifier
  * CVE-2026-95355: Incorrect authorization in Navigation
  * CVE-2026-95356: Use after free in WindowDialog
  * CVE-2026-95357: Out of bounds write in GPU
  * CVE-2026-95358: Incorrect authorization in Mobile
  * CVE-2026-95359: Uninitialized resource in GPU
  * CVE-2026-95360: Race condition in Editing
  * CVE-2026-95361: Confused deputy in DevTools
  * CVE-2026-95362: Cross-site request forgery in DevTools
  * CVE-2026-95363: UI misrepresentation in FileSystem
  * CVE-2026-95364: Improper input validation in Passwords
  * CVE-2026-95365: Type confusion in IndexedDB
  * CVE-2026-95366: Use of released resource in Core
  * CVE-2026-95367: Information leak in DataTransfer
  * CVE-2026-95368: Incorrect authorization in DevTools
  * CVE-2026-95369: Inappropriate implementation in XML
  * CVE-2026-95370: Inappropriate implementation in NFC
  * CVE-2026-95371: Missing authorization in Views
  * CVE-2026-95372: Use after free in Chromecast
  * CVE-2026-95373: Use after free in DevTools
  * CVE-2026-95374: Incorrect authorization in Network
  * CVE-2026-95375: Incorrect authorization in BrowserTag
  * CVE-2026-95376: Externally controlled reference in DevTools
  * CVE-2026-95380: Type confusion in V8
  * CVE-2026-95381: Improper input validation in Printing
  * CVE-2026-95382: Improper input validation in Auth
  * CVE-2026-95384: Race condition in Transactions Platform
  * CVE-2026-95385: Inappropriate implementation in PlatformIntegration
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2540919 - CVE-2026-17770 CVE-2026-17795 CVE-2026-18006 chromium: 
various flaws [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2540919
  [ 2 ] Bug #2540920 - CVE-2026-17770 CVE-2026-17795 CVE-2026-18006 chromium: 
various flaws [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2540920
  [ 3 ] Bug #2540923 - CVE-2026-79246 CVE-2026-79247 CVE-2026-79248 
CVE-2026-79249 CVE-2026-79250 CVE-2026-79251 CVE-2026-79252 CVE-2026-79253 
CVE-2026-79254 CVE-2026-79255 CVE-2026-79257 CVE-2026-79258 CVE-2026-79259 
CVE-2026-79260 ... chromium: various flaws [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2540923
  [ 4 ] Bug #2540924 - CVE-2026-79046 CVE-2026-79047 CVE-2026-79048 
CVE-2026-79049 CVE-2026-79050 CVE-2026-79134 CVE-2026-79136 CVE-2026-79191 
CVE-2026-79192 CVE-2026-79193 CVE-2026-79194 CVE-2026-79218 CVE-2026-79221 
CVE-2026-79222 ... chromium: various flaws [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2540924
  [ 5 ] Bug #2540926 - CVE-2026-79046 CVE-2026-79047 CVE-2026-79048 
CVE-2026-79049 CVE-2026-79050 CVE-2026-79134 CVE-2026-79136 CVE-2026-79191 
CVE-2026-79192 CVE-2026-79193 CVE-2026-79194 CVE-2026-79218 CVE-2026-79221 
CVE-2026-79222 ... chromium: various flaws [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2540926
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8729b61cd3' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to