Back Linuxsecurity Fedora 43 Chromium Critical Buffer Flaws Advisory FEDORA-2026
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
Chromium is an open-source web browser, powered by WebKit (Blink).
Update to 152.0.7977.82 CVE-2026-85046: Type confusion in V8 CVE-2026-85052: Out of bounds read in CrashReporting CVE-2026-85043: Incomplete cleanup in Network CVE-2026-85048: Use after free in Compositing CVE-2026-85045: Race condition in V8 CVE-2026-85050: Out of bounds write in WebGL CVE-2026-85053: Improper resource exposure in CacheStorage CVE-2026-85042: Use after free in DevTools CVE-2026-85049: Use after free in Skia CVE-2026-85051: Type confusion in Compositing CVE-2026-85047: Improper input validation in Transactions Platform CVE-2026-85044: Use of released resource in Mobile
* Sat Sep 5 2026 Than Ngo - 152.0.7977.82-1 - Update to 152.0.7977.82 * CVE-2026-85046: Type confusion in V8 * CVE-2026-85052: Out of bounds read in CrashReporting * CVE-2026-85043: Incomplete cleanup in Network * CVE-2026-85048: Use after free in Compositing * CVE-2026-85045: Race condition in V8 * CVE-2026-85050: Out of bounds write in WebGL * CVE-2026-85053: Improper resource exposure in CacheStorage * CVE-2026-85042: Use after free in DevTools * CVE-2026-85049: Use after free in Skia * CVE-2026-85051: Type confusion in Compositing * CVE-2026-85047: Improper input validation in Transactions Platform * CVE-2026-85044: Use of released resource in Mobile * Thu Sep 3 2026 Dominik Mierzejewski - 152.0.7977.75-2 - Rebuilt for FFmpeg 9
* Sat Sep 5 2026 Than Ngo - 152.0.7977.82-1 - Update to 152.0.7977.82 * CVE-2026-85046: Type confusion in V8 * CVE-2026-85052: Out of bounds read in CrashReporting * CVE-2026-85043: Incomplete cleanup in Network * CVE-2026-85048: Use after free in Compositing * CVE-2026-85045: Race condition in V8 * CVE-2026-85050: Out of bounds write in WebGL * CVE-2026-85053: Improper resource exposure in CacheStorage * CVE-2026-85042: Use after free in DevTools * CVE-2026-85049: Use after free in Skia * CVE-2026-85051: Type confusion in Compositing * CVE-2026-85047: Improper input validation in Transactions Platform * CVE-2026-85044: Use of released resource in Mobile * Thu Sep 3 2026 Dominik Mierzejewski - 152.0.7977.75-2 - Rebuilt for FFmpeg 9
[ 1 ] Bug #2528110 - CVE-2026-84358 chromium: chromium-browser: Improper privilege management in Downloads [fedora-all] [ 2 ] Bug #2528111 - CVE-2026-84358 chromium: chromium-browser: Improper privilege management in Downloads [epel-all] [ 3 ] Bug #2528121 - CVE-2026-84356 chromium: chromium-browser: UI misrepresentation in FullScreen [fedora-all] [ 4 ] Bug #2528122 - CVE-2026-84356 chromium: chromium-browser: UI misrepresentation in FullScreen [epel-all] [ 5 ] Bug #2528123 - CVE-2026-84326 chromium: Chromium-browser: Arbitrary code execution via crafted HTML page [fedora-all] [ 6 ] Bug #2528124 - CVE-2026-84326 chromium: Chromium-browser: Arbitrary code execution vi...
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c3be138e4c' at the command line. For more information, refer to the dnf documentation available at
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
