Critical Vulnerabilities in Fedora Chromium Browser Affecting Multiple Versions

Critical Vulnerabilities in Fedora Chromium Browser Affecting Multiple Versions

First seen 8 Sep 2026, 12:03 UTC Linuxsecurity 72.8

Article Content

Browse articles
ThreatCluster

Recent updates to the Fedora Chromium browser have revealed multiple critical vulnerabilities, including CVE-2026-85046, CVE-2026-85052, and CVE-2026-85043, which involve type confusion, out-of-bounds reads, and improper resource exposure. The vulnerabilities affect Fedora versions 43 and 44, with potential exploitation vectors including crafted web content and malicious scripts. The updates released on September 5, 2026, address these issues, but the presence of proof-of-concept (PoC) code raises concerns about active exploitation. Users are urged to update to version 152.0.7977.82 to mitigate risks. The vulnerabilities were added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 4, 2026, indicating a heightened risk of exploitation. The scope of impact includes all users of the affected Fedora versions, particularly those using the Chromium browser for web activities.

Key Points: • Multiple critical vulnerabilities identified in Fedora Chromium browser. • Updates released on September 5, 2026, to address these vulnerabilities. • CISA added related CVEs to the KEV catalog, indicating active exploitation risk.

Ask AI about this cluster

Timeline

2026-08-16
Public exploit for CVE-2026-78906 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-08-20
CVE-2026-76021 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-76020 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-76022 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-76019 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-76023 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-76017 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79074 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79152 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-78895 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE