Critical Chromium Vulnerabilities in Fedora 44 and 43 Released

Critical Chromium Vulnerabilities in Fedora 44 and 43 Released

First seen 5 Sep 2026, 21:03 UTC Linuxsecurity 60.8

Article Content

Browse articles
ThreatCluster

On September 5, 2026, Fedora released updates for Chromium, addressing multiple critical vulnerabilities, including CVE-2026-84353, CVE-2026-84352, and CVE-2026-84354. These vulnerabilities include use-after-free issues, improper authorization, and information leaks affecting various components of the browser. The updates apply to Fedora 44 and 43, with the latest version being 152.0.7977.75. The vulnerabilities could lead to significant security risks if exploited, including unauthorized access and data leaks. Administrators are urged to apply the updates promptly to mitigate potential threats. The CVEs were published on September 1, 2026, indicating a rapid response to emerging threats. The vulnerabilities affect Linux systems running the specified versions of Chromium.

Key Points: • Fedora 44 and 43 users must update Chromium to version 152.0.7977.75 immediately. • Critical vulnerabilities include use-after-free and improper authorization issues. • Exploitation of these vulnerabilities could lead to unauthorized access and information leaks.

Ask AI about this cluster

Timeline

2026-08-16
Public exploit for CVE-2026-78906 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-08-20
CVE-2026-76023 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-76020 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-76019 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-76017 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-76022 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-76021 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79236 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79240 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-78954 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE