Skip to content
Critical Security Flaws in Chromium Affecting Fedora Users

Critical Security Flaws in Chromium Affecting Fedora Users

First seen 29 Sep 2026, 03:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 05:09 UTC
  • •Multiple critical CVEs identified in Chromium affecting Fedora 43 and 44.
  • •CISA confirms exploitation of a Linux firewall flaw related to these vulnerabilities.
  • •Users are urged to update to version 154.0.8037.57 immediately.

On September 29, 2026, Fedora released an advisory detailing multiple critical security vulnerabilities in Chromium version 154.0.8037.57, including improper input validation, buffer overflows, and missing authorizations. The vulnerabilities are identified by CVEs ranging from CVE-2026-95274 to CVE-2026-95310, with issues like use-after-free and UI misrepresentation. CISA has confirmed exploitation of a Linux firewall flaw, urging users to apply the necessary updates. The flaws could potentially allow attackers to execute arbitrary code or bypass security measures. Users of Fedora 43 and 44 are particularly affected, with the advisory emphasizing the urgency of applying the patches. The vulnerabilities were disclosed on September 23, 2026, and are part of ongoing concerns regarding the security of open-source web browsers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-30
CVE-2026-18006 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-30
CVE-2026-17770 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-30
CVE-2026-17795 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79247 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79191 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79257 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79221 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79194 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79253 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-25
CVE-2026-79193 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2026-17770 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed