Skip to content
Critical Use After Free Vulnerabilities in Fedora Chromium Update

Critical Use After Free Vulnerabilities in Fedora Chromium Update

First seen 14 Jun 2026, 06:20 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 15, 2026 at 05:34 UTC
  • Fedora's Chromium update addresses multiple critical use after free vulnerabilities.
  • CVE-2026-11645 has been confirmed for active exploitation, heightening urgency.
  • All users of Fedora 43 and 44 are affected and should update immediately.

On June 9, 2026, Fedora released an update for Chromium version 149.0.7827.102 addressing multiple critical vulnerabilities, primarily use after free issues. The update includes CVE-2026-11628 to CVE-2026-11667, affecting components like Ozone, Aura, and Bluetooth. These vulnerabilities could allow attackers to execute arbitrary code or crash the browser, impacting all users of Fedora 43 and 44. The vulnerabilities were published between June 8 and June 9, 2026, with CVE-2026-11645 noted for active exploitation as of June 9. Security professionals are urged to apply the updates immediately to mitigate risks. The vulnerabilities are significant due to their potential for exploitation in real-world attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 98d ago How this analysis works

Timeline

2026-06-04
CVE-2026-10926 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11123 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-10929 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-10989 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11175 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11275 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11126 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11165 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11065 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11284 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2026-10881 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed