Critical Use After Free Vulnerabilities in Fedora Chromium Update

Critical Use After Free Vulnerabilities in Fedora Chromium Update

5h ago Linuxsecurity 94% similarity 72.8
Share:

Article Content

Browse articles
ThreatCluster

On June 9, 2026, Fedora released an update for Chromium version 149.0.7827.102 addressing multiple critical vulnerabilities, primarily use after free issues. The update includes CVE-2026-11628 to CVE-2026-11667, affecting components like Ozone, Aura, and Bluetooth. These vulnerabilities could allow attackers to execute arbitrary code or crash the browser, impacting all users of Fedora 43 and 44. The vulnerabilities were published between June 8 and June 9, 2026, with CVE-2026-11645 noted for active exploitation as of June 9. Security professionals are urged to apply the updates immediately to mitigate risks. The vulnerabilities are significant due to their potential for exploitation in real-world attacks.

Key Points: • Fedora's Chromium update addresses multiple critical use after free vulnerabilities. • CVE-2026-11645 has been confirmed for active exploitation, heightening urgency. • All users of Fedora 43 and 44 are affected and should update immediately.

ThreatCluster AI

Timeline

2026-06-04
CVE-2026-10926 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11123 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-10929 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-10989 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11175 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11275 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11126 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11165 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11065 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-11284 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →