Fedora alert FEDORA-2026-59f46c195f (chromium)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 44 Update: chromium-149.0.7827.114-1.fc44 | |
| Date: | Wed, 17 Jun 2026 08:44:24 +0000 | |
| Message-ID: | <20260617084424.877C66A3D4@bastion01.rdu3.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-59f46c195f 2026-06-17 08:41:51.002543+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 44 Version : 149.0.7827.114 Release : 1.fc44 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 149.0.7827.114 CVE-2026-12007: Use after free Core CVE-2026-12008: Use after free DigitalCredentials CVE-2026-12009: Insufficient validation of untrusted input Accessibility CVE-2026-12010: Heap buffer overflow GPU CVE-2026-12011: Use after free WebMIDI CVE-2026-12012: Use after free Network CVE-2026-12013: Use after free Media CVE-2026-12014: Use after free Cast CVE-2026-12015: Use after free Autofill CVE-2026-12016: Insufficient validation of untrusted input DevTools CVE-2026-12017: Insufficient validation of untrusted input Extensions CVE-2026-12018: Inappropriate implementation Mojo CVE-2026-12019: Out of bounds write Codecs CVE-2026-12020: Use after free Autofill CVE-2026-12022: Race Safe Browsing CVE-2026-12023: Use after free GPU CVE-2026-12024: Insufficient policy enforcement DevTools CVE-2026-12025: Insufficient validation of untrusted input Network CVE-2026-12026: Out of bounds read Video CVE-2026-12027: Insufficient policy enforcement Headless CVE-2026-12028: Use after free GPU CVE-2026-12029: Use after free Video CVE-2026-12030: Heap buffer overflow GPU CVE-2026-12031: Inappropriate implementation Views CVE-2026-12032: Inappropriate implementation Passwords CVE-2026-12033: Out of bounds read VideoCapture CVE-2026-12034: Insufficient validation of untrusted input Linux Toolkit Theming CVE-2026-12035: Use after free Views Disable AI Mode settings -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 12 2026 Than Ngo <than@redhat.com> - 149.0.7827.114-1 - Update to 149.0.7827.114 * CVE-2026-12007: Use after free Core * CVE-2026-12008: Use after free DigitalCredentials * CVE-2026-12009: Insufficient validation of untrusted input Accessibility * CVE-2026-12010: Heap buffer overflow GPU * CVE-2026-12011: Use after free WebMIDI * CVE-2026-12012: Use after free Network * CVE-2026-12013: Use after free Media * CVE-2026-12014: Use after free Cast * CVE-2026-12015: Use after free Autofill * CVE-2026-12016: Insufficient validation of untrusted input DevTools * CVE-2026-12017: Insufficient validation of untrusted input Extensions * CVE-2026-12018: Inappropriate implementation Mojo * CVE-2026-12019: Out of bounds write Codecs * CVE-2026-12020: Use after free Autofill * CVE-2026-12022: Race Safe Browsing * CVE-2026-12023: Use after free GPU * CVE-2026-12024: Insufficient policy enforcement DevTools * CVE-2026-12025: Insufficient validation of untrusted input Network * CVE-2026-12026: Out of bounds read Video * CVE-2026-12027: Insufficient policy enforcement Headless * CVE-2026-12028: Use after free GPU * CVE-2026-12029: Use after free Video * CVE-2026-12030: Heap buffer overflow GPU * CVE-2026-12031: Inappropriate implementation Views * CVE-2026-12032: Inappropriate implementation Passwords * CVE-2026-12033: Out of bounds read VideoCapture * CVE-2026-12034: Insufficient validation of untrusted input Linux Toolkit Theming * CVE-2026-12035: Use after free Views - Disable AI Mode settings -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-59f46c195f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
