ISN 2026-31: Chromium Vulnerabilities

First published 24 July 2026

CVSS:3.1: 8.8 (High)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Summary

Multiple security vulnerabilities have been found in Chromium, a web browser used in IGEL OS. This affects the following product versions:

  • IGEL OS 12

  • IGEL OS 11

Details

Google reports vulnerabilities of the use-after-free type in Chromium’s Ozone (CVE-2026-15764, CVE-2026-15765, CVE-2026-15112) and Views components (CVE-2026-15129). A remote attacker could exploit these using a crafted HTML page. Google rates these issues as critical, but other sources such as CISA-ADP rate them as high.

Apart from those, there is an inappropriate implementation in the V8 JavaScript Engine (CVE-2026-15776, high) and an out-of-bounds read in Codecs, which could be exploited via a crafted video file (CVE-2026-15114, high).

In total, Google has reported 42 CVEs, which can be found in the References.

Update Instructions

  • OS 12: Upgrade the Chromium app to version 150.0.7871.124 or newer.

  • OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.

References