First published 5 August 2026
CVSS:3.1: 9.6 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Summary
Multiple security vulnerabilities have been found in Chromium, a web browser used in IGEL OS. This affects the following product versions:
-
IGEL OS 12
-
IGEL OS 11
Details
Google reports multiple critical vulnerabilities, including a use-after-free in the Views component, which allows a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page (CVE-2026-17652). Further criticals are insufficient validation of untrusted input in ANGLE (CVE-2026-17655), a use-after-free in Ozone (CVE-2026-17656) and a use-after-free in Network (CVE-2026-15901).
Other issues are rated as critical by Google, but as high by other organizations such as CISA-ADP – a use-after-free in Skia (CVE-2026-17653) and another in Compositing (CVE-2026-17650).
Apart from this, there is an out-of-bounds write in Codecs (CVE-2026-16807, high), which may allow a remote attacker to perform a sandbox escape via a crafted HTML page, and insufficient validation of untrusted input in Print Preview (CVE-2026-17679, high).
In total, Google has fixed nearly 500 vulnerabilities. Details can be found in the References.
Update Instructions
-
OS 12: Upgrade the Chromium app to version 151.0.7922.71 or newer.
-
OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.
References
-
Chrome Releases Blog: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
-
Chrome Releases Blog https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html
-
Chrome Releases Blog: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html
-
Chrome Releases Blog: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html