ISN 2026-32: Critical Chromium Vulnerabilities

First published 5 August 2026

CVSS:3.1: 9.6 (Critical)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Summary

Multiple security vulnerabilities have been found in Chromium, a web browser used in IGEL OS. This affects the following product versions:

  • IGEL OS 12

  • IGEL OS 11

Details

Google reports multiple critical vulnerabilities, including a use-after-free in the Views component, which allows a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page (CVE-2026-17652). Further criticals are insufficient validation of untrusted input in ANGLE (CVE-2026-17655), a use-after-free in Ozone (CVE-2026-17656) and a use-after-free in Network (CVE-2026-15901).

Other issues are rated as critical by Google, but as high by other organizations such as CISA-ADP – a use-after-free in Skia (CVE-2026-17653) and another in Compositing (CVE-2026-17650).

Apart from this, there is an out-of-bounds write in Codecs (CVE-2026-16807, high), which may allow a remote attacker to perform a sandbox escape via a crafted HTML page, and insufficient validation of untrusted input in Print Preview (CVE-2026-17679, high).

In total, Google has fixed nearly 500 vulnerabilities. Details can be found in the References.

Update Instructions

  • OS 12: Upgrade the Chromium app to version 151.0.7922.71 or newer.

  • OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.

References