First published 01 September 2026
CVSS:3.1: 9.6 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Summary
Multiple security vulnerabilities have been found in Chromium, a web browser used in IGEL OS. This affects the following product versions:
-
IGEL OS 12
-
IGEL OS 11
Details
Google reports a critical use-after-free vulnerability in Chromium’s Aura component (CVE-2026-19149). A user-after-free in Views is rated as critical by Google, but high by CISA-ADP (CVE-2026-19172). These issues allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Besides these, there is insufficient validation of untrusted input in Contextual Tasks (CVE-2026-19169, high) and an inappropriate implementation in the V8 JavaScript engine (CVE-2026-19168, high). V8 also contains a use-after-free (CVE-2026-19556, high).
Other user-after-free vulnerabilities have been discovered in Extensions (CVE-2026-19558, high), HTML (CVE-2026-19559, high) and Blink (CVE-2026-19560, high).
In total, Google reports more than 40 vulnerabilities. Full lists and details can be found in the References.
Update Instructions
-
OS 12: Upgrade the Chromium app to version 151.0.7922.137 from the IGEL APP Portal.
-
OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.