First published 14 September 2026 (Pre-Notification)
CVSS:3.1: 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Summary
Security vulnerabilities have been found in the Chromium web browser used in IGEL OS. This affects the following product versions:
-
IGEL OS 12
-
IGEL OS 11
Details
A type confusion has been found in Chromium’s JavaScript engine V8 (CVE-2026-85046). It allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page and is rated high. Google is aware that an exploit for this issue exists in the wild, and CISA has added the CVE to its Known Exploited Vulnerabilities Catalog (KEV).
Incorrect authorization in the FileSystem component can allow a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox (CVE-2026-84354). This is rated as high by Google, but as critical by CISA-ADP.
V8 is affected by a race condition that could enable command execution (CVE-2026-85045, high). An out-of-bounds read has been discovered in the CrashReporting component (CVE-2026-85052, high), and an out-of-bounds write in WebGL (CVE-2026-85050, high).
In total, more than 40 security issues have been reported. Full lists and details are available in the References.
Update Instructions
-
IGEL OS 12: Upgrade the Chromium app to 152.0.7977.82 as soon as it is available on the IGEL APP Portal
. -
IGEL OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.
References
-
Chrome Releases Blog: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
-
Chrome Releases Blog: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
-
CISA Known Exploited Vulnerabilities Catalog (KEV): https://www.cisa.gov/known-exploited-vulnerabilities-catalog