English German

ISN 2026-41: Critical Chromium Vulnerabilities

First published 5 October 2026 (Pre-Notification)

CVSS:3.1: 9.6 (Critical)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Summary

Security vulnerabilities have been found in Chromium, a web browser used in IGEL OS. This affects the following product versions:

  • IGEL OS 12

  • IGEL OS 11

Details

Google has announced multiple vulnerabilities in Chromium, out of which 16 are rated critical by sources such as CISA-ADP. Among them are use-after-free issues in Views (CVE-2026-95277), AdFilter (CVE-2026-95310), and Fullscreen (CVE-2026-95313). Buffer Overflows affect the components ANGLE (CVE-2026-95281), Tint (CVE-2026-95283), Video (CVE-2026-95318), and WebGL (CVE-2026-95349). These allow a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.

In addition to these, there are many findings rated high, for example improper input validation in Themes (CVE-2026-95276), out-of-bounds writes in GPU (CVE-2026-95322) and in Desktop (CVE-2026-95341), and a type confusion in V8 (CVE-2026-95380).

In total, more than 100 vulnerabilities have been addressed. A full list and details can be found in the References.

Update Instructions

  • OS 12: Upgrade the Chromium app to version 154.0.8037.57 as soon as it is available on the IGEL APP Portal.

  • OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.

References

Chrome Releases Blog: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html