Bug 2531788

Summary: CVE-2026-84324 CVE-2026-84325 CVE-2026-84327 CVE-2026-84329 CVE-2026-84330 CVE-2026-84331 CVE-2026-84332 CVE-2026-84333 CVE-2026-84347 CVE-2026-84348 CVE-2026-84350 CVE-2026-84352 CVE-2026-84353 CVE-2026-84354 ... chromium: various flaws [epel-all]
Product: [Fedora] Fedora EPEL Reporter: Dhananjay Arunesh <darunesh>
Component: chromiumAssignee: Than Ngo <than>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: urgent Docs Contact:
Priority: urgent    
Version: epel10CC: go-sig, pigpigman8686, spotrh, suraj.ghimire7, than, yaneti
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["900e412a-5509-4782-aa13-04e2f42770a6", "5ce7f686-846e-4f6e-b919-cce193823bc2", "c8b0a978-e135-4b29-874a-43fb6058623a", "606429c3-dada-4e91-893f-0d051cd0414b", "6ac54d1d-f1a3-484b-afaf-bd225ae70452", "96d91d43-4085-434e-9dec-01c3150b5d77", "6905dc37-4d3c-42dd-9f72-f9528078dec6", "6d3f5dc4-7e2e-4903-b9dc-2c3d9ca0819e", "7e1f5e8b-fab6-47e7-81d8-220b54a07d16", "ea678081-00b5-4a98-b2bf-b834a66ad7ea", "9ee9026d-acfb-487d-8318-7eb3bebce7be", "20806770-a027-40ad-9181-2c717a469dbf", "d08c7d39-91be-4a91-a79b-3905a1750417", "dde50564-e3a1-4e4a-9aa1-e7aea0a884ff", "b321fb91-45a4-450b-8ca9-c21857fef853"]}
Fixed In Version: chromium-153.0.8010.36-1.fc44 chromium-153.0.8010.36-1.fc45 chromium-153.0.8010.36-1.el10_3 chromium-153.0.8010.36-1.el10_4 chromium-153.0.8010.36-1.fc43 chromium-153.0.8010.36-1.el10_2 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-09-18 01:16:49 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2527158, 2527159, 2527161, 2527164, 2527166, 2527167, 2527168, 2527169, 2527172, 2527173, 2527176, 2527177, 2527178, 2527181, 2527182    

Description Dhananjay Arunesh 2026-09-11 07:45:23 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Comment 1 Fedora Update System 2026-09-17 06:19:25 UTC
FEDORA-EPEL-2026-d7f643de0b (chromium-153.0.8010.36-1.el10_4) has been submitted as an update to Fedora EPEL 10.4.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-d7f643de0b

Comment 2 Fedora Update System 2026-09-17 06:19:34 UTC
FEDORA-2026-6932094a69 (chromium-153.0.8010.36-1.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-6932094a69

Comment 3 Fedora Update System 2026-09-17 06:19:42 UTC
FEDORA-EPEL-2026-eeb82ef938 (chromium-153.0.8010.36-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-eeb82ef938

Comment 4 Fedora Update System 2026-09-17 06:19:50 UTC
FEDORA-2026-441ccd8509 (chromium-153.0.8010.36-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-441ccd8509

Comment 5 Fedora Update System 2026-09-18 01:16:49 UTC
FEDORA-2026-441ccd8509 (chromium-153.0.8010.36-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 6 Fedora Update System 2026-09-18 01:33:02 UTC
FEDORA-2026-a1a12d9b4f has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-a1a12d9b4f`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-a1a12d9b4f

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2026-09-18 01:44:10 UTC
FEDORA-EPEL-2026-dff966929c has been pushed to the Fedora EPEL 10.2 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-dff966929c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 8 Fedora Update System 2026-09-18 01:51:37 UTC
FEDORA-EPEL-2026-d7f643de0b has been pushed to the Fedora EPEL 10.4 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-d7f643de0b

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 9 Fedora Update System 2026-09-18 01:58:01 UTC
FEDORA-EPEL-2026-eeb82ef938 has been pushed to the Fedora EPEL 10.3 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-eeb82ef938

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 10 Fedora Update System 2026-09-18 01:58:12 UTC
FEDORA-2026-6932094a69 has been pushed to the Fedora 45 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-6932094a69`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-6932094a69

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 11 Fedora Update System 2026-09-19 00:17:28 UTC
FEDORA-2026-6932094a69 (chromium-153.0.8010.36-1.fc45) has been pushed to the Fedora 45 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 12 Fedora Update System 2026-09-19 00:31:23 UTC
FEDORA-EPEL-2026-eeb82ef938 (chromium-153.0.8010.36-1.el10_3) has been pushed to the Fedora EPEL 10.3 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 13 Fedora Update System 2026-09-19 00:43:13 UTC
FEDORA-EPEL-2026-d7f643de0b (chromium-153.0.8010.36-1.el10_4) has been pushed to the Fedora EPEL 10.4 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 14 Fedora Update System 2026-09-19 00:58:31 UTC
FEDORA-2026-a1a12d9b4f (chromium-153.0.8010.36-1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 15 Fedora Update System 2026-09-19 01:00:25 UTC
FEDORA-EPEL-2026-dff966929c (chromium-153.0.8010.36-1.el10_2) has been pushed to the Fedora EPEL 10.2 stable repository.
If problem still persists, please make note of it in this bug report.