Bug 2542237

Summary: CVE-2026-93375 CVE-2026-93376 CVE-2026-93377 CVE-2026-93378 CVE-2026-93379 CVE-2026-93380 CVE-2026-93381 CVE-2026-93382 CVE-2026-93383 CVE-2026-93384 CVE-2026-93385 CVE-2026-93386 CVE-2026-93387 chromium: various flaws [epel-all]
Product: [Fedora] Fedora EPEL Reporter: Dhananjay Arunesh <darunesh>
Component: chromiumAssignee: Than Ngo <than>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: high    
Version: epel10CC: go-sig, pigpigman8686, spotrh, suraj.ghimire7, than, yaneti
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["a8b9c5d5-56a6-4b33-b692-88b44d9940cd", "50e80916-6cc4-4ea9-987a-007e5b1c33f2", "748d59d5-4099-469a-abe3-59fd0867340c", "66543314-2d7a-4983-b890-ea01e72da241", "4996b1e5-0aa1-4d9f-acd6-29b0a8f0ed28", "e6cfb1c7-db9c-4f0e-8159-d1208d5e7256", "d64e1910-5ad3-4755-bbd8-8e530dd09926", "7642e26d-17e7-418b-89ae-84c3a6810ddf", "23c53538-2cba-4f89-9f62-520597da73e5", "0541e29d-5277-4ade-8f10-fa3144783d6b", "a739afa9-2a2d-4424-bddf-b416f21b9eb5", "fc599ece-bbd2-466c-b6ab-a12ad991b947", "b749ab2f-e47a-43e1-80a1-3717dcade9a4"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-09-30 11:33:20 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2537875, 2537950, 2537955, 2537971, 2538010, 2538023, 2538195, 2538267, 2538286, 2538299, 2538482, 2538628, 2538948    

Description Dhananjay Arunesh 2026-09-27 22:29:49 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

Comment 1 Than Ngo 2026-09-30 11:33:20 UTC
Fixed in ERRATA - chromium-154.0.8037.57