Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 42: CEF High CVE-2026-0628 Insufficient Policy Enforcement Advisory

fedora
Calendar Grey January 21, 2026
Dist Fedora Esm H88
Fedora 42 has a high-severity update for cef addressing insufficient policy enforcement in WebView tag. Critical fix available.
Update to 143.0.7499.192 [rhbz#2427842] * High CVE-2026-0628: Insufficient policy enforcement in WebView tag

Summary

CEF is an embeddable build of Chromium, powered by WebKit (Blink).

Update Information:

Update to 143.0.7499.192 [rhbz#2427842] * High CVE-2026-0628: Insufficient policy enforcement in WebView tag

Change Log

* Fri Jan 9 2026 Than Ngo - 143.0.13^chromium143.0.7499.192-1 - Update to 143.0.7499.192 [rhbz#2427842] - * High CVE-2026-0628: Insufficient policy enforcement in WebView tag - Fix rhbz#2425338, Enable control flow integrity support for x86_64/aarch64 - Enable build for epel10.1

References


[ 1 ] Bug #2427842 - cef-143.0.14 is available https://bugzilla.redhat.com/show_bug.cgi?id=2427842

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2a94cc43d9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: cef
Product: Fedora 42
Version: 143.0.13^chromium143.0.7499.192
Release: 1.fc42
Summary: Chromium Embedded Framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here