Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 43 chromium Update Heap Overflow Type Confusion CVE-2026-1861

fedora
Calendar Grey February 8, 2026
Dist Fedora Esm H88
Explore Fedora 43's update for chromium addressing critical heap overflow and type confusion issues. Your safety matters!
Update to 144.0.7559.132 * CVE-2026-1861: Heap buffer overflow in libvpx * CVE-2026-1862: Type Confusion in V8

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update Information:

Update to 144.0.7559.132 * CVE-2026-1861: Heap buffer overflow in libvpx * CVE-2026-1862: Type Confusion in V8

Change Log

* Thu Feb 5 2026 Than Ngo - 144.0.7559.132-1 - Update to 144.0.7559.132 * CVE-2026-1861: Heap buffer overflow in libvpx * CVE-2026-1862: Type Confusion in V8 - Add BR on esbuild - Disable devtool bundle - Update scripts for downloading the source

References


[ 1 ] Bug #2436627 - CVE-2026-1861 chromium: Chromium: Arbitrary code execution via crafted HTML page [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2436627 [ 2 ] Bug #2436628 - CVE-2026-1861 chromium: Chromium: Arbitrary code execution via crafted HTML page [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2436628 [ 3 ] Bug #2436629 - CVE-2026-1862 chromium: Chromium: Remote heap corruption via crafted HTML page [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2436629 [ 4 ] Bug #2436630 - CVE-2026-1862 chromium: Chromium: Remote heap corruption via crafted HTML page [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2436630

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-db342a4417' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: chromium
Product: Fedora 43
Version: 144.0.7559.132
Release: 1.fc43
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here