Aggiornamento di Sicurezza per ChromeOS Long-Term Channel
Google ha rilasciato ChromeOS LTC 144.0.7559.246 per la maggior parte dei dispositivi Long-Term Channel. L'aggiornamento include due fix High: CVE-2026-3909 (Skia out-of-bounds write) e CVE-2026-3910 (V8 inappropriate implementation).
CVSS 8.8 HIGH: inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 0.4% (33º percentile). Patch Microsoft: Release Notes.
CVSS 9.6 CRITICAL: insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. EPSS 0.3% (23º percentile). Patch Microsoft: Release Notes.
CVSS 8.8 HIGH: inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. EPSS 0.3% (22º percentile). Patch Microsoft: Release Notes.