Fedora has issued security updates for the Chromium Embedded Framework on both Fedora 43 and 44, bumping the packages to version 145.0.28 with chromium 145.0.7632.159 and addressing a range of CVEs that include integer overflows in ANGLE, Skia and V8, as well as heap buffer overflows in PDFium, WebCodecs and Media. The cef updates also note changes such as the adoption of C++20 for libcef and link to Bug #2437035 for more details. In addition, Fedora 43 received a patch for Vim 9.2.112 that fixes multiple CVEs (CVE‑2026‑28417 through CVE‑2026‑28422) involving command injection, buffer overflows and information disclosure in plugins and terminal handling, and users can apply these advisories with the dnf command dnf upgrade --advisory; all packages are signed with the Fedora Project GPG key.
Fedora 43 Update: cef-145.0.28^chromium145.0.7632.159-1.fc43
Fedora 43 Update: vim-9.2.112-2.fc43
Fedora 44 Update: cef-145.0.28^chromium145.0.7632.159-1.fc44