Skip to content

Build1 publisher2 min readPublished

Two known-exploited Chromium V8 bugs lead September's 36 device CVEs beyond the kernel

TECH VEDA counts 36 actionable device CVEs across 14 non-kernel packages in September, two of them Chromium V8 bugs on CISA's exploited list. How many apply to a given fleet depends on each image's SBOM and on which scorer a team trusts.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Two known-exploited Chromium V8 bugs lead September's 36 device CVEs beyond the kernel
Generated illustration

What happened

  • Proof-of-concept code is public for one of the zlib issues, according to the report.
  • Most items have an upstream fix, but several exist only as commits or release candidates, and BusyBox has no upstream fix yet.
  • The largest groups of fixes landed in U-Boot's network boot code, the TLS libraries, libxml2 and Python.
  • OpenSSL's 29 September advisory adds CVE-2026-84783, a Moderate use-after-free in the X.509 extension cache that affects only 4.0 and is fixed in 4.0.3.
  • Twelve packages, including OpenSSH, systemd, runc and SQLite, were checked and had nothing that met the report's tests.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint The exploited-in-the-wild signal applies only to images that ship Chromium; for every other image, urgency rests on CVSS scores and reachability judgements.
  • contradiction A team that gates on CISA ADP scores would put curl's CVE-2026-82208 on its patch list at 7.5, while the curl project's Low rating keeps it off this one.
  • exposure EU manufacturers carry this list as a compliance input, since the Cyber Resilience Act requires them to keep an SBOM and handle known vulnerabilities in their products.
  • decision Where no release exists, teams choose between a distribution's patched package and cherry-picking the fix themselves, and either path ends in an image rebuild.

TECH VEDA's count comes from a filter the report states up front [1]. The monthly series covers the stack above the kernel in a shipped image: bootloader, C library, TLS libraries, media pipeline, language runtimes and container runtime [20]. An item makes the table if its CVSS base score is 7.0 or higher, if it is in CISA's Known Exploited Vulnerabilities catalog, or if it is clearly reachable in a normal device build [6]. Disputed issues and issues that need unusual build options are dropped. Kernel CVEs go to a separate weekly advisory [7]. The report does not compare September's total with kernel volume [7].

The most useful thing in the report is that it names the scorer for each item, because the first test depends on who did the scoring [10]. Projects, NVD and the CISA ADP do not always agree, and the report says so where the gap is large [10]. The GStreamer entry carries a Red Hat score. The GStreamer project says the flaw cannot cause code execution [13]. The Python entries use CVSS 4.0 only, and CVSS 4.0 tends to give higher numbers than CVSS 3.1 for the same flaw [14]. Five U-Boot CVEs were scored by the VulnCheck CNA, which also published them on 29 September. CISA added only exploitation and automation labels [11][2].

Reachability can override a score. The glibc strfmon bug, CVE-2026-19499, rates 7.7 from the glibc CNA [16]. It still stayed out. Exploiting it needs an application that passes an attacker-controlled format to strfmon. The CVE text says no network-facing impact is known, and the report could not confirm the fixed release [16].

The U-Boot item that needs the most care is CVE-2026-15390, rated 9.0 by the CERT-PL CNA [12]. Its record says the fix is in 2026.07 and also lists 2026.07 as affected [12]. The record manages to disagree with itself. A scanner that matches an SBOM's version string against that record will be wrong one way or the other, depending on which field it reads. The report says to take fix commit b1aec609 and not rely on the version number [12]. I think the commit hash is the right key for tracking this one.

Treat the 36 as a claim about a generic device build [1]. It carries over to a fleet only where an image ships the same packages, at affected versions, with the vulnerable code reachable in that build. The report states the same condition more briefly: which items matter depends on what is in the image and its software bill of materials [2].

What to watch

  • An upstream BusyBox fix, or distribution packages carrying one, would close the only item the report says has no upstream fix.
  • A corrected CVE-2026-15390 record that settles whether U-Boot 2026.07 is fixed or affected would let version-matching scanners handle it.
  • Whether CISA adds the zlib issue with public proof-of-concept code to its Known Exploited Vulnerabilities catalog.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories