Chromium sandbox escape and glibc nscd overflow
Two advisories reached oss-security on 2026-09-11, covering a critical Chromium remote code execution bug and a narrower GNU C Library flaw. Both affect widely deployed components that developers and distributions track closely.
Chromium use-after-free RCE outside sandbox
A use-after-free in Chromium WebGL, tracked as CVE-2026-87464, allows remote code execution outside the sandbox in versions prior to 153.0.8010.36. The issue was disclosed on oss-security. Browser maintainers and anyone shipping Chromium-based software need the fixed release because the flaw bypasses the usual process isolation boundary.
Glibc nscd stack overflow via DNS
The GNU C Library security advisory update for 2026-09-10 reports a stack overflow in nscd triggered by large DNS responses under narrow conditions. The disclosure appeared on oss-security. Systems that run the name service cache daemon should review the advisory and apply the update where the constrained trigger conditions apply.