Security Advisory – March, 2026: Chromium WebView Component Updated to M138 (Cumulative Security Fixes)
Advisory ID: NEAT-SA-2025-03-21-3
Publication date: March 21, 2026
Last updated: March 21, 2026
Severity: Not independently scored by Neat
CVSS vector: Not applicable — see individual CVEs in the referenced Chrome Releases security bulletin
CVE ID: Multiple — corresponds to the CVEs fixed in the Chromium versions between the prior embedded build and M138. Confirm the specific version range with engineering.
Summary
Neat devices embed a Chromium WebView component used for web-based features including Direct Guest Join. With the NeatOS 25.4.2 Stable release, this component was upgraded to Chromium M138. Neat’s release notes describe this as including “a large number of security, performance, and compatibility improvements from the upstream Chromium project,” without introducing Neat-specific functional changes.
Affected Products
| Product | Affected versions | Fixed version |
| All Neat devices (25.4.2 release notes describe this update as applying broadly) | NeatOS releases with Chromium WebView builds prior to M138 | NeatOS 25.4.2 (Chromium WebView M138) |
Impact
Impact varies by individual CVE; Chromium security fixes commonly address memory-safety issues (e.g., use-after-free, heap buffer overflow) that can lead to code execution or information disclosure when the browser engine processes malicious web content. See the Chrome Releases security bulletin for the relevant version range for specifics.
Details
Neat’s Chromium WebView component renders web content for certain in-device features (for example, Direct Guest Join). Because this is a third-party, upstream-maintained component, Neat’s primary remediation path for Chromium vulnerabilities is to update the embedded WebView version, similar to how the October 2023 WebP/libwebp advisory (CVE-2023-4863) was addressed via a Chromium update coordinated with Microsoft.
Remediation
Update to NeatOS 25.4.2, which includes Chromium WebView M138. Devices configured for automatic updates on the Stable channel should already be running this version or later.
Acknowledgements
Not applicable — patches originate from the upstream Chromium project, not an external report to Neat.
References
Contact
Questions about this advisory can be directed to security@neat.no.