AI analysis
CVE-2026-93373 is a use-after-free memory corruption bug (CWE-416) in the Extensions component of Google Chrome. An attacker can trigger it by getting a user to load a crafted Chrome extension, which frees memory that is subsequently reused. Successful exploitation allows a remote attacker to execute arbitrary code outside the browser's sandbox, meaning the code escapes Chrome's strongest isolation layer and runs with broader system privileges. All Chrome users running versions prior to 153.0.8010.52 are affected, and Google has patched the flaw in that release as part of an update fixing 16 security issues, including two critical vulnerabilities. There is currently no evidence of exploitation in the wild, no CISA KEV listing, and no known public proof-of-concept.
What to do: Update Google Chrome to 153.0.8010.52 or later on all platforms (check via chrome://settings/help) and restart the browser to complete the fix. Enterprises should enforce minimum-version compliance via endpoint management, audit installed extensions and remove unvetted ones, and treat extension installation as the primary attack vector until systems are patched.
Affected
| Google Chrome | all versions prior to 153.0.8010.52 |
Estimated exposure
mass≈3+ billion Chrome installs potentially affected before patching (Chrome's global user base), though exploitation requires delivery of a crafted extension — Chrome is the world's dominant desktop browser with an estimated 3 billion-plus users, and the flaw affects every release prior to the 153.0.8010.52 fix, although most users auto-update within days of release.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.