ZeroHour

CVE-2026-93373

mass

Use-after-free in Google Chrome Extensions Enables Sandbox-Escape Code Execution

CVSS 3.1
9.6 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-93373 is a use-after-free memory corruption bug (CWE-416) in the Extensions component of Google Chrome. An attacker can trigger it by getting a user to load a crafted Chrome extension, which frees memory that is subsequently reused. Successful exploitation allows a remote attacker to execute arbitrary code outside the browser's sandbox, meaning the code escapes Chrome's strongest isolation layer and runs with broader system privileges. All Chrome users running versions prior to 153.0.8010.52 are affected, and Google has patched the flaw in that release as part of an update fixing 16 security issues, including two critical vulnerabilities. There is currently no evidence of exploitation in the wild, no CISA KEV listing, and no known public proof-of-concept.

What to do: Update Google Chrome to 153.0.8010.52 or later on all platforms (check via chrome://settings/help) and restart the browser to complete the fix. Enterprises should enforce minimum-version compliance via endpoint management, audit installed extensions and remove unvetted ones, and treat extension installation as the primary attack vector until systems are patched.

Affected
Google Chromeall versions prior to 153.0.8010.52
Estimated exposure
mass≈3+ billion Chrome installs potentially affected before patching (Chrome's global user base), though exploitation requires delivery of a crafted extension — Chrome is the world's dominant desktop browser with an estimated 3 billion-plus users, and the flaw affects every release prior to the 153.0.8010.52 fix, although most users auto-update within days of release.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.