ZeroHour

CVE-2026-93374

mass

Use-After-Free in Dawn (WebGPU) in Chrome for Android Enables Sandbox-Escape RCE

CVSS 3.1
9.6 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-93374 is a use-after-free memory-corruption flaw in Dawn, the WebGPU component of Google Chrome, affecting Chrome on Android prior to version 153.0.8010.52. An attacker can trigger it remotely by convincing a user to open a specially crafted HTML page. Successful exploitation could allow arbitrary code execution outside the browser's security sandbox, which is a severe outcome because it escapes Chrome's core containment mechanism. All users of Chrome for Android on unpatched versions are affected; Google rates the flaw Critical and shipped the fix in Chrome 153, which patched 16 vulnerabilities including two critical ones. No public proof-of-concept or confirmed in-the-wild exploitation is currently known, and the issue is not yet on CISA's KEV list.

What to do: Update Chrome for Android to 153.0.8010.52 or later via the Google Play Store (check the actual version at chrome://version, as Play Store rollout can lag). Enable automatic Chrome updates and avoid untrusted web pages until updated; desktop Chrome users should also apply the Chrome 153 update, which addresses 16 flaws in the same release.

Affected
Google Chrome for Android (Dawn/WebGPU component)All versions prior to 153.0.8010.52
Estimated exposure
mass≫1 billion users (Chrome for Android is the default/dominant browser on Android devices worldwide) — Chrome on Android is the most widely used mobile browser, with Google citing over 3 billion Chrome users overall and Android Chrome holding the majority of global mobile browser share, so essentially every unpatched Android device running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.