ZeroHour

CVE-2026-93376

mass

Out-of-Bounds Read in Google Chrome DataTransfer Prior to 153.0.8010.52

CVSS 3.1
6.3 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-93376 is an out-of-bounds read (CWE-125) in the DataTransfer component of Google Chrome, fixed in version 153.0.8010.52. A local attacker must use social engineering to convince a user to run a local program, which then interacts with Chrome in a way that reads memory outside the browser sandbox. Successful exploitation yields disclosure of memory contents from outside the sandbox, an information-exposure issue rather than code execution, and Chromium rates it Medium severity. All users running Chrome versions prior to 153.0.8010.52 are affected, and the fix shipped as part of the Chrome 153 release that addressed 16 security flaws, including two critical ones. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported.

What to do: Update Google Chrome to 153.0.8010.52 or later and confirm the version via the browser's About/Help page, refreshing the update if needed. Because exploitation requires a local program and social engineering, exercise caution when running untrusted local executables. No interim mitigations are required beyond patching.

Affected
Google Chromeprior to 153.0.8010.52
Estimated exposure
mass≈3 billion+ Chrome users (Chrome's global installed base) — Chrome's publicly documented worldwide user base exceeds three billion, and all installs on versions before 153.0.8010.52 remain affected until updated, though actual risk is limited by the local, social-engineering-based attack vector.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)

Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.