AI analysis
CVE-2026-93376 is an out-of-bounds read (CWE-125) in the DataTransfer component of Google Chrome, fixed in version 153.0.8010.52. A local attacker must use social engineering to convince a user to run a local program, which then interacts with Chrome in a way that reads memory outside the browser sandbox. Successful exploitation yields disclosure of memory contents from outside the sandbox, an information-exposure issue rather than code execution, and Chromium rates it Medium severity. All users running Chrome versions prior to 153.0.8010.52 are affected, and the fix shipped as part of the Chrome 153 release that addressed 16 security flaws, including two critical ones. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported.
What to do: Update Google Chrome to 153.0.8010.52 or later and confirm the version via the browser's About/Help page, refreshing the update if needed. Because exploitation requires a local program and social engineering, exercise caution when running untrusted local executables. No interim mitigations are required beyond patching.
Affected
| Google Chrome | prior to 153.0.8010.52 |
Estimated exposure
mass≈3 billion+ Chrome users (Chrome's global installed base) — Chrome's publicly documented worldwide user base exceeds three billion, and all installs on versions before 153.0.8010.52 remain affected until updated, though actual risk is limited by the local, social-engineering-based attack vector.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.