AI analysis
CVE-2026-93381 is a buffer overflow (CWE-122) in the PDFium PDF rendering engine of Google Chrome on Windows. To trigger it, an attacker must use social engineering to convince a user to open a specially crafted PDF file, which causes the overflow in Chrome's PDF renderer. Successful exploitation could allow a remote attacker to execute arbitrary code, though only inside Chrome's sandbox, which constrains the impact of the compromise. All Chrome users on Windows running versions prior to 153.0.8010.52 are affected; users on other operating systems are not impacted by this specific flaw. There is currently no CVSS score, no entry in the CISA KEV catalog, no known public proof-of-concept, and no confirmed exploitation in the wild, and the fix shipped in Chrome 153.0.8010.52 alongside roughly 15 other security fixes, including two rated critical.
What to do: Update Google Chrome on Windows to 153.0.8010.52 or later (Help > About Google Chrome, or enforce via endpoint management) and verify deployed versions with your fleet inventory tools. Until patched, caution users against opening PDFs from untrusted or unexpected sources, since exploitation depends on social engineering. Prioritize the update, as the same Chrome 153 release also addresses two critical vulnerabilities.
Affected
| Google Chrome (PDFium component) | Windows versions prior to 153.0.8010.52 |
Estimated exposure
mass≈3 billion+ Chrome users worldwide, with the Windows desktop subset affected (likely well over 1 billion installations) — Chrome holds roughly 65% of global browser market share with more than 3 billion users, and since this flaw affects only the Windows build, the affected install base is still the Windows portion of that very large population.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.