AI analysis
CVE-2026-93382 is a use-after-free (CWE-416) memory-safety flaw in PDFium, the PDF rendering engine embedded in Google Chrome. A remote attacker can trigger it by luring a user to a specially crafted HTML page, causing Chrome's PDF component to access freed memory. Successful exploitation lets the attacker execute arbitrary code inside the Chrome sandbox, which constrains the damage but still constitutes a serious compromise of the renderer process. All Chrome users running a version prior to 153.0.8010.52 are affected; the fix shipped in the Chrome 153 release, which addressed 16 security issues including two critical ones. There is currently no evidence of exploitation in the wild, no CISA KEV listing, and no known public proof-of-concept.
What to do: Update Google Chrome to 153.0.8010.52 or later immediately (check via chrome://settings/help or relaunch the browser to trigger auto-update), and verify the version on shared or managed machines. Enterprise administrators should push the update via their endpoint management tools and consider policies that force browser restarts after update. As an interim mitigation, avoid opening untrusted PDF content and exercise caution with unfamiliar web pages until browsers are patched.
Affected
| Google Chrome | All versions prior to 153.0.8010.52 |
Estimated exposure
massbillions of Chrome users/installs (all Chrome users on pre-153.0.8010.52 builds until auto-update completes) — Chrome holds the largest global browser market share with a user base measured in the billions across desktop and mobile, and every installation not yet updated to 153.0.8010.52 is vulnerable, though Chrome's automatic update mechanism…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.