ZeroHour

CVE-2026-93383

mass

Cross-Origin Information Leak via Permissions in Google Chrome Before 153.0.8010.52

CVSS 3.1
4.3 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-93383 is an information disclosure flaw (CWE-200) in the Permissions component of Google Chrome, fixed in version 153.0.8010.52. A remote attacker can trigger the flaw by luring a user to a specially crafted HTML page, which causes the browser to leak data from cross-origin sites in violation of the same-origin policy. An attacker gains access to content or data from other origins that the victim's browser has access to, potentially including sensitive page content from other sites. All users of Google Chrome versions prior to 153.0.8010.52 are affected. No public proof-of-concept is known, the issue is not listed in CISA's KEV catalog, and exploitation has not been confirmed in the wild.

What to do: Update Google Chrome to version 153.0.8010.52 or later (verify via chrome://settings/help or chrome://version) and restart the browser to complete the update; ensure automatic updates are enabled for managed fleets. As interim mitigation, exercise caution with untrusted websites, since exploitation requires rendering a crafted HTML page. Treat this as a medium-severity, low-friction patch and roll it out with the regular Chrome 153 update cycle, which also addresses two critical vulnerabilities.

Affected
Google Chromeall versions prior to 153.0.8010.52
Estimated exposure
massbillions of Chrome installations (Chrome's global user base exceeds 3 billion), though the auto-updating stable channel shrinks the vulnerable population… — Chrome is the world's dominant desktop browser with billions of users, so effectively the entire Chrome installed base on versions before 153.0.8010.52 is potentially affected; the flaw is triggered client-side by visiting a crafted page…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.