ZeroHour

CVE-2026-93384

mass

Server-Side Request Forgery in Omnibox in Google Chrome for Android

CVSS 3.1
3.7 low
EPSS
Published
()
Modified
AI analysis

CVE-2026-93384 is a server-side request forgery (SSRF) flaw in the Omnibox (address bar) component of Google Chrome running on Android. It can be triggered by a remote attacker who uses social engineering to induce user actions, causing the browser to send crafted network traffic that bypasses system access restrictions. A successful exploit lets the attacker reach resources or services that should be blocked by those restrictions, though the Medium Chromium severity and social-engineering requirement limit the practical impact. Only Chrome on Android is named in the advisory; affected versions are those prior to 153.0.8010.52. There are no reports of exploitation in the wild, no public proof of concept, and the flaw is not listed in CISA's KEV; the fix shipped in Chrome 153.0.8010.52, which addresses 16 security flaws in total, including two critical ones.

What to do: Update Chrome on Android to version 153.0.8010.52 or later via Google Play (Settings > About Chrome > check for updates) and relaunch the browser. Given the Medium severity and social-engineering prerequisite, this is not an emergency patch, but applying it promptly also picks up the two critical fixes in the same Chrome 153 release. Desktop and other Chrome builds should still be kept current per Google's regular update channel.

Affected
Google Chrome (Android)prior to 153.0.8010.52
Estimated exposure
massbillions of users (Chrome is the dominant browser on Android, which has 3B+ active devices) — Chrome holds roughly 60%+ of the mobile browser market and ships as the default browser on Android's 3B+ active devices, so nearly all Chrome-for-Android installs below 153.0.8010.52 are plausibly affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.