ZeroHour

CVE-2026-93385

mass

Information Leak in Google Chrome Paint Component Prior to 153.0.8010.52

CVSS 3.1
6.5 medium
EPSS
Published
()
Modified
AI analysis

An information leak exists in the Paint component of Google Chrome that allows a remote attacker to obtain sensitive information by tricking a user into visiting a crafted HTML page. The flaw is classified as CWE-200 (Exposure of Sensitive Information) and carries a Medium severity rating from the Chromium security team. All users of Google Chrome prior to version 153.0.8010.52 are affected across the platforms on which Chrome ships. Successful exploitation yields access to sensitive information from the browser's rendering/painting process, but the flaw does not permit arbitrary code execution. No public proof-of-concept is known and the issue is not in CISA's KEV catalog; it was patched as one of 16 vulnerabilities in the Chrome 153.0.8010.52 release.

What to do: Update Google Chrome to version 153.0.8010.52 or later (check via chrome://settings/help or deploy the updated MSI/enterprise package). Because the flaw is triggered by a crafted HTML page, instruct users to avoid untrusted links until patching is complete. Note that the same release fixes 15 other issues including two critical vulnerabilities, so apply the 153.0.8010.52 update promptly and completely.

Affected
Google Chromeprior to 153.0.8010.52
Estimated exposure
mass≈1 billion+ users (Chrome is the world's dominant desktop browser with a multi-billion installed base) — Chrome is the most widely used browser globally with publicly reported market share of roughly 65% and over three billion users, so essentially every desktop/laptop estate not yet on 153.0.8010.52 is potentially affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.