AI analysis
CVE-2026-93387 is an improper state validation flaw in Skia, the graphics rendering library used by Google Chrome, affecting Chrome versions prior to 153.0.8010.52. An attacker triggers it by luring a victim to a crafted HTML page, which causes Skia to mishandle rendering state and break the same-origin policy. A successful attack allows a remote attacker to read cross-origin data from other sites the victim has open or authenticated to, potentially exposing sensitive page content, tokens, or account information. All Chrome users on pre-153 builds are affected, and the flaw was rated High severity by the Chromium team; Google shipped the fix in the Chrome 153 release alongside 15 other security fixes. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
What to do: Update Google Chrome to version 153.0.8010.52 or later immediately via chrome://settings/help, and confirm the patched version is reflected there after relaunch. Enterprise administrators should push the 153.0.8010.52 update through managed update policies (e.g., Google Admin console or MSI deployment) and audit endpoints for outdated builds. Until updated, exercise caution with untrusted links, as the flaw is triggered simply by loading a malicious web page.
Affected
| Google Chrome | all versions prior to 153.0.8010.52 |
Estimated exposure
mass≫1 billion users (Chrome's global install base; all pre-153.0.8010.52 builds affected) — Chrome is the world's dominant desktop browser with an estimated multi-billion-user install base, and every user who has not yet applied the 153.0.8010.52 update remains exposed to this client-side flaw triggered by web browsing.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.