ZeroHour

CVE-2026-93387

mass

Cross-Origin Data Leak via Improper State Validation in Google Chrome Skia

CVSS 3.1
4.3 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-93387 is an improper state validation flaw in Skia, the graphics rendering library used by Google Chrome, affecting Chrome versions prior to 153.0.8010.52. An attacker triggers it by luring a victim to a crafted HTML page, which causes Skia to mishandle rendering state and break the same-origin policy. A successful attack allows a remote attacker to read cross-origin data from other sites the victim has open or authenticated to, potentially exposing sensitive page content, tokens, or account information. All Chrome users on pre-153 builds are affected, and the flaw was rated High severity by the Chromium team; Google shipped the fix in the Chrome 153 release alongside 15 other security fixes. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.

What to do: Update Google Chrome to version 153.0.8010.52 or later immediately via chrome://settings/help, and confirm the patched version is reflected there after relaunch. Enterprise administrators should push the 153.0.8010.52 update through managed update policies (e.g., Google Admin console or MSI deployment) and audit endpoints for outdated builds. Until updated, exercise caution with untrusted links, as the flaw is triggered simply by loading a malicious web page.

Affected
Google Chromeall versions prior to 153.0.8010.52
Estimated exposure
mass≫1 billion users (Chrome's global install base; all pre-153.0.8010.52 builds affected) — Chrome is the world's dominant desktop browser with an estimated multi-billion-user install base, and every user who has not yet applied the 153.0.8010.52 update remains exposed to this client-side flaw triggered by web browsing.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Weakness
CWE-754
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.