Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-93373: Google Chrome extensions could let attacker run code
CVE-2026-93373 · published 11 days ago
Summary
Versions of Google Chrome before 153.0.8010.52 let a specially crafted browser extension cause the program to run code that should be blocked. This could let an attacker take control of the computer beyond the browser’s safety limits. Updating Chrome to the latest version removes the risk.
What to do
- Update google chrome to version 153.0.8010.52 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | chrome | < 153.0.8010.52 | |
| Debian:12 | debian | chromium | All versions |
Original advisory text
Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security sever...
Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
Severity
9.6
Critical
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published17 Sep 2026
Updated27 Sep 2026
First seen17 Sep 2026
Track software like this
Free during beta