Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-93374: Chrome for Android may run malicious code
CVE-2026-93374 · published 3 days ago
Summary
Google Chrome on Android versions before 153.0.8010.52 can be tricked by a specially crafted web page to run code outside its normal safety sandbox. This could let an attacker take control of the device or access data. Update Chrome to the latest version to protect against this risk.
What to do
- Update google chrome to version 153.0.8010.52 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | chrome | < 153.0.8010.52 | |
| Debian:12 | debian | chromium | All versions |
Original advisory text
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s...
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Severity
9.6
Critical
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published17 Sep 2026
Updated19 Sep 2026
First seen17 Sep 2026
Track software like this
Free during beta