
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-93384 is a Server-Side Request Forgery (SSRF) vulnerability in the Omnibox component of Google Chrome on Android. It allows a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. The vulnerability affects Google Chrome for Android versions prior to 153.0.8010.52 and was reported internally by Google on 2026-05-10, with public disclosure on September 17, 2026. It carries a Chromium security severity rating of Medium; no official CVSS base score has been published at this time (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and resides in Chrome's Omnibox (address bar) component on Android. An attacker can craft malicious network traffic that, when interacted with by a victim through social engineering (e.g., clicking a specially crafted link), causes the browser to issue server-side requests that bypass system access restrictions. Exploitation requires user interaction, as the attacker must convince the target to engage with the crafted content. The Chromium issue tracker reference is bug #511832293, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation allows an unauthenticated remote attacker to bypass system access restrictions on Android devices running vulnerable versions of Chrome. The primary impact is a security feature bypass, potentially enabling the attacker to make the browser issue requests to internal or restricted network resources that would otherwise be inaccessible. The vulnerability's scope is limited to Chrome on Android, and exploitation requires social engineering, reducing but not eliminating real-world risk (GitHub Advisory, Chrome Releases).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to induce user interaction, which raises the bar for opportunistic attacks. No threat actor attribution has been reported (GitHub Advisory).
Google has released a patch in Chrome version 153.0.8010.52 for Android (and 153.0.8010.52/.53 for Windows/Mac/Linux), published September 17, 2026. Users should update Google Chrome on Android to version 153.0.8010.52 or later immediately. As a behavioral mitigation, users should be educated to avoid clicking suspicious or unsolicited links, since exploitation requires social engineering and user interaction (Chrome Releases).
Coverage of this vulnerability has been limited to standard vulnerability tracking and aggregation sites. GBHackers reported on the broader Chrome 153 update that addressed 16 security flaws, including CVE-2026-93384, but no notable independent researcher commentary or significant community discussion has been identified specific to this CVE.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."