
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-93385 is an information leak vulnerability in the Paint component of Google Chrome that allows a remote attacker to obtain sensitive information via a crafted HTML page. It affects all versions of Google Chrome prior to 153.0.8010.52 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on 2026-08-26 and publicly disclosed on September 17, 2026, alongside a stable channel update. It carries a Chromium security severity rating of Medium, with an EPSS score of 0.0 (Chrome Releases, Feedly).
The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and resides in Chrome's Paint component, which is responsible for rendering web content. An unauthenticated remote attacker can exploit this flaw by luring a victim to visit a specially crafted HTML page, which triggers a memory disclosure condition within the Paint subsystem. The bug was tracked internally as Chromium issue 553136980 and detected using Google's internal security tooling. No public technical write-up or proof-of-concept code has been released (Chrome Releases, Feedly).
Successful exploitation results in a confidentiality breach, allowing a remote attacker to read sensitive information from the Chrome Paint component's memory without user authentication beyond visiting a malicious page. The impact is limited to information disclosure — there is no evidence of integrity or availability impact associated with this vulnerability. The exposed data could potentially include rendered content, memory addresses, or other browser-internal state, though the exact nature of the leaked information has not been publicly detailed (Feedly, Chrome Releases).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability has an EPSS score of 0.0 and is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires only that a victim visit a crafted HTML page, making the attack vector network-based with no authentication required, but the medium severity rating and lack of code execution impact reduce its attractiveness to threat actors (Feedly).
Google has released a patch in Chrome stable channel version 153.0.8010.52 (Linux) and 153.0.8010.52/.53 (Windows and Mac), which addresses this vulnerability along with 15 other security fixes. Users should update Google Chrome to version 153.0.8010.52 or later immediately by navigating to chrome://settings/help or enabling automatic updates. As a temporary precaution prior to patching, users should avoid visiting untrusted or unknown websites (Chrome Releases).
GBHackers reported on the broader Chrome 153 update, noting it addressed 16 security flaws including CVE-2026-93385. No notable independent researcher commentary or significant social media discussion specific to this vulnerability has been observed, consistent with its medium severity rating and lack of public exploit code (GBHackers).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."