Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-93385
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-93385 is an information leak vulnerability in the Paint component of Google Chrome that allows a remote attacker to obtain sensitive information via a crafted HTML page. It affects all versions of Google Chrome prior to 153.0.8010.52 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on 2026-08-26 and publicly disclosed on September 17, 2026, alongside a stable channel update. It carries a Chromium security severity rating of Medium, with an EPSS score of 0.0 (Chrome Releases, Feedly).

Technical details

The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and resides in Chrome's Paint component, which is responsible for rendering web content. An unauthenticated remote attacker can exploit this flaw by luring a victim to visit a specially crafted HTML page, which triggers a memory disclosure condition within the Paint subsystem. The bug was tracked internally as Chromium issue 553136980 and detected using Google's internal security tooling. No public technical write-up or proof-of-concept code has been released (Chrome Releases, Feedly).

Impact

Successful exploitation results in a confidentiality breach, allowing a remote attacker to read sensitive information from the Chrome Paint component's memory without user authentication beyond visiting a malicious page. The impact is limited to information disclosure — there is no evidence of integrity or availability impact associated with this vulnerability. The exposed data could potentially include rendered content, memory addresses, or other browser-internal state, though the exact nature of the leaked information has not been publicly detailed (Feedly, Chrome Releases).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability has an EPSS score of 0.0 and is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires only that a victim visit a crafted HTML page, making the attack vector network-based with no authentication required, but the medium severity rating and lack of code execution impact reduce its attractiveness to threat actors (Feedly).

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 153.0.8010.52 (Linux) and 153.0.8010.52/.53 (Windows and Mac), which addresses this vulnerability along with 15 other security fixes. Users should update Google Chrome to version 153.0.8010.52 or later immediately by navigating to chrome://settings/help or enabling automatic updates. As a temporary precaution prior to patching, users should avoid visiting untrusted or unknown websites (Chrome Releases).

Community reactions

GBHackers reported on the broader Chrome 153 update, noting it addressed 16 security flaws including CVE-2026-93385. No notable independent researcher commentary or significant social media discussion specific to this vulnerability has been observed, consistent with its medium severity rating and lack of public exploit code (GBHackers).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium

Affected

sid

chromium: 153.0.8010.52-1

Fixed

trixie

chromium: 153.0.8010.52-1~deb13u1

Fixed

SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93385MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93386MEDIUM5.4
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93387MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93383MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93384LOW3.7
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management