Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-93386
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-93386 is a UI misrepresentation vulnerability in the WebAppInstalls component of Google Chrome that allows a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. It affects all versions of Google Chrome prior to 153.0.8010.52 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on 2026-05-17 and publicly disclosed on 2026-09-17 alongside a stable channel update. It is rated Low severity by Chromium's security team, with an EPSS score of 0.0 (Chrome Release, GitHub Advisory).

Technical details

The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning the browser fails to accurately represent critical UI state to the user during web app installation flows. An attacker can craft a malicious HTML page that manipulates how Chrome's WebAppInstalls interface renders, causing UI elements such as permission prompts or installation dialogs to appear misleading or spoofed. Exploitation requires the victim to visit a specially crafted web page, and success depends on social engineering — there is no memory corruption or authentication bypass involved. The Chromium bug tracker entry (issue 513996595) is currently restricted pending broad user update (Chrome Release).

Impact

Successful exploitation allows an attacker to deceive users into taking unintended actions — such as granting permissions or installing malicious web apps — by presenting spoofed Chrome UI elements. The primary impact is on integrity of user decision-making and potential unauthorized permission grants, rather than direct system compromise or data exfiltration. Because exploitation relies entirely on social engineering, the practical impact is limited to scenarios where users interact with and trust the spoofed UI (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability has an EPSS score of 0.0 and is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires user interaction and social engineering, significantly limiting its practical attack surface (GitHub Advisory).

Exploitation steps

  1. Craft malicious HTML page: Develop a web page that exploits the WebAppInstalls UI misrepresentation flaw to render spoofed Chrome installation or permission dialogs.
  2. Deliver to target: Host the page on an attacker-controlled server and lure the victim via phishing, malvertising, or social media links.
  3. Social engineering: When the victim visits the page, the spoofed UI element (e.g., a fake web app install prompt or permission dialog) is displayed, mimicking a legitimate Chrome interface.
  4. Induce unintended action: The victim, believing the UI is legitimate, clicks through the prompt — potentially granting permissions, installing a malicious web app, or disclosing sensitive information (Chrome Release).

Mitigation and workarounds

Update Google Chrome to version 153.0.8010.52 or later (153.0.8010.52/.53 for Windows and Mac, 153.0.8010.52 for Linux), which was released on September 17, 2026. No configuration-based workaround is available; upgrading is the only remediation. As a supplementary measure, organizations should educate users to scrutinize web app installation prompts and be cautious when interacting with unfamiliar web pages (Chrome Release).

Community reactions

Coverage of this specific CVE has been minimal given its Low severity rating, though it was included in broader reporting on the Chrome 153 update that addressed 16 security fixes including two Critical-rated vulnerabilities. Security news outlets such as GBHackers covered the overall Chrome 153 security update (GBHackers).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium

Affected

sid

chromium: 153.0.8010.52-1

Fixed

trixie

chromium: 153.0.8010.52-1~deb13u1

Fixed

SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93385MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93386MEDIUM5.4
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93387MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93383MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93384LOW3.7
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management