Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-93387
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-93387 is an improper state validation vulnerability in the Skia graphics library component of Google Chrome that allows a remote attacker to obtain cross-origin data via a crafted HTML page. It affects Google Chrome versions prior to 153.0.8010.52 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on 2026-08-26 and patched on September 17, 2026, as part of a 16-fix stable channel update. It is rated High severity by Chromium's security team; a formal CVSS score has not yet been published (Chrome Releases, GitHub Advisory).

Technical details

The root cause is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions), specifically an improper state validation flaw within Chrome's Skia 2D graphics engine. Skia is responsible for rendering web content, and the failure to properly validate internal rendering state can allow pixel or memory data from one origin to be read by another, effectively bypassing the browser's same-origin policy. Exploitation requires only that a victim visit a specially crafted HTML page — no authentication or user interaction beyond navigation is needed. The Chromium issue tracker entry is bug #553130676, though details remain restricted pending broad patch rollout (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation enables an unauthenticated remote attacker to read sensitive cross-origin data that should be protected by the browser's same-origin policy, constituting a confidentiality breach. This could expose session tokens, authentication cookies, or other sensitive page content rendered by the browser from a different origin. Integrity and availability are not directly impacted, but disclosed data could facilitate follow-on attacks such as session hijacking or credential theft (GitHub Advisory, Chrome Releases).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported. The bug was discovered and reported internally by Google, which may have limited external attacker awareness prior to patching.

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 153.0.8010.52 (Linux) and 153.0.8010.52/.53 (Windows and Mac), which began rolling out on September 17, 2026. Users should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or enable automatic updates. As a precautionary measure, users should avoid visiting untrusted or suspicious websites until the update is applied (Chrome Releases).

Community reactions

Security news outlet GBHackers covered the broader Chrome 153 update, noting it addressed 16 security flaws including CVE-2026-93387. No notable independent researcher commentary or significant social media discussion specific to this CVE has been observed beyond standard vulnerability aggregator coverage.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium

Affected

sid

chromium: 153.0.8010.52-1

Fixed

trixie

chromium: 153.0.8010.52-1~deb13u1

Fixed

SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93385MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93386MEDIUM5.4
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93387MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93383MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93384LOW3.7
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management