CVE-2026-93373
Google · Chrome
A use after free vulnerability in Google Chrome Extensions allows a remote attacker to execute arbitrary code outside the sandbox via a crafted extension.
Executive summary
A critical use after free vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk to system integrity.
Vulnerability
The vulnerability is a use after free condition within the Extensions component of Google Chrome. This flaw allows an unauthenticated remote attacker to achieve arbitrary code execution outside the browser sandbox by tricking a user into interacting with a crafted extension.
Business impact
The potential for arbitrary code execution outside the browser sandbox presents a critical threat to organizational security. Successful exploitation could lead to full system compromise, unauthorized data exfiltration, or the deployment of persistent malware. With a CVSS score of 9.6, this vulnerability necessitates immediate attention to prevent significant operational and data security breaches.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.52 or later immediately to incorporate the security fix.
Proactive Monitoring: Review browser and endpoint logs for suspicious extension installation activity or unauthorized process spawning that deviates from standard user behavior.
Compensating Controls: Deploy endpoint detection and response solutions to monitor for anomalous memory access patterns and restrict the installation of unauthorized or unverified extensions via group policy.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS severity and the nature of the vulnerability, administrators must prioritize the deployment of the Chrome update across the environment. Failure to remediate this flaw exposes systems to remote code execution attacks that could result in total compromise. Ensure all end users are prompted to restart their browsers to apply the mandatory security patches.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written