CVE-2026-93374

Google · Chrome

A use after free vulnerability in the Dawn component of Google Chrome on Android allows a remote attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome for Android enables remote code execution, posing a severe risk to device integrity and user data.

Vulnerability

This is a use after free vulnerability within the Dawn component of the browser. The flaw allows an unauthenticated remote attacker to trigger memory corruption and execute arbitrary code outside the browser sandbox by enticing a user to visit a malicious HTML page.

Business impact

The ability to execute arbitrary code remotely represents the highest level of security risk, as it allows attackers to bypass browser security boundaries. Successful exploitation could lead to full device compromise, theft of sensitive credentials, or the installation of malicious software, directly impacting organizational security and user privacy. Given the CVSS score of 9.6, this vulnerability must be treated as a high priority for immediate remediation.

Remediation

Immediate Action: Update Google Chrome on all affected Android devices to version 153.0.8010.52 or later immediately.

Proactive Monitoring: Monitor mobile device management (MDM) consoles to ensure all managed browsers are updated and check web gateway logs for traffic directed toward suspicious or unknown domains.

Compensating Controls: While no direct virtual patch exists for this client-side flaw, ensure that users are trained to avoid clicking untrusted links and that mobile threat defense solutions are active to detect anomalous process behavior.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for remote code execution, organizations must prioritize the deployment of the update across all mobile endpoints. Users should be prompted to verify their browser version and apply the update through the official app store to mitigate the risk of exploitation.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written

Sources