CVE-2026-93375
Google · Chrome
A local code execution vulnerability exists in Google Chrome for Windows due to incorrect reference resolution within the Tracing component.
Executive summary
A high-severity sandbox escape vulnerability in Google Chrome allows a local attacker to execute arbitrary code with elevated privileges on Windows systems.
Vulnerability
The flaw arises from incorrect reference resolution within the Tracing component of the browser. An unauthenticated local attacker can leverage this weakness to bypass sandbox protections and execute arbitrary code via a local program.
Business impact
Successful exploitation of this vulnerability permits a local attacker to break out of the Chrome sandbox, potentially leading to a full system compromise. Given the CVSS score of 8.1, this vulnerability poses a significant risk to organizational assets by enabling lateral movement or data exfiltration from the host machine.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.52 or later immediately to apply the necessary reference resolution fixes.
Proactive Monitoring: Monitor system logs for suspicious process spawning or unexpected local program execution originating from the Google Chrome process.
Compensating Controls: Implement strict endpoint security policies to restrict the execution of unauthorized local programs and ensure that browser instances are running with the least privilege necessary.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a critical risk to workstation security due to the potential for sandbox escape and arbitrary code execution. IT administrators should prioritize the deployment of the 153.0.8010.52 update across all managed Windows environments to eliminate this attack vector.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.1 (3.1)
- Analyst report written