securityonline.info 18 Sept 2026, 06:20 UTC

Google Patches Two Critical Chrome Flaws Enabling Code Execution

Google Patches Two Critical Chrome Flaws Enabling Code Execution
CyberSIXT Evidence Panel Source marked as original reporting

GOOGLE released Chrome security updates on 17 September 2026 to fix 16 vulnerabilities. The issues include two described as critical: CVE-2026-93374, a use-after-free flaw in the Dawn graphics library, and CVE-2026-93372, a buffer overflow in WebGL. Both could potentially cause memory corruption and allow arbitrary code execution. Other high-severity defects affect the V8 JavaScript engine, Skia graphics and PDFium, including CVE-2026-93377, a type-confusion vulnerability in V8. The article says there is no confirmed active exploitation or public proof-of-concept exploit for these flaws.

The affected versions are Chrome releases before 153.0.8010.52 on Linux, and earlier than 153.0.8010.52/.53 on Windows and macOS. The listed vulnerabilities—CVE-2026-93372, CVE-2026-93374, CVE-2026-93377, CVE-2026-93381 and CVE-2026-93382—are fixed in version 153.0.8010.52. Google has restricted some vulnerability details and links until most users have installed the fixes. Users can check for the update by opening Chrome’s menu, selecting Help, then About Google Chrome, and restarting the browser when prompted.

View full article

Article by CyberSIXT