CVE-2026-93374: Use After Free
Published Sep 17, 2026
·Updated
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Affected Software
1 affected component
Google Dawn<153.0.8010.52
Event History
Sep 17, 2026
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionWeakness
Frequently Asked Questions
1
Which devices are affected?
The issue affects Google Chrome on Android before version 153.0.8010.52. The provided information does not establish impact on desktop Chrome or other platforms.
2
What does an attacker need to exploit this issue?
An attacker would need to cause a victim to load a crafted HTML page remotely. Successful exploitation could potentially allow arbitrary code execution outside the browser sandbox.
3
How can I determine whether an Android device is affected?
Check the installed Google Chrome version on the Android device. Versions earlier than 153.0.8010.52 are affected according to the provided information.