CVE-2026-93375: Google Google Chrome vulnerability
Published Sep 17, 2026
·Updated
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Affected Software
1 affected component
Google Google Chrome<153.0.8010.52
Event History
Sep 17, 2026
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Windows systems running Google Chrome versions earlier than 153.0.8010.52 are affected. The issue is in Chrome Tracing.
2
What does an attacker need to exploit it?
The attacker needs the ability to run a local program on the affected Windows system. Successful exploitation could allow arbitrary code execution outside Chrome's sandbox.
3
Is remote exploitation described?
No. The available information describes exploitation by a local attacker through a local program.
4
What version resolves the issue?
Update Google Chrome on Windows to version 153.0.8010.52 or later.