Skip to content
googleCVE-2026-93380

Race condition in FileSystem in Google Chrome prior to 153.0.8010.

Low3.1CVE-2026-93380 · Published Sep 17, 2026 · updated Sep 21, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Chrome
Vendor
>= 153.0.8010.52, < 153.0.8010.52153.0.8010.52
Details and references

Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Severity from
no source yet
Weakness
CWE-367

More google advisories

All
DateAdvisory
Sep 17google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.
CVE-2026-89418High8.7no fix yet
Sep 17Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
CVE-2026-93372Critical9.6fixed in Chrome 153.0.8010.52
Sep 17Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension.
CVE-2026-93373Critical9.6fixed in Chrome 153.0.8010.52
Sep 17Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page.
CVE-2026-93374Critical9.6fixed in Chrome 153.0.8010.52
Sep 17Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program.
CVE-2026-93375High8.1fixed in Chrome 153.0.8010.52
Sep 17Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program.
CVE-2026-93376Medium6.3fixed in Chrome 153.0.8010.52

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.