OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-93373

CRITICAL · CVSS 9.6 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in Chrome extensions prior to version 153.0.8010.52 allows remote attackers to execute arbitrary code outside the browser's sandbox, potentially compromising user systems. Organizations using affected versions of Chrome should prioritize patching to mitigate the risk of exploitation through malicious extensions. This issue is particularly critical for environments that rely on Chrome for web-based applications and services.

CVE
CVE-2026-93373
Severity
CRITICAL
CVSS
9.6
EPSS
0.34%
Chrome

Original NVD Description

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)