Junglewise Threat Intelligence

CVE-2026-93374: Google Chrome use-after-free in Dawn on Android

CVE-2026-93374 · Severity: critical · CVSS 9.6 · Published 2026-09-17

Executive brief

Google Chrome on Android contains a memory safety vulnerability in its graphics rendering engine (Dawn) that allows attackers to execute arbitrary code outside the browser sandbox. An attacker can exploit this flaw by crafting a malicious HTML page; if a user visits the page, the attacker gains the ability to run code with the same privileges as the browser, potentially compromising user data and device security.

Technical details

This is a use-after-free vulnerability in the Dawn graphics engine component of Google Chrome on Android prior to version 153.0.8010.52. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox boundary via a crafted HTML page. No user interaction beyond visiting a malicious page is required. The vulnerability was reported by Florian Schweitzer on April 8, 2026, and patched in Chrome 153.0.8010.52 released September 17, 2026. No public exploit has been reported.

Affected products

  • Google Chrome prior to 153.0.8010.52 on Android

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Chrome 153.0.8010.52

References

Related threats