Junglewise Threat Intelligence

CVE-2026-93383: Google Chrome information leak in Permissions

CVE-2026-93383 · Severity: medium · CVSS 4.3 · Published 2026-09-17

Executive brief

Google Chrome's permissions system contained an information leak that allowed remote attackers to extract sensitive cross-origin data by sending a specially crafted web page to a user. This vulnerability could enable attackers to bypass web security boundaries and access data they should not have access to, potentially compromising user privacy and sensitive information handled by web applications.

Technical details

An information leak vulnerability exists in the Permissions component of Google Chrome prior to version 153.0.8010.52. The vulnerability allows a remote attacker to leak cross-origin data via a crafted HTML page sent to a victim. The attack vector is network-based and likely requires user interaction (visiting a malicious page). The attacker gains the ability to exfiltrate sensitive data that should be protected by browser same-origin policy. The vulnerability has been patched in Chrome 153.0.8010.52 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.52

Timeline

  • 2026-05-22: disclosed: Vulnerability reported to Google
  • 2026-09-17: patched: Fixed in Chrome 153.0.8010.52

References

Related threats