Executive brief
Google Chrome contains an information leak vulnerability in its Paint component that allows remote attackers to obtain sensitive information by tricking users into visiting a crafted webpage. This could result in exposure of private user data or system information to unauthorized parties. The vulnerability affects Chrome versions prior to 153.0.8010.52 and has been patched in the latest release.
Technical details
CVE-2026-93385 is an information leak vulnerability in the Paint component of Google Chrome. The vulnerability can be exploited by a remote attacker through a crafted HTML page, allowing unauthorized disclosure of sensitive information. The attack requires user interaction (visiting a malicious webpage) but no authentication. Google has patched this issue in Chrome version 153.0.8010.52 and later. The vulnerability was reported by Google's internal security team on 2026-08-26.
Affected products
- Google Chrome prior to 153.0.8010.52
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Chrome 153.0.8010.52/.53