Junglewise Threat Intelligence

CVE-2026-93387: Google Chrome improper state validation in Skia

CVE-2026-93387 · Severity: medium · CVSS 4.3 · Published 2026-09-17

Executive brief

Google Chrome's Skia graphics rendering library contained a flaw that failed to properly validate internal state, allowing attackers to extract sensitive data from websites the user visited without authorization. An attacker could craft a malicious webpage that, when opened in Chrome, would leak private information from other origins (websites) the user accessed in the same browser session.

Technical details

The vulnerability is an improper state validation issue in Skia, Chrome's graphics rendering engine. The flaw permits a remote attacker to bypass origin isolation controls through a crafted HTML page, leading to unauthorized cross-origin data access. Attack vector is network-based and requires only that a user visit a malicious webpage; no additional authentication or user interaction beyond normal browsing is needed. The vulnerability was patched in Chrome 153.0.8010.52 and later. Google's own security team discovered and reported this issue.

Affected products

  • Google Chrome prior to 153.0.8010.52

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Fixed in Chrome 153.0.8010.52

References

Related threats