Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.7 Browsers CVE-2026-93385 CVE-2026-93386

Google Chrome Stable Update Fixes Two Vulnerabilities (CVE-2026-93385, CVE-2026-93386)

Google released Chrome 153.0.8010.52 for desktop, fixing an information leak in the Paint component and a UI spoofing issue in WebAppInstalls. Both require user interaction and have no known exploitation.

Synthesized by AI from 3 sources · updated 2 hours ago

AI summary

Google has published a Stable Channel update for Chrome on desktop, addressing two vulnerabilities disclosed under CVE-2026-93385 and CVE-2026-93386. Both issues were fixed in Chrome version 153.0.8010.52. Neither vulnerability is currently known to be exploited in the wild, and no public exploit code has been reported.

What happened

Google released a Stable Channel update for Chrome on desktop that resolves two security issues. CVE-2026-93385 is an information leak in the Paint component, rated Medium severity by Chromium's internal severity classification. CVE-2026-93386 is a UI misrepresentation issue in WebAppInstalls, rated Low severity. Both were fixed in Chrome 153.0.8010.52.

Technical cause

CVE-2026-93385 (CWE-200, Exposure of Sensitive Information) stems from a flaw in Chrome's Paint component that allowed a remote attacker to obtain sensitive information through a crafted HTML page. CVE-2026-93386 (CWE-451, User Interface Misrepresentation of Critical Information) is located in the WebAppInstalls component and allowed an attacker to spoof UI elements via a crafted HTML page, requiring social engineering to succeed.

Why it matters

CVE-2026-93385 could allow an attacker to read sensitive information from a visited page without the user noticing anything unusual, which is why it carries a higher confidentiality impact rating. CVE-2026-93386 could be used to make a malicious or misleading UI element appear legitimate, potentially aiding social engineering attacks, though its direct impact is lower since it does not grant access to data or system control on its own.

Who is affected

Any user running Google Chrome on desktop prior to version 153.0.8010.52 is affected by both vulnerabilities. Both issues require the victim to visit a specially crafted HTML page and involve some level of user interaction to be exploited.

Affected versions

Google Chrome versions prior to 153.0.8010.52 are affected by both CVE-2026-93385 and CVE-2026-93386. The exact starting version range for either flaw was not specified in the available vendor information.

Fixes and mitigation

Google has fixed both vulnerabilities in Chrome version 153.0.8010.52, released through the Stable Channel for desktop. Users should ensure their browser updates automatically or manually trigger an update check via Chrome's settings.

Recommended action

Update Google Chrome to version 153.0.8010.52 or later as soon as possible. Most installations update automatically on restart, but administrators managing Chrome deployments in organizational environments should verify that the update has been applied across all endpoints.

PatchBriefing score

4.7 / 10 · Medium

Official CVSS: 6.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Why this score

The Patchwire score of 4.7 for CVE-2026-93385 reflects its CVSS base score of 6.5 (confidentiality impact is high, but exploitation requires user interaction and no privileges), combined with a modest increase for being unauthenticated and remotely exploitable, plus a small factor for Chrome's extremely large install base. No known exploitation or public exploit code increases the score further. CVE-2026-93386 scores 4.1, reflecting its lower CVSS base score of 5.4 (limited confidentiality and availability impact, and it depends on social engineering), with similar small adjustments for remote unauthenticated access and product popularity. Neither vulnerability is flagged as actively exploited or having public exploit code available.

Affected versions

≥ 153.0.8010.52
patched
≥ 153.0.8010.52
patched

Reported fixes

Google has fixed both vulnerabilities in Chrome version 153.0.8010.52, released through the Stable Channel for desktop. Users should ensure their browser updates automatically or manually trigger an update check via Chrome's settings.

How this was built

3 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Two Vulnerabilities (CVE-2026-93385, CVE-2026-93386)
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email