Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.4 Browsers CVE-2026-93373 CVE-2026-91729 CVE-2026-91736 CVE-2026-91741

Google Chrome: Eight High-Severity Vulnerabilities Fixed in Two Stable Channel Updates

Google shipped two Chrome Stable Channel updates in September 2026 fixing eight high-severity vulnerabilities, including several use-after-free and type confusion bugs that could allow remote code execution via crafted web pages, extensions, or PDF files.

AI summary

Google released two Stable Channel updates for Chrome on desktop in September 2026, addressing a total of eight vulnerabilities rated High severity by the Chromium security team. The issues span multiple browser components, including the DOM, V8 JavaScript engine, PDF handling, ServiceWorker, CacheStorage, DigitalCredentials, PDFium, and the Extensions subsystem. Most of the flaws are use-after-free or type confusion bugs that could be exploited via a specially crafted HTML page, PDF file, or malicious browser extension to execute arbitrary code, in several cases outside the browser sandbox. Users and administrators should ensure Chrome is updated to the latest fixed version as soon as possible.

What happened

Google published two separate Stable Channel updates for Chrome on desktop during September 2026, fixing eight distinct vulnerabilities in total. The first update, released around September 15, 2026, addressed six issues fixed in version 153.0.8010.47: use-after-free vulnerabilities in DigitalCredentials, DOM, PDF handling, and V8, as well as type confusion issues in CacheStorage and ServiceWorker. A second update, released around September 17, 2026, addressed two further issues fixed in version 153.0.8010.52: a use-after-free in the Extensions component and a buffer overflow in PDFium affecting Chrome on Windows. All eight vulnerabilities are rated High severity by the Chromium security team.

Technical cause

Six of the eight vulnerabilities are use-after-free bugs (CWE-416), a memory safety issue where a program continues to reference memory after it has been freed, which can be abused to execute attacker-controlled code. These affect the Extensions (CVE-2026-93373), DigitalCredentials (CVE-2026-91729), DOM (CVE-2026-91736), PDF (CVE-2026-91737), and V8 (CVE-2026-91745) components. Two vulnerabilities are type confusion bugs (CWE-843) in CacheStorage (CVE-2026-91741) and ServiceWorker (CVE-2026-91709), where code treats an object as a different, incompatible type, which can also lead to memory corruption and code execution. The eighth, CVE-2026-93381, is a buffer overflow (CWE-122) in PDFium, Chrome's built-in PDF rendering library, specifically affecting the Windows version of Chrome.

Why it matters

Several of these vulnerabilities, including the Extensions use-after-free (CVE-2026-93373) and the DigitalCredentials use-after-free (CVE-2026-91729), carry a CVSS score of 9.6 and allow code execution outside the Chrome sandbox, which is the isolation boundary normally preventing a compromised web page or extension from affecting the rest of the system. The remaining vulnerabilities, scored 8.8, allow code execution inside the sandbox, which still poses a serious risk and could potentially be chained with a separate sandbox-escape vulnerability. Exploitation generally requires a user to interact with crafted content, such as visiting a malicious web page, opening a crafted PDF file, or installing a malicious extension.

Who is affected

All users of Google Chrome on desktop are potentially affected. One vulnerability, CVE-2026-93381, specifically affects Chrome running on Windows; the fact package does not specify whether the other seven vulnerabilities are platform-specific or affect Chrome across all desktop operating systems.

Affected versions and fixes

Chrome versions prior to 153.0.8010.47 are affected by six of the vulnerabilities (CVE-2026-91729, CVE-2026-91736, CVE-2026-91741, CVE-2026-91737, CVE-2026-91745, CVE-2026-91709), fixed in that version. Chrome versions prior to 153.0.8010.52 are affected by two vulnerabilities (CVE-2026-93373, CVE-2026-93381), fixed in that version. The fact package does not provide a precise lower bound for when each vulnerability was introduced.

Recommended action

Update Google Chrome to version 153.0.8010.47 or later to address the six vulnerabilities fixed in that release, and to version 153.0.8010.52 or later to address the remaining two vulnerabilities, including the Extensions and PDFium issues. Chrome typically updates automatically; users should restart the browser to apply a pending update and can manually check the version via the browser's settings menu to confirm the installed version is current.

PatchBriefing score

6.4 / 10 · Medium

Official CVSS: 9.6

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

The Patchwire scores for these vulnerabilities (6.4 for the two sandbox-escape issues and 5.9 for the remaining six) are driven primarily by their high CVSS base scores (9.6 and 8.8 respectively), reflecting the potential for remote code execution. Additional contribution comes from the vulnerabilities being remotely triggerable without authentication and from Chrome's extremely large user base (product popularity factor). None of these vulnerabilities are currently known to be exploited in the wild, and no public exploit code has been reported, which limits the immediate urgency compared to actively exploited flaws, but the combination of high impact and broad exposure still warrants prompt patching.

Affected versions

≥ 153.0.8010.52
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.52
patched
≥ 153.0.8010.47
patched

Reported fixes

Update Google Chrome to version 153.0.8010.47 or later to address the six vulnerabilities fixed in that release, and to version 153.0.8010.52 or later to address the remaining two vulnerabilities, including the Extensions and PDFium issues. Chrome typically updates automatically; users should restart the browser to apply a pending update and can manually check the version via the browser's settings menu to confirm the installed version is current.

How this was built

10 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome: Eight High-Severity Vulnerabilities Fixed in Two Stable Channel Updates
1 article · 10 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email