TL;DR
Google released security updates on September 17, 2026, addressing sixteen vulnerabilities in its web browser.
These Google Chrome vulnerabilities include two critical flaws that permit memory corruption. Attackers could exploit these weaknesses to execute unauthorized code on victim devices. Users should install the latest browser release immediately to protect their systems.
- Total: 5 CVEs
- Severity: 5 Unrated
- Actively exploited: None confirmed
- Highest severity: Awaiting analysis — CVE-2026-93374
- Action: Apply the latest security updates now
Track every Google CVE the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | Fixed in | Status |
|---|---|---|
| CVE-2026-93374 | 153.0.8010.52 | Not exploited |
| CVE-2026-93372 | 153.0.8010.52 | Not exploited |
| CVE-2026-93377 | 153.0.8010.52 | Not exploited |
| CVE-2026-93382 | 153.0.8010.52 | Not exploited |
| CVE-2026-93381 | 153.0.8010.52 | Not exploited |
Why It Matters
Sourced estimates show that more than three billion people rely on Chrome worldwide. Therefore, browser security flaws create serious exposure for home users and enterprise environments. If an attacker breaches the browser sandbox, they can access personal data. Furthermore, intruders can steal authentication tokens and plant malicious payloads on endpoints.
How the Attack Works
The update tackles multiple memory safety issues. In the official advisory, Google confirmed that “This update includes 16 security fixes.”
The most severe flaw, CVE-2026-93374, involves a use-after-free error within the Dawn graphics library. When an application accesses released memory, the browser becomes unstable. Consequently, attackers can trigger unexpected behavior or execute arbitrary code. Another critical defect, CVE-2026-93372, causes a buffer overflow inside WebGL during graphics rendering.
Additionally, high-severity bugs affect the V8 JavaScript engine, Skia graphics, and PDFium components. For instance, CVE-2026-93377 stems from type confusion in V8. Attackers exploit type confusion by tricking the engine into reading objects as incorrect data types. Currently, researchers have confirmed no active in-the-wild exploitation or public proof-of-concept exploits.
Affected Versions
These Google Chrome vulnerabilities impact versions prior to 153.0.8010.52 on Linux. They also affect versions earlier than 153.0.8010.52/.53 on Windows and macOS platforms.
Patch and Mitigation Steps
Administrators should deploy the latest release across all endpoints. To safeguard users, Google noted: “Access to bug details and links may be kept restricted until a majority of users are updated with a fix.”
Users can verify the patch in the official Chrome desktop update announcement. Open the browser menu, select Help, and click About Google Chrome to apply the update. Restart the application to finalize the installation.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!