Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Phishing Campaign Impersonates ChatGPT to Steal OpenAI Credentials
September 18, 2026
Critical Tutor LMS flaw exposes 100,000+ WordPress sites to RCE
September 18, 2026
Chrome 153 Update Patches 16 Vulnerabilities, Including Critical Dawn and WebGL Flaws
September 18, 2026
Home/CyberSecurity News/Chrome 153 Update Patches 16 Vulnerabilities, Including Critical Dawn and WebGL Flaws
CyberSecurity News

Chrome 153 Update Patches 16 Vulnerabilities, Including Critical Dawn and WebGL Flaws

Key Takeaways Google has released Chrome 153, addressing 16 security vulnerabilities across Windows, macOS, and Linux. Two critical memory-safety flaws, CVE-2026-93374 in Dawn and CVE-2026-93372 in...

Jennifer sherman
Jennifer sherman
September 18, 2026 3 Min Read
3 0

Key Takeaways

  • Google has released Chrome 153, addressing 16 security vulnerabilities across Windows, macOS, and Linux.
  • Two critical memory-safety flaws, CVE-2026-93374 in Dawn and CVE-2026-93372 in WebGL, are patched.
  • Users are strongly advised to update immediately to mitigate risks of arbitrary code execution and memory corruption.
  • The update also resolves eight high-severity issues and several medium and low-severity vulnerabilities.

Google has rolled out Chrome 153 to its Stable channel for desktop users, delivering crucial security updates that resolve 16 vulnerabilities. This release includes patches for two critical memory-safety flaws impacting the browser’s Dawn and WebGL components.

Table Of Content

  • Key Takeaways
  • Critical Vulnerabilities Addressed
  • High-Severity Flaws and Other Patches
  • What You Should Do

The updated versions are 153.0.8010.52/.53 for Windows and macOS, and 153.0.8010.52 for Linux distributions.

Critical Vulnerabilities Addressed

The most severe vulnerability patched in this release is CVE-2026-93374, a critical use-after-free flaw identified in Dawn. Dawn serves as Chrome’s implementation of the WebGPU graphics API. Use-after-free vulnerabilities occur when a program attempts to access memory after it has been deallocated, which can lead to memory corruption, browser crashes, or, in severe cases, arbitrary code execution via specially crafted web content.

Florian Schweitzer is credited with reporting the Dawn vulnerability to Google on April 8, 2026. The reward amount for this discovery has not yet been publicly disclosed by Google.

Another critical issue, CVE-2026-93372, involves a buffer overflow in WebGL. WebGL enables web applications to render interactive 2D and 3D graphics directly within the browser. A buffer overflow arises when an application writes data beyond the allocated size of a memory buffer, potentially overwriting adjacent memory and altering program execution flow, which attackers could exploit for malicious purposes.

Google’s internal security team identified the WebGL vulnerability on August 17, 2026. In line with standard security practices, Google has withheld technical details regarding both critical flaws. This approach aims to provide users sufficient time to apply the updates before exploit information becomes widely available to potential attackers.

High-Severity Flaws and Other Patches

Beyond the critical issues, Chrome 153 addresses eight high-severity vulnerabilities spanning various browser components:

  • CVE-2026-93375: An incorrect reference resolution flaw in Tracing.
  • CVE-2026-93382: A use-after-free vulnerability in PDFium.
  • CVE-2026-93387: Improper state validation in Skia.
  • CVE-2026-93373: A use-after-free bug affecting Extensions.
  • CVE-2026-93381: A buffer overflow issue in PDFium.
  • CVE-2026-93379: An incorrect authorization flaw in ORB.
  • CVE-2026-93377: A type confusion vulnerability in the V8 JavaScript engine.

The type confusion flaw in V8 is particularly noteworthy due to V8’s role in processing JavaScript from websites. Such vulnerabilities can be exploited by attackers to manipulate the engine into misinterpreting object types, leading to memory corruption. This could potentially form part of a chain of vulnerabilities to achieve sandbox escapes.

The update also includes fixes for several medium- and low-severity vulnerabilities. These span components such as FileSystem, Omnibox, Permissions, DataTransfer, Storage, Paint, and WebAppInstalls, addressing issues like race conditions, server-side request forgery (SSRF), information leaks, out-of-bounds reads, authorization flaws, and UI spoofing.

Google has stated that it will keep bug details and related links restricted until the majority of Chrome users have updated their browsers. Restrictions may also remain in place if affected third-party libraries are utilized by other projects that have not yet released their own patches.

What You Should Do

  • Update Immediately: All users should update their Chrome browser without delay. Navigate to the browser menu (three dots), select “Help,” then “About Google Chrome.” The browser typically downloads updates automatically but requires a restart to apply them.
  • Prioritize Organizational Deployment: IT administrators in organizations should prioritize the deployment of this update across all managed endpoints. Browser vulnerabilities are a common attack vector, exploitable through routine web browsing, malicious advertisements, phishing attempts, and compromised legitimate websites.
  • Verify Version: After updating, confirm that your Chrome version matches 153.0.8010.52/.53 (Windows/macOS) or 153.0.8010.52 (Linux).

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchphishingSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Android Apps Can Verify Missing Critical Security Patches

Next Post

Critical Tutor LMS flaw exposes 100,000+ WordPress sites to RCE

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical MikroTik RouterOS Flaw (CVE-2023-30799) Lets Attackers Gain Admin Access
September 18, 2026
Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites
September 18, 2026
Critical Plugin4Shell RCE Flaw Impacts AI Coding Assistants
September 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us