External risk intelligence

Chrome Extension Use After Free Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-93373

This vulnerability exists within the Chrome browser's extension framework and requires a user to install or interact with a crafted extension. It is a client-side component, not a public-facing network service, appliance, or gateway, making it very unlikely to be exposed as an internet-facing surface in common deployments.

Use After Free

Google Chrome

before 153.0.8010.52

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A use-after-free vulnerability in Google Chrome extensions could allow a remote attacker to execute arbitrary code outside the sandbox by tricking a user into installing or interacting with a malicious extension.

  • A code flaw exists in browser extensions.
  • It could allow unauthorized code execution.
  • Confirm relevance and exposure for your organization.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into installing a malicious Chrome extension. If the user opens this extension, the attacker's code could execute outside the browser's secure sandbox, potentially allowing them to run their own commands on the user's computer.

  • User must install a malicious extension.
  • User must interact with the crafted extension.
  • Risk of arbitrary code execution outside sandbox.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Chrome extensions could allow a remote attacker to execute arbitrary code outside the sandbox when supported by a crafted extension and user interaction.

  • Arbitrary code execution outside sandbox.
  • Remote attacker via crafted extension.
  • Compromise of user's browser environment.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability resides within Google Chrome's extension framework, meaning it primarily impacts end-user workstations and potentially any systems where custom Chrome extensions are deployed or user interaction with malicious extensions is possible. The first practical step is for system owners and security teams to identify Chrome deployments, confirm if extensions are a factor in their environment, and then assess the risk based on user behavior and the criticality of affected systems. Coordination with vendor management for updates or with internal teams for deployment is key.

  • Browser and endpoint teams own this vulnerability.
  • Verify extension usage and user access.
  • Plan for Chrome browser updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome and how do extensions work?

Google Chrome is a widely used web browser that connects users to the internet. Extensions are small software programs that users install to add extra features or functionality to the browser. These extensions interact directly with the browser's core code, which is why flaws within them can have significant security implications for the overall application.

What is the Use After Free weakness in CVE-2026-93373?

A Use After Free, or CWE-416, happens when software continues to use a piece of computer memory after it has been cleared or deleted. In this case, the vulnerability allows an attacker to manipulate this memory space to insert and run their own unauthorized instructions, effectively tricking the browser into executing code that the software developer never intended to run.

How does an attacker trigger this vulnerability?

An attacker triggers this bug by providing a specially crafted Chrome extension that a user must install and interact with. It is important to note that simply visiting a website is not enough to trigger the vulnerability; the malicious extension must be actively installed and used on the system for the exploit to take effect.

Is this Chrome vulnerability an internet-facing threat?

According to Halo Surface Signal, this vulnerability is very unlikely to be an internet-facing surface. It resides in a client-side component rather than a public-facing server or network gateway. Because it requires a user to manually install or interact with a specific extension, it does not pose a direct, automated risk to your network infrastructure.

What should I do if I use Google Chrome?

The most effective step is to update your browser to version 153.0.8010.52 or later, as this release contains the fix from Google. Additionally, security teams should audit which extensions are currently installed across their workstations and educate users on the risks of installing untrusted or unauthorized browser add-ons.

References