External risk intelligence

Chrome for Android Use After Free Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-93374

This vulnerability exists within the Dawn component of the Google Chrome browser on Android. Browser vulnerabilities are client-side issues that require a user to navigate to a crafted web page; they are not internet-facing services, gateways, or reachable infrastructure components that are independently exposed to the public network.

Use After Free

Google Chrome

before 153.0.8010.52

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A use-after-free vulnerability in the Dawn component of Google Chrome on Android could allow a remote attacker to execute arbitrary code by tricking a user into visiting a malicious webpage. This issue has been rated as Critical.

  • A flaw in Chrome could let attackers run their own code.
  • Critical rating means it's a significant technical risk.
  • Verify if Chrome on Android is used and update to mitigate.

Attack Path

How an attacker could exploit the issue

A remote attacker could exploit this vulnerability by tricking a user into visiting a malicious HTML page. This could allow them to execute arbitrary code within the browser's sandbox, potentially compromising the device.

  • Entry condition: User visits a malicious page.
  • Trigger point: Vulnerable component in Chrome for Android.
  • Resulting risk: Arbitrary code execution outside the sandbox.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Chrome's Dawn component on Android could allow a remote attacker to execute arbitrary code outside the sandbox by tricking a user into visiting a malicious HTML page. This could impact the overall security and integrity of the affected Android device.

  • Arbitrary code execution outside the sandbox.
  • User visits a crafted HTML page.
  • Compromise of the Android device.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Dawn component of Google Chrome on Android requires immediate attention from teams managing user-facing applications and mobile device security. The first practical step is to identify all Android devices running affected Chrome versions, determine their business criticality, and locate the accountable owner for remediation planning, prioritizing those most exposed.

  • Ownership: Application owners and mobile device managers.
  • Verify first: Identify affected Android Chrome instances.
  • Action: Plan and coordinate browser updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Dawn component in Google Chrome for Android?

Dawn is an open-source library used by Google Chrome to implement web graphics standards like WebGPU. It acts as a translator between web applications and the underlying graphics hardware on your Android device, allowing browsers to render complex visuals efficiently. Because it handles intensive data processing, it is a critical part of the browser's architecture for modern web content.

What does a use-after-free vulnerability mean in CVE-2026-93374?

This weakness, categorized as CWE-416, happens when a program continues to use a memory address after that memory has been cleared or released. If an attacker can manipulate this process, they can replace the original data with their own malicious instructions. In the context of this CVE, this flaw allows unauthorized code to execute outside the browser's intended security boundaries.

How is this Chrome vulnerability triggered?

The vulnerability is triggered when a user navigates to a specifically crafted HTML page designed to exploit the memory management flaw in the Dawn component. Simply having the browser installed is not enough to trigger the issue; the attack requires active user interaction with malicious web content. Standard web browsing on trusted sites does not initiate this exploit path.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that this vulnerability is very unlikely to be exploited as an automated network attack. Because this is a client-side issue residing within the browser on Android, it does not function like a service or gateway exposed to the internet. The risk is tied to the actions of the individual user and the web pages they choose to visit.

Do I need to update Chrome on my Android devices?

Yes, you should ensure that all Android devices are updated to version 153.0.8010.52 or later. The first step is to inventory your mobile fleet to identify instances running older, vulnerable versions of the application. Once identified, coordinate with the device owners or management teams to push the latest browser update, which contains the necessary security patches to resolve this flaw.

References