4.3
CVE-2026-93387
- EPSS 0.25%
- Veröffentlicht 17.09.2026 21:17:56
- Zuletzt bearbeitet 18.09.2026 17:17:02
- Erkennungen
Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.172 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
CWE-754 Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html
https://issues.chromium.org/issues/553130676