CVE-2026-93382 explained: what the Google Chrome flaw means for your business and how to fix it

Introduction
CVE-2026-93382 is a flaw in Google Chrome that Google has already fixed with an update. If you run Chrome on any computer, phone, or server, this guide tells you whether it touches you and what to do about it.
Does this affect you?
The two-minute check
- Open Google Chrome on the computer, phone, or server you use.
- Click the three-dot menu in the top-right corner.
- Go to Help, then About Google Chrome.
- Look at the version number shown on that screen.
- Note whether the page says the browser is up to date or needs a restart to finish updating.
- If you use Chrome on a phone, check the app store listing for pending updates too.
When you can stop reading
The record lists only Google as the vendor and only Chrome, including the Chrome build on Android, as affected products. If your business does not use Google Chrome anywhere, on desktops, laptops, phones, or servers, you can close this tab. If you only use a different browser, this record does not apply to you.
How bad is it, honestly?
What the official record says
CVE-2026-93382 is a use-after-free bug in a component called PDFium, which Chrome uses to open PDF files. A use-after-free bug means the software reuses a piece of memory it already released, and an attacker can fill that memory with their own instructions. The National Vulnerability Database (NVD) scores this CVE-2026-93382 at 8.8, rated HIGH, under Common Vulnerability Scoring System (CVSS) version 3.1.
The scoring details say an attacker can reach this flaw over a network without needing any account or login on your system. They do need you to open a crafted web page or file, so some action from a person is required. The Exploit Prediction Scoring System (EPSS) puts the probability at 0.37 percent, in the 31st percentile, according to FIRST.org. That is a low chance of exploitation in the next 30 days. EPSS forecasts exploitation activity over the next month; it does not measure how severe the flaw itself is.
This flaw is not on the Known Exploited Vulnerabilities (KEV) catalog. The record shows no confirmed exploitation yet, and that can change without warning. The same September update also fixes eleven related issues in Chrome, including CVE-2026-93385, CVE-2026-93386, CVE-2026-93387, CVE-2026-93383, CVE-2026-93384, CVE-2026-93374, CVE-2026-93373, CVE-2026-93372, CVE-2026-93381, CVE-2026-93377, and CVE-2026-93375. You install one update and all twelve issues are addressed at once.
What that means for a business like yours
A remote attacker who gets an employee to open a crafted web page could run code inside Chrome's sandbox, a restricted area meant to contain damage. That is a real risk to any business, but it needs a person to click something first. It is not the kind of flaw that spreads on its own across your network without any action from your team.
What to do about it, step by step
If someone else manages your IT
Ask your provider directly and in writing. You can paste this into an email:
- "Have all our Google Chrome installs been updated past version 153.0.8010.52?"
- "Can you confirm this for every device, including phones running Android?"
- "Please send me confirmation once it's done."
A good answer names the version number, states a completion date, and covers every device type your business uses, not just desktops. If your provider cannot answer within a business day, that is worth a follow-up call. LayerLogix clients can confirm patch status through our managed IT services, which include update tracking as a standard part of the service.
If you manage it yourself
- Open Google Chrome on each device your business uses.
- Click the three-dot menu, then Help, then About Google Chrome.
- Let the page check for updates; it usually does this automatically.
- Click the button that says Relaunch if one appears.
- Repeat this on every laptop, desktop, and phone running Chrome in your business.
- Check the official Chrome release notes if you want the vendor's own description of the fix.
How long you have
The record shows no confirmed exploitation and a low EPSS score, so there is no need to drop everything today. That said, this flaw is reachable over a network and does not require a login, so a sensible window is to patch within the next week or two. If exploitation shows up on the KEV catalog later, that would change the timeline and call for faster action.
How to check it actually worked
Do not just trust a progress bar. After updating, open Chrome's menu, go to Help, then About Google Chrome again. The version shown should now read 153.0.8010.52 or higher. If the page still shows an older number after a restart, the update did not complete, and you should relaunch the browser again. For a fleet of devices, ask whoever manages your IT for a written list confirming each device's version number.
What to do if you can't patch right now
If you cannot update immediately, avoid opening PDF files or links from unfamiliar senders in Chrome until you can. This does not remove the risk, but it reduces the chance someone triggers the flaw by accident. You can also review who has administrative rights on business devices; limiting those rights is part of good privileged access management and reduces what any single compromised browser session can do. Neither step replaces the update. Both simply buy you time until you can install it.
Frequently Asked Questions
Do I have to do anything if we only use Chrome at home?
This guide is written for business use, but the same steps apply at home. Update Chrome the same way, through the three-dot menu and Help, then About Google Chrome.
Will this update break anything?
The record does not mention compatibility issues. Chrome updates are routine, and most businesses see no disruption beyond a short restart of the browser.
Does this affect our other business software?
The record names only Google Chrome, including its Android build, as affected. If your other software does not run inside Chrome, this record does not apply to it.
How do I know if this has already been used against us?
The record shows no confirmed exploitation of this flaw. If you are concerned about unusual activity on your network, our cybersecurity services can review your logs and endpoints for signs of compromise.
Do regulated businesses need to treat this differently?
If your business handles health records or financial data, patching promptly supports obligations under frameworks like HIPAA or the FTC Safeguards Rule. The update process itself is the same regardless of your industry.
If you want help confirming every device in your business is patched, or you would rather not track browser updates yourself, request a free IT assessment or contact LayerLogix. We provide 100% Texas-based support with 20+ years of experience keeping business software current.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.


