CVE-2026-93380
chrome: Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-2026-93380)
lowEPSS 0.2%
Description
Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
googlechrome
153.0.8010.52fixed from 153.0.8010.52Metrics
Show all metrics
Severity
low
46.16
no public PoC known
3.1
Published
2026-09-30 20:25 UTC
CWE-367
Weakness classes (CWE)
CWE-367Base
Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-21 11:00 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to (excluding) 153.0.8010.52
- Reference Type: Chrome: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html Types: Release Notes, Vendor Advisory
- Reference Type: Chrome: https://issues.chromium.org/issues/498411599 Types: Permissions Required
- CVE Modified2026-09-18 14:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
- SSVC: {"id":"CVE-2026-93380","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-17 21:17 UTC· chrome-cve-admin@google.com
- Description: Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- CWE: CWE-367
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/93xxx/CVE-2026-93380.json">CVE-2026-93380</a>
- Reference: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html