CVE-2026-93384

Google Chrome: Server-Side-Request-Forgery (SSRF)

Description

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

Affected operating systems

  • linux

    debian / chromiumtrixie

Metrics

3.7
Source: cna-v3
14.5 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
low
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-09-17 21:08 UTC
CWE-918

Weakness classes (CWE)

  • CWE-918Base

    Server-Side Request Forgery (SSRF)

    The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-09-18 17:19 UTC· nvd@nist.gov
    • CPE Configuration: AND OR *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to (excluding) 153.0.8010.52 OR cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
    • Reference Type: Chrome: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html Types: Release Notes, Vendor Advisory
    • Reference Type: Chrome: https://issues.chromium.org/issues/511832293 Types: Permissions Required
  2. CVE Modified2026-09-18 14:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
    • SSVC: {"id":"CVE-2026-93384","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-09-17 21:17 UTC· chrome-cve-admin@google.com
    • Description: Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
    • CWE: CWE-918
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/93xxx/CVE-2026-93384.json">CVE-2026-93384</a>
    • Reference: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html