Microsoft Security Response Center guidance
Release Notes
Vendor-listed releases
- 153.0.4234.48
Vulnerability intelligence
CVE-2026-93378 and is rated Low severity with a CVSS score of 3.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)