Cybersecurity

Chrome 153 Fixes 7th Exploited Zero-Day of 2026: CVE-2026-87491

Published 2 min readBy NewUJ Editorial Desk

Updated factual errors corrected

Chrome 153 Fixes 7th Exploited Zero-Day of 2026: CVE-2026-87491
Photo: Google
0 0
XWhatsAppTelegramLinkedIn

Google shipped Chrome 153 to the stable channel on 8 September 2026, and in the same release post stated that it "is aware that an exploit for CVE-2026-87491 exists in the wild." The flaw is an out-of-bounds write in V8, the JavaScript and WebAssembly engine at the core of Chrome. Help Net Security and SecurityWeek, which both covered the update on 9 September, describe it as reachable through nothing more than a specially crafted HTML page, giving an attacker code execution inside the browser's sandbox — no download, no installer, no second step.

It is the seventh actively exploited Chrome zero-day Google has patched in 2026, and the second in under five days. Help Net Security dates the previous one, CVE-2026-85046, to 4 September, and lists the five before it as CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. SecurityWeek reports that the fix ships in Chrome 153.0.8010.36 and .37 for Windows and macOS and 153.0.8010.36 for Linux, in a release closing 230 security issues in total: five rated critical — four use-after-free, out-of-bounds write and buffer overflow bugs in WebGL, plus one use-after-free in Cast — and 41 rated high.

For anyone reading this in Chrome, the practical detail is the one most people skip: the update downloads in the background but does not take effect until the browser is fully relaunched. A machine left open with thirty tabs for a week is still running the vulnerable build. Open chrome://settings/help, wait for the version to read 153.0.8010.36 or later, then click Relaunch. Google rated CVE-2026-87491 medium severity on Chromium's own scale and published no CVSS score, but the rating matters less here than the exploitation status: a medium-rated bug attackers are already using is a more urgent problem than a critical one nobody has weaponised.

What is still missing is most of the substance. Google withholds technical detail until the majority of users have updated — standard practice that also keeps the targets and the delivery method out of public view. Help Net Security reports that the flaw was submitted on 6 August 2026 by Jihyeon Jeong of the Compsec Lab at Seoul National University, who received a $2,500 reward; SecurityWeek adds that the release paid roughly $23,000 across 35 externally reported bugs. Neither Google's post nor the coverage explains the month between that report and the patch, or says whether the in-the-wild attacks began before or after it. Technical write-ups typically appear weeks later, once the fix has propagated widely.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.