Chrome 153 Fixes 7th Exploited Zero-Day of 2026: CVE-2026-87491

Google shipped Chrome 153 to the stable channel on 8 September 2026, and in the same release post stated that it "is aware that an exploit for CVE-2026-87491 exists in the wild." The flaw is an out-of-bounds write in V8, the JavaScript and WebAssembly engine at the core of Chrome. Help Net Security and SecurityWeek, which both covered the update on 9 September, describe it as reachable through nothing more than a specially crafted HTML page, giving an attacker code execution inside the browser's sandbox — no download, no installer, no second step.
It is the seventh actively exploited Chrome zero-day Google has patched in 2026, and the second in under five days. Help Net Security dates the previous one, CVE-2026-85046, to 4 September, and lists the five before it as CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. SecurityWeek reports that the fix ships in Chrome 153.0.8010.36 and .37 for Windows and macOS and 153.0.8010.36 for Linux, in a release closing 230 security issues in total: five rated critical — four use-after-free, out-of-bounds write and buffer overflow bugs in WebGL, plus one use-after-free in Cast — and 41 rated high.
For anyone reading this in Chrome, the practical detail is the one most people skip: the update downloads in the background but does not take effect until the browser is fully relaunched. A machine left open with thirty tabs for a week is still running the vulnerable build. Open chrome://settings/help, wait for the version to read 153.0.8010.36 or later, then click Relaunch. Google rated CVE-2026-87491 medium severity on Chromium's own scale and published no CVSS score, but the rating matters less here than the exploitation status: a medium-rated bug attackers are already using is a more urgent problem than a critical one nobody has weaponised.
What is still missing is most of the substance. Google withholds technical detail until the majority of users have updated — standard practice that also keeps the targets and the delivery method out of public view. Help Net Security reports that the flaw was submitted on 6 August 2026 by Jihyeon Jeong of the Compsec Lab at Seoul National University, who received a $2,500 reward; SecurityWeek adds that the release paid roughly $23,000 across 35 externally reported bugs. Neither Google's post nor the coverage explains the month between that report and the patch, or says whether the in-the-wild attacks began before or after it. Technical write-ups typically appear weeks later, once the fix has propagated widely.
Sources
Related
Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
CISA Adds 5 Exploited Flaws; ScreenConnect Rated CVSS 9.9
GitLab CVSS 10.0 Flaw Exploited; CISA Deadline Is September 14
Cisco Firewall Flaw Rated 10.0 Exploited; US Orders Patch by Sept 12
IDScan.net Confirms Cloud Breach; 153M ID Scans on Sale
Microsoft Patches Two Exploited Windows Zero-Days; CISA Sets Sept. 22
CERT Polska: MikroTik SSH Flaw Exploited Since September 2
Manchester Airport Breach: 8.8M Hit by 4-Year API Flaw
Trending now
- US Diesel Sets Record $6.23 a Gallon, AAA Figures Show
- Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
- DeepMind AGI Safety Researcher Quits, Turns Down Anthropic, OpenAI
- Apple Ships iOS 27 With Siri AI, but Not for EU iPhones
- King Charles Convenes AI Leaders in Scotland, Palace Confirms
- Amazon Cuts Ties With 21 Air After Miami Crash That Killed 5
- Tom Aspinall Vacates UFC Heavyweight Title Over Eye Injury
- Treasury Yield Tops 5.014%, Highest Since 2023, Then Retreats
Comments
No comments yet. Be the first.