Google patches exploited Chrome zero-day CVE-2026-87491 in Chrome 153

Google released Chrome 153 with a fix for an actively exploited security flaw, so Chrome users should update their browsers as soon as possible. The zero-day, CVE-2026-87491, is a medium-severity out-of-bounds write bug in the V8 JavaScript and WebAssembly engine. Google says an in-the-wild exploit exists. Chrome 153 also fixes 230 vulnerabilities total, including five critical flaws, and is rolling out as 153.0.8010.36/.37 for Windows and macOS and 153.0.8010.36 for Linux.
Why it matters: Chrome is one of the world's most widely used browsers, and this flaw was already being exploited before many users patched. The practical action is simple and urgent: update Chrome now on all desktops and managed endpoints.

Sources

Chrome 153 Patches Seventh Zero-Day of 2026
Ionut Arghire 2026.09.09 100% relevant
This article establishes a distinct new event: the Chrome 153 release and Google's patch for the newly identified exploited zero-day CVE-2026-87491, which is not the same underlying event as earlier tracked Chrome 148, 149, 150, 151, or 152 update stories or the separate Chrome zero-day CVE-2026-11645.
← Back to all stories