TL;DR
Google released Chrome 153 to fix 230 security flaws. One is a Chrome zero-day, CVE-2026-87491, already exploited in the wild. Users should update their browser right away.
- CVE: CVE-2026-87491
- CVSS: Awaiting analysis
- Product: Google Chrome
- Affected: 153.0.8010.36
- Impact: CWE-787
- Status: Exploited in the wild
- Patched in: 153.0.8010.36
- Action: Update to 153.0.8010.36 now
Why This Chrome Zero-Day Matters
Google confirmed an active exploit for CVE-2026-87491. The flaw sits in V8, the JavaScript engine that runs on every Chrome install. Attackers can reach it through a malicious web page.
Chrome runs on billions of devices worldwide. A working exploit against this Chrome zero-day puts a huge user base at risk. That scale makes fast patching urgent.
How the Attack Works
CVE-2026-87491 is an out-of-bounds write in V8. Such bugs let attackers corrupt memory and hijack browser execution. Google withheld exploit details until most users update.
The update also fixes five critical bugs in WebGL and Cast. These include use-after-free flaws CVE-2026-87464 and CVE-2026-87628. Each could allow remote code execution through a crafted page.
Affected Versions
All Chrome builds before 153 are affected. The fixed builds are 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac. The rollout reaches users over the coming days.
Patch and Mitigation Steps
Update Chrome now through Settings, then About Chrome. Restart the browser to apply the fix. Full details appear in the official Chrome stable channel release notes.
Chromium-based browsers like Edge, Brave, and Opera share the same engine. Watch for their updates and apply them too. No safe workaround replaces installing the patch.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!