Back to Feed
VulnerabilitiesSep 9, 2026

Chrome 153 Patches Seventh Zero-Day of 2026

Chrome 153 fixes 230 vulnerabilities, including a zero-day exploited in the wild.

Summary

Google has released Chrome 153 with patches for 230 vulnerabilities, notably including CVE-2026-87491, a medium-severity out-of-bounds write issue in the V8 JavaScript engine that is already being exploited. This marks the seventh zero-day vulnerability addressed in Chrome this year. The update also resolves five critical-severity bugs and numerous high-severity defects.

Full text

Google on Tuesday released Chrome 153 to the stable channel with patches for 230 vulnerabilities, including an exploited zero-day. Tracked as CVE-2026-87491, the medium-severity security defect is described as an out-of-bounds write issue in Chrome’s V8 JavaScript and WebAssembly engine. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the internet giant notes in its advisory. The flaw was reported by Jihyeon Jeong of Compsec Lab, Seoul National University, who received a $2,500 bug bounty reward for the finding. This is the seventh zero-day vulnerability patched in Chrome in 2026. The other six are: CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and CVE-2026-85046. Five of the newly resolved bugs are critical-severity vulnerabilities: four are use-after-free, out-of-bounds write, and buffer overflow issues in WebGL, and one is a use-after-free weakness in Cast.Advertisement. Scroll to continue reading. The fresh Chrome update resolves 41 high-severity security defects, including numerous use-after-free, out-of-bounds read, incorrect/missing authorization, and race condition issues. Google also patched over 180 medium and low-severity bugs, including information leak, UI misrepresentation, incorrect reference resolution, incorrect/missing authorization, uninitialized resource, improper validation, clickjacking, and other types of weaknesses. Per Google’s advisory, only 35 of the 230 vulnerabilities were reported by external researchers. Google says it paid approximately $23,000 in bug bounty rewards for them, but has yet to disclose the amounts handed out for roughly two dozen reports. The latest Chrome iteration is now rolling out as versions 153.0.8010.36/.37 for Windows and macOS, and as version 153.0.8010.36 for Linux. Users are advised to update their browsers as soon as possible. Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day Related: SAP Patches Critical Extended Passport Processing Vulnerability Related: MikroTik Patches Critical Flaws Chained to Hack Routers Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Mathspace Data Breach Exposes Over 1 Million PeopleN-able Patches Critical Zero-Day in N-centralNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitsNorth Korean Hackers Deploy New Linux Espionage ToolkitAdobe Commerce Zero-Day Exploited to Backdoor Online StoresModified ScreenConnect Clients Used in Worm-Like CampaignElementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesHPE Patches Critical RCE Vulnerabilities in AOS-CX Latest News Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-DaysAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-DayThe Hidden Instructions That Can Hijack AI AgentsHackers Return $263 Million Stolen From Liquid NetworkCylake Raises $245 Million Ahead of Cybersecurity Platform BetaSAP Patches Critical Extended Passport Processing VulnerabilityParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin TheftMikroTik Patches Critical Flaws Chained to Hack Routers Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-87491
  • cve — CVE-2026-2441
  • cve — CVE-2026-3909
  • cve — CVE-2026-3910
  • cve — CVE-2026-5281
  • cve — CVE-2026-11645
  • cve — CVE-2026-85046

Entities

Chrome (product)Google (vendor)V8 JavaScript engine (technology)