Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Chrome 153 Patches Seventh Zero-Day of 2026

The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible.

Chrome security

Google on Tuesday released Chrome 153 to the stable channel with patches for 230 vulnerabilities, including an exploited zero-day.

Tracked as CVE-2026-87491, the medium-severity security defect is described as an out-of-bounds write issue in Chrome’s V8 JavaScript and WebAssembly engine.

“Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the internet giant notes in its advisory.

The flaw was reported by Jihyeon Jeong of Compsec Lab, Seoul National University, who received a $2,500 bug bounty reward for the finding.

This is the seventh zero-day vulnerability patched in Chrome in 2026. The other six are: CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and CVE-2026-85046.

Five of the newly resolved bugs are critical-severity vulnerabilities: four are use-after-free, out-of-bounds write, and buffer overflow issues in WebGL, and one is a use-after-free weakness in Cast.

Advertisement. Scroll to continue reading.

The fresh Chrome update resolves 41 high-severity security defects, including numerous use-after-free, out-of-bounds read, incorrect/missing authorization, and race condition issues.

Google also patched over 180 medium- and low-severity bugs, including information leak, UI misrepresentation, incorrect reference resolution, incorrect/missing authorization, uninitialized resource, improper validation, clickjacking, and other types of weaknesses.

Per Google’s advisory, only 35 of the 230 vulnerabilities were reported by external researchers. Google says it paid approximately $23,000 in bug bounty rewards for them, but has yet to disclose the amounts handed out for roughly two dozen reports.

The latest Chrome iteration is now rolling out as versions 153.0.8010.36/.37 for Windows and macOS, and as version 153.0.8010.36 for Linux. Users are advised to update their browsers as soon as possible.

Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Related: SAP Patches Critical Extended Passport Processing Vulnerability

Related: MikroTik Patches Critical Flaws Chained to Hack Routers

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.