Google on Tuesday released Chrome 153 to the stable channel with patches for 230 vulnerabilities, including an exploited zero-day.
Tracked as CVE-2026-87491, the medium-severity security defect is described as an out-of-bounds write issue in Chrome’s V8 JavaScript and WebAssembly engine.
“Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the internet giant notes in its advisory.
The flaw was reported by Jihyeon Jeong of Compsec Lab, Seoul National University, who received a $2,500 bug bounty reward for the finding.
This is the seventh zero-day vulnerability patched in Chrome in 2026. The other six are: CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and CVE-2026-85046.
Five of the newly resolved bugs are critical-severity vulnerabilities: four are use-after-free, out-of-bounds write, and buffer overflow issues in WebGL, and one is a use-after-free weakness in Cast.
The fresh Chrome update resolves 41 high-severity security defects, including numerous use-after-free, out-of-bounds read, incorrect/missing authorization, and race condition issues.
Google also patched over 180 medium- and low-severity bugs, including information leak, UI misrepresentation, incorrect reference resolution, incorrect/missing authorization, uninitialized resource, improper validation, clickjacking, and other types of weaknesses.
Per Google’s advisory, only 35 of the 230 vulnerabilities were reported by external researchers. Google says it paid approximately $23,000 in bug bounty rewards for them, but has yet to disclose the amounts handed out for roughly two dozen reports.
The latest Chrome iteration is now rolling out as versions 153.0.8010.36/.37 for Windows and macOS, and as version 153.0.8010.36 for Linux. Users are advised to update their browsers as soon as possible.
Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Related: SAP Patches Critical Extended Passport Processing Vulnerability
Related: MikroTik Patches Critical Flaws Chained to Hack Routers
