VMTech
Discuss a project

Google fixes actively exploited V8 flaw in Chrome 153

Google fixes actively exploited V8 flaw in Chrome 153

Google has released a Chrome security update that fixes 230 vulnerabilities, including CVE-2026-87491, a V8 zero-day the company says is being actively exploited in the wild. The issue is an out-of-bounds write in V8, Chrome’s JavaScript and WebAssembly engine, and affects versions before Chrome 153.0.8010.36.

The NIST National Vulnerability Database describes the flaw as allowing a remote attacker to execute arbitrary code inside Chrome’s sandbox by using a crafted HTML page. Google issued Chrome 153.0.8010.36/.37 for Windows and Apple macOS, while the Linux release is 153.0.8010.36.

Active exploitation raises browser patch priority

Google said it is aware of an exploit for CVE-2026-87491 in the wild, but did not disclose the attack method or the parties behind the activity. It said access to bug details and related links can remain restricted until most users have updated, or longer where a third-party library used by other projects has not been fixed.

The vulnerability was discovered and reported on August 6, 2026 by Jihyeon Jeong of Compsec Lab at Seoul National University. Google awarded a $2,500 bug bounty for the responsible disclosure.

This is the seventh actively exploited Chrome zero-day Google has addressed since the start of 2026. The wider pattern is reflected in Chrome patching and endpoint security risks and reinforces why browser releases need the same operational attention as other widely deployed endpoint software.

Other critical fixes affect WebGL and Cast

The update also addresses five critical issues in WebGL and Cast: CVE-2026-87464 and CVE-2026-87488, both use-after-free flaws in WebGL; CVE-2026-87438, an out-of-bounds write in WebGL; CVE-2026-87527, a WebGL buffer overflow; and CVE-2026-87628, a use-after-free flaw in Cast.

Google reported 195 of the 230 issues fixed in this release. OpenAI Codex Security received credit for CVE-2026-87639, a high-severity use-after-free vulnerability in WebPackaging. Google also noted that it finds many security issues through tools including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer and AFL.

What organisations should do

Administrators should verify that managed Windows and macOS devices are on Chrome 153.0.8010.36 or .37, and that Linux devices are on 153.0.8010.36. Users can check through More, Help and About Google Chrome, then select Relaunch to complete installation.

Teams using Chromium-based browsers, including Microsoft Edge, Brave, Opera and Vivaldi, should watch for their vendors’ corresponding releases. The practical business implication is to treat this update as a priority endpoint maintenance task, verify deployment rather than relying on automatic updates alone, and include alternative browsers in the same remediation workflow.

#chromesecurity#zeroday#vulnerability#endpointsecurity
Open analytics
On the site 0 views
min read 3 09.09.2026
Instagram

Google fixes actively exploited V8 flaw in Chrome 153

Open the post on Instagram ↗