Chrome 153 patches seventh zero-day of 2026

Google released Chrome 153 to the stable channel, fixing 230 bugs including an exploited zero-day, CVE-2026-87491, an out-of-bounds write in the V8 JavaScript and WebAssembly engine.
Google released Chrome 153 to the stable channel on Tuesday, patching 230 vulnerabilities including an exploited zero-day tracked as CVE-2026-87491. The flaw is described as an out-of-bounds write in Chrome’s V8 JavaScript and WebAssembly engine.
Google’s advisory states, “Google is aware that an exploit for CVE-2026-87491 exists in the wild.” The vulnerability was reported by Jihyeon Jeong of Compsec Lab at Seoul National University; Jeong received a $2,500 bug bounty for the report.
The update fixes five critical-severity bugs. Four of those are in WebGL and involve use-after-free, out-of-bounds write and buffer overflow conditions. The fifth is a use-after-free issue in Cast.Advertisement. The release also resolves 41 high-severity defects, including use-after-free, out-of-bounds read, missing or incorrect authorization and race condition issues.
More than 180 medium- and low-severity bugs are addressed as well. Google lists fixes for information leaks, UI misrepresentation, incorrect reference resolution, uninitialized resources, improper validation and clickjacking weaknesses among the patched defects.
According to Google’s advisory, 35 of the 230 issues were reported by external researchers. Google paid approximately $23,000 in bounty rewards for those reports and has not disclosed the payout amounts for roughly two dozen other reports. CVE-2026-87491 is the seventh zero-day patched in Chrome this year; earlier fixes include CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645 and CVE-2026-85046.
Chrome 153 is rolling out as versions 153.0.8010.36 and 153.0.8010.37 for Windows and macOS, and as 153.0.8010.36 for Linux. Users and administrators are advised to install the update promptly to reduce exposure to the known exploit and other serious vulnerabilities.







