securityonline.info 9 Sept 2026, 00:16 UTC

Chrome 153 Patches Exploited V8 Zero Day and 229 Flaws

Chrome 153 Patches Exploited V8 Zero Day and 229 Flaws
CyberSIXT Evidence Panel

GOOGLE has released Chrome 153 to address 230 security flaws, including a zero-day vulnerability in the V8 JavaScript engine that is already being exploited in the wild. The flaw, CVE-2026-87491, is described as an out-of-bounds write in V8 that could allow a remote attacker to hijack browser execution via a malicious webpage. The disclosure underscores the breadth of risk given Chrome’s ubiquity across billions of devices, and the need for users to update promptly.

Affected builds are earlier than 153.0.8010.36, with the patch delivered in Chrome 153.0.8010.36 on Linux and 153.0.8010.36/0.37 on Windows and macOS. The article notes that CVE-2026-87491 is “exploited in the wild” and that CVSS analysis is still to come. The update also fixes five WebGL and Cast issues, including use-after-free flaws CVE-2026-87464 and CVE-2026-87628, which could enable remote code execution through a crafted page.

Practical response recommended is to update Chrome promptly via Settings > About Chrome and restart the browser; Chromium-based browsers sharing the same engine should also be updated.

View full article

Article by CyberSIXT