www.malwarebytes.com 10 Sept 2026, 10:52 UTC

Chrome Patches 230 Flaws as Hackers Exploit V8 Bug

Chrome Patches 230 Flaws as Hackers Exploit V8 Bug
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

CHROME is rolling out an update for its desktop browser that addresses 230 security fixes, including one that is known to be actively exploited. The patch is available in the stable channel, with Windows and macOS builds at 153.0.8010.36/.37 and Linux at 153.0.8010.36. The actively exploited flaw is tracked as CVE-2026-87491, described as an out-of-bounds write in Chrome’s V8 JavaScript engine that could allow a remote attacker to run arbitrary code inside the browser sandbox via a crafted HTML page.

The breach relies on a target loading a malicious page that manipulates memory within the JavaScript engine, potentially giving the attacker a foothold even though code would run inside the sandbox rather than directly on the device.

In addition to CVE-2026-87491, the update fixes five vulnerabilities rated Critical, four of which were found in WebGL. WebGL is a JavaScript API used for rendering interactive graphics in the browser without plugins. The article emphasises practical mitigation: users should update Chrome promptly, either by allowing automatic updates or by manually navigating to More > Settings > About Chrome and following prompts to restart once the update has downloaded.

The piece notes that keeping the browser up to date reduces immediate exposure to active exploits and highlights that email clients are less likely to trigger the flaw, though links in emails could lead to malicious sites.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline