GOOGLE released Chrome 153 to the stable channel on 9 September 2026, delivering fixes for 230 vulnerabilities and notably addressing a zero-day that is already being exploited in the wild. The CVE tracked as CVE-2026-87491 is described as an out-of-bounds write flaw in Chrome’s V8 JavaScript and WebAssembly engine. The advisory states that exploitation exists in the wild, underscoring the urgency of updating. The flaw was reported by Jihyeon Jeong of Compsec Lab, Seoul National University, who received a $2,500 bug bounty for the finding.
Among the patched issues, five are classified as critical-severity: four are use-after-free, out-of-bounds write, or buffer overflow vulnerabilities in WebGL, and one is a use-after-free weakness in Cast. In total, Google resolved 41 high-severity defects and more than 180 medium and low-severity bugs, addressing problems ranging from information leakage and incorrect authorisation to race conditions and improper validation.
Only 35 of the 230 vulnerabilities were reported by external researchers, with Google noting about $23,000 paid in bug bounties for those disclosures; rewards for the remaining reports have not been disclosed. The update rolls out as Chrome versions 153.0.8010.36/37 for Windows and macOS, and 153.0.8010.36 for Linux. Users are advised to update as soon as possible to mitigate the risk from these issues.