GOOGLE has released Chrome version 153, fixing 42 security defects, including three vulnerabilities highlighted in the report. CVE-2026-91749 is rated critical with a CVSSv3 score of 9.6 and involves an out-of-bounds read in the WebGL component. CVE-2026-91721 is rated high at 8.8, while CVE-2026-91726 is rated medium at 4.7. All three are fixed in version 153.0.8010.47. The report says none is confirmed as actively exploited and that no public proof-of-concept code is available.
According to the article, an attacker could use a malicious web page to trigger memory errors. The other two highlighted issues are use-after-free flaws affecting Chrome’s Internals component and Web Workers. The claimed impact includes unauthorised command execution on the host, although the report does not provide evidence that this has occurred in attacks. Older Chrome installations on Windows, macOS and Linux are affected.
Google’s Stable channel update is version 153.0.8010.47 for Linux, while Windows and Mac users receive version 153.0.8010.47 or 153.0.8010.48. Chrome normally installs updates automatically, but users are advised to check the installed version and restart the browser so the update takes effect.