Chrome 153 Patches Seventh Zero-Day of 2026
Google released Chrome 153, addressing 230 security vulnerabilities including the seventh zero-day of 2026. The zero-day, tracked as CVE-2026-87491, is a medium-severity out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine, with known exploitation in the wild. The update also fixes five critical vulnerabilities and 41 high-severity issues affecting components like WebGL and Cast. Users are strongly advised to update to Chrome 153.0.8010.36/.37 on supported platforms promptly.
AI Analysis
Technical Summary
Chrome 153 patches 230 vulnerabilities, including CVE-2026-87491, a medium-severity out-of-bounds write in the V8 engine actively exploited in the wild. This is the seventh zero-day fixed in Chrome during 2026. The update also remediates five critical bugs (use-after-free, out-of-bounds write, buffer overflow) in WebGL and Cast, plus 41 high-severity defects involving use-after-free, race conditions, and authorization issues. Over 180 medium and low-severity bugs were also fixed. The update is available for Windows, macOS, and Linux as versions 153.0.8010.36/.37.
Potential Impact
The zero-day vulnerability CVE-2026-87491 allows out-of-bounds write in the V8 engine, which can lead to memory corruption and potential arbitrary code execution. The presence of known exploits in the wild increases risk to users who do not update. The critical vulnerabilities fixed could also allow remote code execution or privilege escalation. Overall, unpatched Chrome versions are exposed to multiple severe security risks.
Mitigation Recommendations
Google has released an official patch in Chrome version 153.0.8010.36/.37 that addresses this zero-day and other vulnerabilities. Users should update their Chrome browsers immediately to these versions to mitigate the risks. No additional vendor-recommended mitigations are indicated beyond applying the update.
Chrome 153 Patches Seventh Zero-Day of 2026
Description
Google released Chrome 153, addressing 230 security vulnerabilities including the seventh zero-day of 2026. The zero-day, tracked as CVE-2026-87491, is a medium-severity out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine, with known exploitation in the wild. The update also fixes five critical vulnerabilities and 41 high-severity issues affecting components like WebGL and Cast. Users are strongly advised to update to Chrome 153.0.8010.36/.37 on supported platforms promptly.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Chrome 153 patches 230 vulnerabilities, including CVE-2026-87491, a medium-severity out-of-bounds write in the V8 engine actively exploited in the wild. This is the seventh zero-day fixed in Chrome during 2026. The update also remediates five critical bugs (use-after-free, out-of-bounds write, buffer overflow) in WebGL and Cast, plus 41 high-severity defects involving use-after-free, race conditions, and authorization issues. Over 180 medium and low-severity bugs were also fixed. The update is available for Windows, macOS, and Linux as versions 153.0.8010.36/.37.
Potential Impact
The zero-day vulnerability CVE-2026-87491 allows out-of-bounds write in the V8 engine, which can lead to memory corruption and potential arbitrary code execution. The presence of known exploits in the wild increases risk to users who do not update. The critical vulnerabilities fixed could also allow remote code execution or privilege escalation. Overall, unpatched Chrome versions are exposed to multiple severe security risks.
Mitigation Recommendations
Google has released an official patch in Chrome version 153.0.8010.36/.37 that addresses this zero-day and other vulnerabilities. Users should update their Chrome browsers immediately to these versions to mitigate the risks. No additional vendor-recommended mitigations are indicated beyond applying the update.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/","fetched":true,"fetchedAt":"2026-09-09T09:52:45.890Z","wordCount":952}
Threat ID: 6aa12c6dacd9273b491da591
Added to database: 09/09/2026, 09:52:45 UTC
Last enriched: 09/09/2026, 09:52:51 UTC
Last updated: 09/09/2026, 09:52:51 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.