ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Google patches actively exploited Chrome V8 flaw CVE-2026-87491 in Chrome 153 stable update

highAdvisoryexploited in the wildimportance 79CVE-2026-87491
What's new: Initial merge; no previous story summary exists for this incident.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Google shipped a Chrome stable channel update fixing 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write in the V8 JavaScript engine confirmed exploited in the wild. CISA added the flaw to its Known Exploited Vulnerabilities catalog on…

Google released a stable channel desktop update fixing vulnerabilities in Chrome prior to 153.0.8010.37, per an advisory from the Canadian Centre for Cyber Security (AV26-904) dated September 9, 2026. Malwarebytes Labs reports the update ships as 153.0.8010.36/.37 for Windows and Mac and 153.0.8010.36 for Linux, containing 230 security fixes, including five Critical vulnerabilities, four of which are in WebGL. The actively exploited flaw is CVE-2026-87491, an out-of-bounds write in Chrome's V8 JavaScript engine that a crafted HTML page can exploit to execute arbitrary code inside the browser sandbox. Google rates the flaw medium severity, but its in-the-wild exploitation is confirmed, and CISA added it to the KEV catalog on September 9, 2026. The Canadian Centre for Cyber Security urged users and administrators to apply the update. Sources differ slightly on the exact patched build: CCCS advises 153.0.8010.37 or later, while Malwarebytes cites 153.0.8010.36/.37 (Windows/Mac) and 153.0.8010.36 (Linux); Windows and Mac users should be on 153.0.8010.37 or later to satisfy both advisories. Remediation is via Settings > About Chrome followed by a browser restart.

  • CVE-2026-87491 is an out-of-bounds write in Chrome's V8 JavaScript engine, confirmed exploited in the wild.
  • A crafted HTML page can exploit the flaw to execute arbitrary code inside the browser sandbox (per Malwarebytes).
  • Google rates CVE-2026-87491 medium severity despite confirmed active exploitation (per Malwarebytes).
  • CISA added CVE-2026-87491 to its Known Exploited Vulnerabilities catalog on September 9, 2026.
  • The Canadian Centre for Cyber Security issued advisory AV26-904 on 2026-09-09 urging users to update.
  • Chrome stable 153.0.8010.36/.37 for Windows and Mac and 153.0.8010.36 for Linux include 230 security fixes (per Malwarebytes); CCCS cites patching via 153.0.8010.37 or later.
  • The update includes five Critical vulnerabilities, four of which were found in WebGL (per Malwarebytes).
  • Remediation: update via Settings > About Chrome and restart the browser.

Coverage timeline

  1. · 6d ago
    Canadian Centre for Cyber Security· 79
    Google security advisory (AV26-904)

    Google patches Chrome CVE-2026-87491, exploited in the wild and added to CISA's KEV; users should update to 153.0.8010.37.

  2. · 5d ago
    Malwarebytes Labs· 75
    Update Chrome now to protect against an actively exploited vulnerability

    Google shipped Chrome 153.0.8010.36/.37 fixing 230 flaws including actively exploited V8 out-of-bounds write CVE-2026-87491 enabling sandboxed code execution.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87491
Actively Exploited Out-of-Bounds Write in Google Chrome V8

CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown.

Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching.

8.8<1% KEV
  • Google Chrome (V8 JavaScript engine; tracked by CISA as 'Google Chromium V8') prior to 153.0.8010.36
massbillions of installations (Chrome's install base exceeds 3 billion users)