Overview
- Google rolled out Chrome 153 on Tuesday with fixes for 230 vulnerabilities and said an exploit for CVE-2026-87491 is being used in the wild.
- CVE-2026-87491 is an out-of-bounds write in the V8 JavaScript and WebAssembly engine that can allow a remote attacker to execute arbitrary code inside Chrome’s sandbox by loading a crafted HTML page.
- The patched builds are available for Windows, macOS and Linux as versions 153.0.8010.36/.37, but Google says the update rollout could take days or weeks and some users may need to restart or manually check for updates to receive the fix.
- The bug was reported to Google on August 6 by Jihyeon Jeong of the Compsec Lab at Seoul National University, who received a $2,500 bounty, and it is the seventh actively exploited Chrome zero‑day Google has fixed in 2026.
- Organizations and individual users should update immediately, monitor other Chromium browsers for equivalent patches, and expect Google to limit technical disclosure until most users and dependent projects are protected.