Google Fixes Actively Exploited V8 Vulnerability in Chrome 153

Chrome 153 fixes CVE-2026-87491 in V8, which Google knows is being exploited in the wild. Desktop users should update their browser.

Chrome 153 and the V8 vulnerability involve CVE-2026-87491, an actively exploited vulnerability that Google fixed in the stable desktop browser version released on September 8. The flaw is located in the V8 engine for JavaScript and WebAssembly, and Google confirmed that it is aware of an exploit in the wild.

The Chrome 153 update includes a total of 230 security fixes. Google released version 153.0.8010.36 for Linux and Windows, and version 153.0.8010.37 for macOS. The rollout is gradual, so the new version may not appear for all users at the same time.

Chrome 153 and the V8 vulnerability: What Google fixed

CVE-2026-87491 is an out-of-bounds write vulnerability in V8, a Chrome component that processes JavaScript and WebAssembly code on websites. Google classified it as medium severity, but its priority is increased by confirmed active exploitation.

According to the National Vulnerability Database entry, a specially crafted HTML page could exploit the flaw to execute arbitrary code within the browser sandbox. The confirmed impact therefore concerns Chrome’s isolated environment, not the entire operating system directly.

Google has not disclosed technical details of the exploitation, information about the attackers, the scope of any campaign, or the number of affected users.

Updating is the available mitigation

For desktop Chrome users, the practical step is to update to the fixed version.

  • Linux: Chrome 153.0.8010.36
  • Windows: Chrome 153.0.8010.36
  • macOS: Chrome 153.0.8010.37

Since Google is rolling out the update gradually, the fixed version may not be available to all users at once. The information applies to Chrome’s stable desktop channel.

What has not been confirmed yet

Although the NVD states that code execution in the browser sandbox is possible, it has not been confirmed that CVE-2026-87491 alone enables a sandbox escape or compromise of the operating system. Claims that the entire device was taken over would therefore go beyond the publicly confirmed information.

Secondary sources describe CVE-2026-87491 as the seventh actively exploited Chrome zero-day vulnerability in 2026. Google’s announcement, however, directly confirms mainly that an exploit for this specific flaw exists in the wild.

Further developments will depend on whether Google or security researchers publish technical details, attribution of the attacks, or other information about the campaign. Completing the gradual rollout of the fixed Chrome 153 versions will also be important.

Sources

  • Chrome Releases – Confirms the release of Chrome 153, 230 fixes, the affected versions, the nature of CVE-2026-87491, and that Google is aware of an exploit in the wild.
  • NIST National Vulnerability Database – States that the V8 vulnerability before version 153.0.8010.36 could lead to arbitrary code execution in the sandbox through a specially crafted HTML page.
  • BleepingComputer – Independently corroborates the active exploitation and released versions, and notes that Google has not disclosed attack details.
  • SecurityWeek – Corroborates the number of fixes, the classification of the V8 flaw, and the context of the seventh actively exploited Chrome zero-day in 2026.

Verified and updated: 09/09/2026 15:26

Sharing