Chrome 153 fixes CVE-2026-87491, a V8 engine flaw already being exploited in the wild, making it the seventh actively exploited Chrome zero-day of 2026. Update by relaunching Chrome now, don't wait for auto-update.
Read the full story: Chrome 153 Patches Seventh Zero-Day of 2026, CVE-2026-87491 →
Transcript
Google just shipped Chrome 153, and one of the bugs it fixes was already being used in attacks. CVE-2026-87491 is an out of bounds write in V8, Chrome's JavaScript engine. Visit the wrong page and it can corrupt memory and run attacker code, no download required. It's the seventh actively exploited Chrome zero-day patched this year alone. A researcher at Seoul National University found it and got a two thousand five hundred dollar bounty for the catch.
Google isn't saying who's behind the attacks yet, that's normal for a fresh zero-day. What matters is what you do next. Open your Chrome settings page, check the version reads 153 point 0 point 8010 point 36 or newer, then relaunch the browser. The patch does nothing until you restart. Seven zero days in one year is a lot. Don't be the reason number seven gets you.