Chrome 153 Patches Seventh Zero-Day of 2026
Google on Tuesday released Chrome 153 to the stable channel with patches for 230 vulnerabilities, including an exploited zero-day.
Tracked as CVE-2026-87491, the medium-severity security defect is described as an out-of-bounds write issue in Chrome’s V8 JavaScript and WebAssembly engine.
“Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the internet giant notes in its advisory.
The flaw was reported by Jihyeon Jeong of Compsec Lab, Seoul National University, who received a $2,500 bug bounty reward for the finding.
This is the seventh zero-day vulnerability patched in Chrome in 2026. The other six are: CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and CVE-2026-85046.
Five of the newly resolved bugs are critical-severity vulnerabilities: four are use-after-free, out-of-bounds write, and buffer overflow issues in WebGL, and one is a use-after-free weakness in Cast.
Advertisement. Scroll to continue reading.
The fresh Chrome update resolves 41...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE