Google has issued an urgent update to Chrome 153 following the discovery that a zero-day flaw in the browser’s V8 engine is actively being exploited by attackers, prompting a critical security patch for users worldwide.
Google has released Chrome 153 after confirming that attackers are already using a newly disclosed zero-day flaw in the browser’s V8 engine. The vulnerability, tracked as CVE-2026-87491, is an out-of-bounds write that can let a specially crafted HTML page force Chrome to write data beyond the intended memory area, potentially corrupting content and enabling code execution within the browser’s sandbox.
The risk is serious even with Chrome’s isolation mechanisms in place. In practice, a successful attacker would still need a second weakness to break out of the sandbox or gain extra privileges on the device. Google has not said who is behind the attacks, which targets are affected, or whether CVE-2026-87491 is being used alone or alongside another flaw.
Help Net Security reported that the bug was identified by Jihyeon Jeong of Seoul National University’s Compsec Lab on 6 August 2026 and earned a $2,500 bounty. SecurityWeek said the update closes 230 security issues in total and described CVE-2026-87491 as the seventh Chrome zero-day of 2026. Some security trackers rate the flaw as high severity, underlining the urgency of patching.
Google says users should update to Chrome 153.0.8010.36 or later on Windows, macOS and Linux. The browser usually downloads the update automatically in the background, but it must be restarted before the fix takes effect.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





