Chrome 153 Patches 230 Vulnerabilities, Including One Actively Exploited Zero-Day
Key Takeaways Google has released Chrome version 153, addressing 230 security vulnerabilities. The update includes a critical zero-day flaw (CVE-2026-87491) in the V8 JavaScript engine that is...
Key Takeaways
- Google has released Chrome version 153, addressing 230 security vulnerabilities.
- The update includes a critical zero-day flaw (CVE-2026-87491) in the V8 JavaScript engine that is actively being exploited.
- The patch is available for Windows, Mac, and Linux, and users are urged to update immediately.
Google has pushed out Chrome 153 to its stable channel for desktop platforms, including Windows, Mac, and Linux. The update arrives as version 153.0.8010.36 for Linux systems and 153.0.8010.36/.37 for Windows and Mac users. This significant release, containing 230 security patches, represents one of the largest vulnerability remediation efforts in Chrome’s recent history and will be distributed to users over the coming days and weeks.
Table Of Content
Actively Exploited Zero-Day
The most pressing concern addressed in this update is CVE-2026-87491, a medium-severity out-of-bounds write vulnerability found in V8, Chrome’s JavaScript and WebAssembly engine. Google has confirmed that this flaw is already under active exploitation in real-world attacks, making prompt installation of the update crucial for all users.
Jihyeon Jeong of Compsec Lab at Seoul National University was credited with reporting this bug, receiving a $2,500 bounty. While classified as “Medium,” the active exploitation of a V8 memory corruption bug is particularly concerning. Such vulnerabilities are frequently chained with other flaws, like sandbox escapes, to achieve remote code execution, elevating their practical severity beyond their initial CVSS rating.
Beyond the zero-day, Chrome 153 remediates five critical-rated vulnerabilities. Most of these involve use-after-free and out-of-bounds write conditions within the WebGL and Cast components. Specific critical issues include CVE-2026-87464, CVE-2026-87488, CVE-2026-87438, CVE-2026-87527, and CVE-2026-87628. Several of these were discovered internally by Google’s security research team.
The update also resolves 43 high-severity bugs impacting various modules such as ANGLE, PDFium, V8, Views, DevTools, Web Authentication, and Payments. Notable high-severity fixes include CVE-2026-87512 in ANGLE and CVE-2026-87585 in PDFium, each earning bounties up to $2,500 for their discoverers.
Interestingly, some high-severity issues were identified by external researchers utilizing AI-assisted tools, including OpenAI’s Codex Security team. This highlights the increasing integration of automated vulnerability discovery methods in enhancing browser security.
The bulk of the release consists of 141 medium-severity and 41 low-severity fixes. These cover a wide array of categories, including incorrect authorization, missing authorization, UI misrepresentation, and information leaks across components like FileSystem, ServiceWorker, Extensions, Safebrowsing, and Payments.
Among the bounties awarded, CVE-2026-87504, a use-after-free vulnerability in Core, received a notable $5,000. Additionally, CVE-2026-87640 in WebView garnered $3,000, with both significant payouts credited to the same researcher.
Why This Update Is Important
With a staggering 230 fixes in a single release and confirmed in-the-wild exploitation of at least one vulnerability, Chrome 153 is a high-priority update for both enterprise environments and individual users.
Google continues to leverage advanced tools such as AddressSanitizer, MemorySanitizer, and libFuzzer to identify and address these issues before they impact production environments. However, the sheer volume of this patch batch underscores the persistent targeting of browser engines by both security researchers and malicious actors.
What You Should Do
- Update your Google Chrome browser to version 153.0.8010.36 or later immediately.
- Verify your Chrome version by navigating to Settings > About Chrome. The browser should automatically initiate the update if not already applied.
- Enable automatic updates to ensure you receive future security patches promptly.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.