Google released Chrome 153 this week to patch a zero-day vulnerability that attackers were already exploiting in the wild, the seventh actively exploited Chrome flaw the company has had to fix so far in 2026.
The bug, tracked as CVE-2026-87491, is an out-of-bounds memory issue in the V8 JavaScript engine that powers Chrome. Google says a remote attacker could exploit it through a crafted webpage to run arbitrary code inside the browser’s sandbox. The company confirmed an exploit for the flaw exists in the wild but has not disclosed who is using it or against whom.
How was the Chrome flaw discovered?
Jihyeon Jeong, a research intern at Seoul National University’s Compsec Lab, reported the vulnerability to Google and received a $2,500 bug bounty for the find. Google has rolled the fix out to the stable desktop channel, with patched builds numbered 153.0.8010.36 for Windows and Linux and 153.0.8010.37 for Mac.
Chrome’s V8 engine has been a repeated target this year because it sits at the center of how the browser executes code from every webpage a user visits, making a successful exploit there valuable to attackers regardless of what site delivers it. Chrome 153 addresses 230 vulnerabilities in total alongside the zero-day fix.
What should Chrome users do?
Security researchers recommend users update immediately rather than waiting for Chrome’s automatic update cycle, since the flaw is already being used in attacks. Users can trigger an update manually from Chrome’s menu under Help, then About Google Chrome, which prompts an immediate download and installation of the latest version.
Google has not said whether the seven zero-days patched this year point to a single well-resourced actor or several unrelated efforts, but the pace matches roughly last year’s total and keeps Chrome among the most frequently targeted consumer software platforms.
Sources: The Hacker News · BleepingComputer · SecurityWeek







