Google fixes in-the-wild V8 bug as Chrome zero-day count hits seven

Chrome 153 closes an out-of-bounds write in V8 that Google says is exploited in the wild, the browser's seventh zero-day of 2026.

CSBadmin
1 Min Read

A crafted webpage can now run code inside Chrome’s sandbox, and Google says the bug behind it is being exploited. The company shipped Chrome 153.0.8010.36 for Windows, macOS and Linux on September 9 with fixes for 230 vulnerabilities, including the seventh in-the-wild zero-day of 2026. The flaw, CVE-2026-87491, is an out-of-bounds write in V8, the JavaScript and WebAssembly engine.

Seoul National University’s Jihyeon Jeong found it on August 6 and collected a $2,500 bounty. Google is keeping technical specifics under wraps until most users update, and will hold back details longer if the bug touches a third-party library that other projects share.

Beyond the zero-day, the release repairs five critical flaws in WebGL and the Cast component, plus a use-after-free in WebPackaging reported by OpenAI Codex Security. Google says its own fuzzing and sanitizer tooling uncovered 195 of the 230 bugs.

For managed fleets the instruction is simple: move to 153.0.8010.36 or newer now, because exploit code is in circulation. Seven exploited Chrome zero-days in eight months has turned browser patching into a monthly habit for most teams.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.