A crafted webpage can now run code inside Chrome’s sandbox, and Google says the bug behind it is being exploited. The company shipped Chrome 153.0.8010.36 for Windows, macOS and Linux on September 9 with fixes for 230 vulnerabilities, including the seventh in-the-wild zero-day of 2026. The flaw, CVE-2026-87491, is an out-of-bounds write in V8, the JavaScript and WebAssembly engine.
Seoul National University’s Jihyeon Jeong found it on August 6 and collected a $2,500 bounty. Google is keeping technical specifics under wraps until most users update, and will hold back details longer if the bug touches a third-party library that other projects share.
Beyond the zero-day, the release repairs five critical flaws in WebGL and the Cast component, plus a use-after-free in WebPackaging reported by OpenAI Codex Security. Google says its own fuzzing and sanitizer tooling uncovered 195 of the 230 bugs.
For managed fleets the instruction is simple: move to 153.0.8010.36 or newer now, because exploit code is in circulation. Seven exploited Chrome zero-days in eight months has turned browser patching into a monthly habit for most teams.
