Google released Chrome 153 for Windows, macOS, Linux, Android, and iOS, fixing 230 reported security vulnerabilities, including CVE-2026-87491, an out-of-bounds write in the V8 JavaScript and WebAssembly engine that is reportedly being exploited in the wild. The release includes five critical and 43 high-severity fixes across WebGL, Cast, ANGLE, PDFium, V8, and WebView; organizations should prioritize updating managed browsers to 153.0.8010.36 or later.
Google has formally reduced Chrome's stable release cycle from four weeks to two weeks, aiming to shorten the N-day window between public disclosure of a flaw and deployment of a patch. The company cited a growing volume of reports and automated AI-assisted security work, alongside faster-moving AI-enabled threats, as drivers for the accelerated cadence; the schedule will also speed delivery and iteration of Chrome features, including AI capabilities.

See which actors are running it and whether you're in range.
11 events from the most recent confirmed update back to the earliest known activity.
CISA added Chrome V8 out-of-bounds write vulnerability CVE-2026-87491 to its Known Exploited Vulnerabilities Catalog after Google reported that an exploit exists in the wild. The Canadian Centre for Cyber Security advised users and administrators to apply available Google updates.
A Tenable Nessus Agent plugin identified CVE-2026-87491 as unpatched on Debian Linux 12.0, 13.0, and 14.0 systems in a Chromium package context. The plugin rated the flaw as network-accessible with low attack complexity, no privileges required, user interaction required, and high confidentiality, integrity, and availability impact.
Tenable documented that Chrome 153.0.8010.36 remediates multiple vulnerabilities, including critical WebGL memory-safety flaws that could permit code execution outside the browser sandbox through crafted HTML. It also identified CVE-2026-87657 as a V8 use-after-free issue and reported no known public exploits for the covered vulnerabilities.
Google patched CVE-2026-85046, an actively exploited type-confusion vulnerability in Chrome's V8 engine. The flaw was patched before the Chrome 153 release that addressed CVE-2026-87491.
Jihyeon Jeong of Seoul National University's Compsec Lab reported the V8 out-of-bounds write vulnerability CVE-2026-87491 to Google. Google awarded Jeong a $2,500 bug bounty for the report.
Chrome changed its standard release cycle from six weeks to four weeks to improve patch management.
Chrome 153 remediated CVE-2026-87639, a serious use-after-free vulnerability in WebPackaging that OpenAI Codex Security identified. The flaw was among the update's 230 security fixes.
Google published a security advisory covering vulnerabilities affecting Chrome versions before 153.0.8010.37, including exploited V8 flaw CVE-2026-87491. Guyana National CIRT recommended that users and administrators review and apply the applicable Chrome update.
CVE-2026-87491 was reported as a CWE-787 V8 out-of-bounds write exploitable when a victim visits a crafted HTML page containing malicious JavaScript, potentially enabling code execution within Chrome's browser sandbox. Versions before 153.0.8010.36 on Windows, Linux, and Android and before 153.0.8010.37 on macOS were identified as affected.
Chrome 153's stable release for Windows, macOS, and Linux included 230 reported security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write vulnerability that Google confirmed was exploited in the wild. The release also addressed five critical and 43 high-severity vulnerabilities.
Google launched Chrome 153 for desktop, iOS, and Android and formally changed Chrome's standard release schedule from four weeks to two weeks. Google said the faster cadence is intended to shorten the N-day patch gap and support faster security and AI-feature iteration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
28 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecysecurity.news
Open sourcecsirt.sk
Open sourcecert.hr
Open sourcetechcrunch.com
Open sourcechromereleases.googleblog.com
Open sourcecirt.gy
Open sourcechromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.