Google released Chrome 153 to the Stable channel, fixing 42 security vulnerabilities, including three Critical memory-safety flaws: use-after-free vulnerabilities in Internals (CVE-2026-91721) and Workers (CVE-2026-91749), plus an out-of-bounds read in WebGL (CVE-2026-91726). The update also addresses 27 High-severity issues affecting components including V8, ServiceWorker, Core, Extensions, Skia, ANGLE, PDF, WebPackaging, and Input. High-severity use-after-free bugs include CVE-2026-87639 in WebPackaging, reported by amyb of OpenAI Codex Security, and CVE-2026-87542 in Input, reported by BigSleep@Grape.
Google has not reported active exploitation of any of the fixed vulnerabilities and withheld technical exploit details. Organizations should deploy Chrome 153.0.8010.47/.48 on Windows and macOS or 153.0.8010.47 on Linux, confirm managed endpoints have completed the update and restarted the browser, and investigate devices delayed by update policies or incomplete rollout.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Chrome 153 addressed CVE-2026-87542, a High-severity use-after-free vulnerability in Chrome's Input component. Google credited BigSleep@Grape with reporting the vulnerability.
Chrome 153 addressed CVE-2026-87639, a High-severity use-after-free vulnerability in the WebPackaging component. Google credited researcher “amyb,” working with OpenAI Codex Security, for reporting the issue.
On September 8, 2026, Google released Chrome 153 to the Stable channel. The update addressed 42 reported vulnerabilities, including three Critical flaws—CVE-2026-91721, CVE-2026-91749, and CVE-2026-91726—and 27 High-severity issues; the advisory did not report active exploitation of the fixed flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcebugflation.com
Open sourcebugflation.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.