Cyber Security News

Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild

Google has rolled out Chrome 153 to the stable channel for Windows, Mac, and Linux, shipping as version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.

The update will reach users over the coming days and weeks and includes 230 security fixes, one of the largest patch batches in recent Chrome release history.

Actively Exploited 0-Day

The most critical issue in this release is CVE-2026-87491, a Medium-severity out-of-bounds write vulnerability in V8, Chrome’s JavaScript and WebAssembly engine. Google has confirmed that an exploit for this flaw already exists in the wild, making immediate updates essential for all users.

Jihyeon Jeong of Compsec Lab at Seoul National University reported the bug and earned a $ 2,500 bounty for the discovery. Despite its “Medium” classification, active exploitation of a V8 memory-corruption bug matters, since V8 flaws are often chained with sandbox-escape vulnerabilities to achieve remote code execution.

Beyond the zero-day, Chrome 153 closes five Critical-rated vulnerabilities, most involving use-after-free and out-of-bounds write conditions in WebGL and Cast components. Notable entries include CVE-2026-87464, CVE-2026-87488, CVE-2026-87438, CVE-2026-87527, and CVE-2026-87628, several of which Google’s security team discovered internally.

The update also resolves 43 High-severity bugs spanning ANGLE, PDFium, V8, Views, DevTools, Web Authentication, and Payments modules. Several of these, including CVE-2026-87512 in ANGLE and CVE-2026-87585 in PDFium, carried bounty rewards of up to 2,500 dollars.

External researchers flagged several high-severity issues using AI-assisted tools, including OpenAI’s Codex Security team, reflecting the growing role of automated vulnerability discovery in browser security.

The bulk of the release consists of 141 Medium-severity fixes and 41 Low-severity fixes, covering categories such as incorrect authorization, missing authorization, UI misrepresentation, and information leaks across components like FileSystem, ServiceWorker, Extensions, Safebrowsing, and Payments.

One standout bounty went to CVE-2026-87504, a use-after-free in Core rewarded at 5,000 dollars, while CVE-2026-87640 in WebView earned 3,000 dollars, both credited to the same researcher.

Why This Update Is Important

With 230 fixes packed into a single release and confirmed in-the-wild exploitation of at least one flaw, Chrome 153 represents a high-priority update for enterprises and individual users alike.

Google continues to rely on tools like AddressSanitizer, MemorySanitizer, and libFuzzer to catch these issues before they reach production, but the scale of this fix batch underscores how actively browser engines remain a target for both researchers and threat actors.

Users should update to build 153.0.8010.36 or later without delay.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago