Google Patches 7th Chrome Zero-Day of 2026 in 230-Fix Security Update
Updated
Updated · BleepingComputer · Sep 9
Google Patches 7th Chrome Zero-Day of 2026 in 230-Fix Security Update
3 articles · Updated · BleepingComputer · Sep 9
Summary
Google rolled out Chrome 153.0.8010.36 for Windows and Linux and 153.0.8010.37 for Mac to fix CVE-2026-87491, an actively exploited zero-day disclosed Tuesday.
CVE-2026-87491 is a high-severity out-of-bounds write in Chrome’s V8 JavaScript and WebAssembly engine that can let attackers use crafted HTML pages to execute code inside the browser sandbox.
Jihyeon Jeong of Seoul National University’s Compsec Lab reported the flaw two days before the patch, but Google said exploit details will stay restricted until most users are updated.
The fix was part of a 230-vulnerability batch and marks the seventh Chrome zero-day patched this year, following earlier exploited flaws in CSSFontFeatureValuesMap, Skia, Dawn and V8.