Updated
Updated · BleepingComputer · Sep 9
Google Patches 7th Chrome Zero-Day of 2026 in 230-Fix Security Update
Updated
Updated · BleepingComputer · Sep 9

Google Patches 7th Chrome Zero-Day of 2026 in 230-Fix Security Update

3 articles · Updated · BleepingComputer · Sep 9

Summary

  • Google rolled out Chrome 153.0.8010.36 for Windows and Linux and 153.0.8010.37 for Mac to fix CVE-2026-87491, an actively exploited zero-day disclosed Tuesday.
  • CVE-2026-87491 is a high-severity out-of-bounds write in Chrome’s V8 JavaScript and WebAssembly engine that can let attackers use crafted HTML pages to execute code inside the browser sandbox.
  • Jihyeon Jeong of Seoul National University’s Compsec Lab reported the flaw two days before the patch, but Google said exploit details will stay restricted until most users are updated.
  • The fix was part of a 230-vulnerability batch and marks the seventh Chrome zero-day patched this year, following earlier exploited flaws in CSSFontFeatureValuesMap, Skia, Dawn and V8.

Insights

Who is secretly exploiting Chrome's massive blind spot before Google can safely warn the public?
Could the AI tools discovering these critical browser bugs be the same ones hackers use to exploit them?
Why did a modest bounty uncover a zero-day vulnerability that cybercriminals are already actively weaponizing?