we_are_coded.by CODE · The world, decoded
БГ
Google

Chrome 153 fixed 230 security holes, and one of them in V8 is already used in attacks

Google Chrome Releases · event date: 9 September 2026Security

Google released Chrome 153 on 8 September with 230 security fixes and wrote that it is aware of an exploit in the wild for CVE-2026-87491. The next day CISA added the vulnerability to its catalog of actively exploited flaws. Other Chromium browsers are affected too.

In short
  • CVE-2026-87491: an out-of-bounds write in V8, the engine that runs JavaScript.
  • Google rates it Medium, yet it is the only one of the 230 for which it says an exploit exists in the wild.
  • The KEV deadline is 23 September; CISA also names Microsoft Edge and Opera as possibly affected.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Medium. That is how Google rated the severity of CVE-2026-87491 in its own list. The same flaw is the only one of 230 for which the company writes that an exploit exists in the wild.

The two don't contradict each other. The rating measures what the flaw can do on its own. The attack shows what someone is already doing with it.

The facts: on 8 September 2026 Google promoted Chrome 153 to the stable channel (153.0.8010.36 for Linux and 153.0.8010.36/.37 for Windows and Mac) with 230 security fixes. Among them is CVE-2026-87491, an out-of-bounds write in V8, rated Medium in Google's list; it was reported on 6 August by Jihyeon Jeong (Compsec Lab, Seoul National University). Google writes that it is aware an exploit for CVE-2026-87491 exists in the wild. On 9 September CISA added the vulnerability to the KEV catalog with a deadline of 23 September, noting that it allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page and may affect other Chromium-based browsers, including Microsoft Edge and Opera. The update rolls out over the coming days and weeks.

What inside the sandbox means

CISA writes that the code runs inside the browser's sandbox. That sounds reassuring, and to a point it is. The sandbox is the wall that keeps a web page away from the rest of the machine.

But a page that runs code in the sandbox has covered half the distance. The other half is a second flaw that gets through the wall. That is why such bugs are valuable in combination. Google may keep the bug details restricted until a majority of users have updated to the fix.

The browser is the program you use every day to open unfamiliar things.

The good part is that the work here takes two minutes. Chrome updates itself, but until you restart it the old version keeps running. Open the menu, Help, About Google Chrome, and check whether the number starts with 153.

If your office uses Edge or Opera, check those too. CISA's catalog names them, and their updates arrive on their own schedule.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Google Chrome Releases - Stable Channel Update for Desktop, 08.09.2026→CISA - Known Exploited Vulnerabilities Catalog (official catalog)
Original: https://wearecoded.com/en/articles/chrome-153-cve-2026-87491-v8.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news