Google released Chrome 153 on September 9, 2026, fixing at least 12 vulnerabilities including CVE-2026-87491, an out-of-bounds bug in V8 that was actively exploited in the wild. This marked the seventh actively exploited Chrome zero-day patched in 2026.
11 reports · 10 independentother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
⚪️ Chrome fixes sixth zero-day vulnerability this year 🗨️ Google developers have released an update for the Chrome browser that fixes 12 vulnerabilities, including an actively exploited zero-day flaw in the V8 engine (CVE-2026-85046). The bug allows attackers to achieve arbitrary code execution through a specially crafted HTML page.… 🔗 https:// hackmag.com/news/cve-2026-8504 6?utm_source=mastodo
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]
Chrome users: Google patched a HIGH severity zero-day actively exploited in the wild. No CVE or version specifics disclosed. Update to the latest Chrome release to mitigate risk. Patch part of 230 fixes. https:// radar.offseq.com/threat/google -warns-of-new-chrome-zero-day-bug-exploited-in-attacks-6560a13f4031475b # OffSeq # ZeroDay # BrowserSecurity # Vuln
Google fixed CVE-2026-87491, an out-of-bounds write in Chrome V8 exploited in the wild via crafted HTML. It enables arbitrary code execution inside the sandbox with risk of heap corruption and memory disclosure. Patch to version 153 immediately and hunt for anomalous browser activity. # ChromeSecurity # ZeroDay # ThreatIntel https:// cyberworldops.eu/en/chrome-v8- zero-day-exploited-in-active-atta
Google Chrome # zeroday Google is aware that an exploit for CVE-2026-87491 exists in the wild. https:// chromereleases.googleblog.com/ 2026/09/stable-channel-update-for-desktop_0808145027.html # Google # Chrome # CVE
The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. https:// thehackernews.com/2026/09/chro me-v8-zero-day-exploited-in-wild.html