Google has released a major security update for Chrome after confirming that a newly discovered V8 zero-day vulnerability is being actively exploited in the wild.
Tracked as CVE-2026-87491, the flaw affects Chrome’s V8 JavaScript and WebAssembly engine and is described as an out-of-bounds write vulnerability. Attackers can potentially exploit the bug by tricking a victim into opening a specially crafted HTML page, allowing arbitrary code execution within Chrome’s sandbox.
The vulnerability affects Chrome versions prior to 153.0.8010.36. While Google has classified the issue as medium severity, the fact that it is already being exploited makes it particularly concerning for users and organizations.
The flaw was discovered by Jihyeon Jeong of Compsec Lab at Seoul National University, who reported it to Google on August 6, 2026. The researcher received a $2,500 bug bounty for the responsible disclosure.
Google has confirmed that an exploit for CVE-2026-87491 exists in real-world attacks. However, the company has not yet revealed details about how attackers are exploiting the vulnerability, who is behind the activity, or what targets may have been affected. Google said technical details may remain restricted until a majority of users have installed the available security fixes.
This latest vulnerability also highlights a broader trend. With CVE-2026-87491, Google has now patched seven Chrome zero-days that were actively exploited in the wild this year. Previous cases include vulnerabilities tracked as CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645 and CVE-2026-85046.
The latest Chrome update addresses 230 security vulnerabilities in total. Among them are five additional critical flaws affecting Chrome’s WebGL and Cast components, including use-after-free, buffer overflow and out-of-bounds write vulnerabilities.
Google is urging users to update Chrome to version 153.0.8010.36/.37 on Windows and macOS and 153.0.8010.36 on Linux. Users can check for the update by going to Chrome → Help → About Google Chrome and restarting the browser when prompted.
The issue may also affect other Chromium-based browsers, including Microsoft Edge, Brave, Opera and Vivaldi. Users of these browsers should install the corresponding security updates as soon as they become available.
With attackers already exploiting the flaw, delaying the update could leave systems unnecessarily exposed.
Let’s refine your stalking skills; go through our Instagram and LinkedIn.