Skip to main content

Morning Overview

Chrome has patched its seventh exploited zero-day of 2026, so check your version

Google confirmed on September 8 that attackers were already exploiting a flaw in Chrome’s V8 engine when it shipped the fix, and security outlets count it as the seventh Chrome zero-day used in real attacks in 2026. The bug, tracked as CVE-2026-87491, is one of 230 security fixes in the Chrome 153 stable release. Browsers that installed 153.0.8010.36 or later are protected, and anyone who has not restarted Chrome in recent weeks may still be running something older.

Google’s own release note for the update carries the standard warning. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the Chrome Releases post for the update reads. The company also states that access to bug details and links may stay restricted until a majority of users have updated, which is why the note says nothing about who is using the exploit or against whom.

Inside the seventh zero-day

CVE-2026-87491 is an out-of-bounds write in V8, the engine that runs JavaScript and WebAssembly inside Chrome. Help Net Security’s write-up of the fix describes it as allowing code execution inside Chrome’s sandbox through a crafted HTML page, and credits Jihyeon Jeong of Compsec Lab at Seoul National University, who reported it on August 6 and received a $2,500 reward.

Google rates the bug medium severity, a label that can look reassuring next to the five critical-severity fixes in the same release. A sandbox-contained code-execution bug is rarely the last step in an attack, though. Exploit chains typically pair one flaw like this with a second bug that escapes the sandbox, and the medium rating reflects that limit rather than any indication that the exploitation Google described is harmless.

Windows and Mac builds are 153.0.8010.36 and 153.0.8010.37, and Linux is 153.0.8010.36. The full release fixed 230 issues by Google’s own count: 5 critical, 43 high, 174 medium and 8 low. Google’s note credits its usual battery of internal detection tools, including AddressSanitizer, MemorySanitizer, libFuzzer and AFL, for catching other bugs before they reached the stable channel, a reminder that most of the 230 never involved an outside attacker at all.

Six earlier exploited bugs since February

The count of seven comes from press tallies, not from Google, which flags exploited bugs one at a time without numbering them. SecurityWeek lists the earlier six as CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645 and CVE-2026-85046. Two of those landed in March, and the sixth arrived only days before the seventh: CVE-2026-85046, another V8 flaw, was patched in the first week of September.

V8 keeps turning up. Startup Fortune’s tally counts four of the seven as V8 bugs, with CVE-2026-3909 in Skia, the graphics library, among the exceptions. Two V8 zero-days inside roughly a week is unusual pacing even in a year that has already produced seven, and the same publication notes that Google has moved Chrome to a two-week release schedule, which shortens the time a fixed bug stays exposed on machines that have not updated.

Chrome 153 is no longer the newest build

The version named in the September 8 note has been overtaken. A September 15 stable update moved desktop Chrome to 153.0.8010.47 and 48 with 42 more security fixes, and the Chrome Releases index shows a Chrome 154 stable build (154.0.8037.57 on Windows and Mac) on September 22 with 108 security fixes, followed by an early-stable push of Chrome 155 on September 23. None of those posts reviewed for this article carries an exploited-in-the-wild line, so the seventh remains the latest as of September 28.

For anyone checking a machine, the target is whichever stable build Chrome offers now rather than 153.0.8010.36 specifically. Anything at 153.0.8010.36 or higher contains this particular fix, and 154 includes it along with the newer patches.

Checking the version and finishing the update

The check takes under a minute. Typing chrome://settings/help into the address bar opens the About page, which shows the installed version number and starts a download if a newer one exists. The update does not take effect until Chrome is relaunched, and a browser left open for days with dozens of tabs is the most common way to stay on an old build after the patch has already downloaded.

Other browsers built on the same Chromium code, including Microsoft Edge, Brave and Opera, receive V8 fixes on their own schedules through their own updaters. A patched Chrome does nothing for an unpatched copy of another Chromium browser installed on the same computer.

Google has not said how many users were targeted, by whom, or whether the sandbox-contained code execution was combined with a second flaw. Those answers are what the restricted bug details are meant to withhold until most of the installed base has updated, and so far the only public description of the attacks is that single sentence in the September 8 release note.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview