3 min read

Google patches Chrome zero-day exploited by hackers – update now!

Filip TRUȚĂ

September 09, 2026

Google patches Chrome zero-day exploited by hackers – update now!

Google has released Chrome 153 with security fixes for desktop and Android users, including a vulnerability that attackers are already exploiting in the wild.

Key takeaways

  • Google has released Chrome 153 with a large batch of security fixes
  • CVE-2026-87491 affects Chrome's V8 JavaScript engine
  • Google confirms that an exploit for the vulnerability is already being used in the wild
  • Windows, macOS, Linux and Android users should install the latest Chrome update as soon as possible
  • Chrome on iOS is not affected by this particular vulnerability

Google is urging Chrome users to update their browsers after patching a security vulnerability that is already being exploited by hackers.

The company this week released Chrome 153 as the latest stable version of its browser, bringing a long list of security fixes to users on Windows, macOS, Linux and Android.

Among the vulnerabilities addressed is CVE-2026-87491, an out-of-bounds write flaw in Chrome's V8 JavaScript engine.

“Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in its security advisory.

A vulnerability already under attack

CVE-2026-87491 was reported by Jihyeon Jeong of Seoul National University and is classified by Google as a medium-severity out-of-bounds write vulnerability in V8, the JavaScript and WebAssembly engine used by Chrome.

A medium rating shouldn't give users a false sense of security. The most important detail in Google's advisory is that attackers have already found a way to exploit the flaw.

Browser vulnerabilities are particularly valuable to attackers because a victim may encounter malicious content simply while browsing the web. In sophisticated targeted attacks, vulnerabilities can also be chained with other weaknesses to compromise devices more deeply.

Such exploit chains have historically been used in highly targeted attacks, including spyware campaigns.

Google typically restricts technical information about actively exploited vulnerabilities until most users have received the fix, making it harder for other attackers to reverse-engineer the bug before people have had a chance to update.

Update Chrome now

Even if you don't consider yourself a high-risk target, installing security updates promptly is one of the easiest ways to reduce your exposure to cyberattacks.

Users should also be wary of suspicious links in emails, messages and websites. A malicious link can lead to a compromised or attacker-controlled webpage designed to exploit a browser vulnerability.

As of Sept. 9, Chrome users should be running:

  • Chrome 153.0.8010.36/.37 on Windows and macOS
  • Chrome 153.0.8010.36 on Linux
  • Chrome 153.0.8010.36 on Android

Google says Android releases contain the same security fixes as desktop releases unless otherwise noted. Android users should therefore update Chrome as soon as the latest version becomes available through Google Play.

Chrome on iOS is not affected by CVE-2026-87491.

How to update Chrome

Chrome on desktop normally checks for updates automatically and installs them when the browser is relaunched. You can also trigger the process manually:

1.     Open Chrome and click the three-dot menu

2.     Select Settings

3.     Choose About Chrome

4.     Let Chrome check for and install the latest available version

5.     Relaunch Chrome when prompted

On Android, open Google Play, search for Chrome and install any available update.

Keeping the browser patched is only one layer of protection. Avoid suspicious links and downloads, and consider running a dedicated security solution across your personal devices to help block malicious websites, malware and other threats.

On topic:

Big Tech calls for cyber-defense before AI attacks surge

Update your iPhone and Mac! Apple patches image flaw with spyware potential

macOS ‘Screen Sharing’ flaw exploited for crypto-mining

tags


Author


Filip TRUȚĂ

Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.

View all posts

You might also like

Bookmarks


loader