
Google has released Chrome 153 with security fixes for desktop and Android users, including a vulnerability that attackers are already exploiting in the wild.
Google is urging Chrome users to update their browsers after patching a security vulnerability that is already being exploited by hackers.
The company this week released Chrome 153 as the latest stable version of its browser, bringing a long list of security fixes to users on Windows, macOS, Linux and Android.
Among the vulnerabilities addressed is CVE-2026-87491, an out-of-bounds write flaw in Chrome's V8 JavaScript engine.
“Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in its security advisory.
CVE-2026-87491 was reported by Jihyeon Jeong of Seoul National University and is classified by Google as a medium-severity out-of-bounds write vulnerability in V8, the JavaScript and WebAssembly engine used by Chrome.
A medium rating shouldn't give users a false sense of security. The most important detail in Google's advisory is that attackers have already found a way to exploit the flaw.
Browser vulnerabilities are particularly valuable to attackers because a victim may encounter malicious content simply while browsing the web. In sophisticated targeted attacks, vulnerabilities can also be chained with other weaknesses to compromise devices more deeply.
Such exploit chains have historically been used in highly targeted attacks, including spyware campaigns.
Google typically restricts technical information about actively exploited vulnerabilities until most users have received the fix, making it harder for other attackers to reverse-engineer the bug before people have had a chance to update.
Even if you don't consider yourself a high-risk target, installing security updates promptly is one of the easiest ways to reduce your exposure to cyberattacks.
Users should also be wary of suspicious links in emails, messages and websites. A malicious link can lead to a compromised or attacker-controlled webpage designed to exploit a browser vulnerability.
As of Sept. 9, Chrome users should be running:
Google says Android releases contain the same security fixes as desktop releases unless otherwise noted. Android users should therefore update Chrome as soon as the latest version becomes available through Google Play.
Chrome on iOS is not affected by CVE-2026-87491.
Chrome on desktop normally checks for updates automatically and installs them when the browser is relaunched. You can also trigger the process manually:
1. Open Chrome and click the three-dot menu
2. Select Settings
3. Choose About Chrome
4. Let Chrome check for and install the latest available version
5. Relaunch Chrome when prompted
On Android, open Google Play, search for Chrome and install any available update.
Keeping the browser patched is only one layer of protection. Avoid suspicious links and downloads, and consider running a dedicated security solution across your personal devices to help block malicious websites, malware and other threats.
On topic:
Big Tech calls for cyber-defense before AI attacks surge
Update your iPhone and Mac! Apple patches image flaw with spyware potential
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts