What Changed
On September 8, 2026, Google promoted Chrome 153 to stable with 230 security fixes. Among them is CVE-2026-87491, a Medium-severity (Chromium rating) out-of-bounds write in V8 that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
Google’s advisory states plainly: “Google is aware that an exploit for CVE-2026-87491 exists in the wild.” Fixed versions: 153.0.8010.36 / .37 (Windows/macOS) and 153.0.8010.36 (Linux). The bug was reported by Jihyeon Jeong (Compsec Lab, Seoul National University).
CISA added CVE-2026-87491 to the KEV catalog on September 9, 2026 (federal due date September 23, 2026 per secondary reporting of the catalog entry). This is Google’s seventh actively exploited Chrome zero-day patched in 2026.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Chromium-based browsers (Edge, Brave, Opera, Vivaldi, and enterprise Chromium builds) inherit the same V8 engine and need equivalent vendor updates.
Why This Matters Operationally
Browser zero-days remain the default drive-by path into the endpoint. A sandbox RCE is not full SYSTEM by itself — but it is the first half of every modern kit that wants to finish the job with a local privilege escalation. Getting the fleet to 153+ closes a confirmed wild exploit before it becomes someone else’s Monday incident.
What Defenders Should Verify First
- Force-update Chrome/Chromium/Edge fleets to ≥153.0.8010.36 (or vendor-equivalent) and relaunch browsers.
- Confirm enterprise update channels actually completed — not just “policy set.”
- Prioritize high-risk users (executives, finance, developers) for manual version checks.
- Pair browser currency with September Windows updates; sandbox escapes often hunt for a local LPE next.
Source Context
- Chrome Releases: Stable Channel Update for Desktop (Sep 8, 2026)
- Help Net Security: Google fixes exploited Chrome zero-day CVE-2026-87491
- CISA: Adds Four KEVs including Chromium CVE-2026-87491 (Sep 9)
- CVE Record: CVE-2026-87491
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.