Chrome CVE-2026-87491: Google’s Seventh Exploited Zero-Day of 2026 — Update to 153

By George Bailey   Published: 09/13/26   Updated: 09/13/26   2 min read

What Changed

On September 8, 2026, Google promoted Chrome 153 to stable with 230 security fixes. Among them is CVE-2026-87491, a Medium-severity (Chromium rating) out-of-bounds write in V8 that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

Google’s advisory states plainly: “Google is aware that an exploit for CVE-2026-87491 exists in the wild.” Fixed versions: 153.0.8010.36 / .37 (Windows/macOS) and 153.0.8010.36 (Linux). The bug was reported by Jihyeon Jeong (Compsec Lab, Seoul National University).

CISA added CVE-2026-87491 to the KEV catalog on September 9, 2026 (federal due date September 23, 2026 per secondary reporting of the catalog entry). This is Google’s seventh actively exploited Chrome zero-day patched in 2026.

Chromium-based browsers (Edge, Brave, Opera, Vivaldi, and enterprise Chromium builds) inherit the same V8 engine and need equivalent vendor updates.

Why This Matters Operationally

Browser zero-days remain the default drive-by path into the endpoint. A sandbox RCE is not full SYSTEM by itself — but it is the first half of every modern kit that wants to finish the job with a local privilege escalation. Getting the fleet to 153+ closes a confirmed wild exploit before it becomes someone else’s Monday incident.

What Defenders Should Verify First

Source Context

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.