Google Fixes 230 Chrome Vulnerabilities, Including Active Zero-Day


chrome zero day fixed
Image credit: Google

Google has fixed 230 Chrome vulnerabilities with the release of Chrome 153, including a zero-day that attackers are already exploiting in the wild.

The flaw, tracked as CVE-2026-87491, affects Chrome’s V8 engine and marks the seventh actively exploited Chrome zero-day patched since the beginning of 2026.

Google fixes 230 security vulnerabilities in Chrome

Google says its latest Chrome Stable update includes 230 security fixes, with the company confirming that an exploit for CVE-2026-87491 exists in the wild.

Security researcher Jihyeon Jeong, a research intern at Seoul National University’s Compsec Lab, reported the vulnerability to Google.

Google’s release notes classify CVE-2026-87491 as a Medium-severity out-of-bounds write vulnerability in V8, Chrome’s JavaScript and WebAssembly engine.

CVE-2026-87491 can trigger heap corruption

Attackers can exploit the vulnerability through a specially crafted HTML page.

Successful exploitation could allow an attacker to execute arbitrary code inside Chrome’s sandbox. The flaw can also cause heap corruption, allowing access to memory outside the intended buffer.

That could potentially expose sensitive information or cause Chrome to crash.

Google has not revealed how attackers are exploiting CVE-2026-87491 or who they are targeting.

The company also says it may restrict access to technical bug details until most users have installed the update. This reduces the amount of information available to attackers while vulnerable Chrome installations remain online.

Chrome 153 patches the actively exploited zero-day

Google has shipped the fix with Chrome 153 for Windows, macOS, and Linux. The update is rolling out globally and could take days or weeks to reach every device.

Chrome 153 also marks another major change for the browser. Google has now switched Chrome to a two-week release cycle, allowing security fixes and other improvements to reach users faster.

Chrome has faced several actively exploited flaws this year

CVE-2026-87491 is the seventh Chrome zero-day patched in 2026 after Google confirmed attackers were exploiting it in the wild.

It also follows another recent V8 security issue. Google previously released an emergency fix for CVE-2026-85046, a type confusion vulnerability that attackers were also actively exploiting.

Users should install Chrome 153 as soon as it becomes available and restart the browser to complete the update.

Via BleepingComputer

More about the topics: Chrome, Google, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages