Google Chrome 153 Security Patches Address 7th Zero-Day Vulnerability of 2026

www.news4hackers.com-google-chrome-153-security-patches-address-7th-zero-day-vulnerability-of-2026-google-chrome-153-security-patches-address-7th-zero-day-vulnerability-of-2026

Google issued Chrome version 153 to the stable channel on Tuesday, addressing 230 security flaws, among them an actively exploited zero-day vulnerability.

Chrome 153 Release Details

Google issued Chrome version 153 to the stable channel on Tuesday, addressing 230 security flaws, among them an actively exploited zero-day vulnerability. The critical flaw, designated CVE-2026-87491, affects the V8 JavaScript and WebAssembly engine and involves an out-of-bounds write condition. Google confirmed the existence of an exploit for this issue in real-world attacks, according to its security advisory.

Vulnerability Breakdown

Critical Flaw Details

The vulnerability was disclosed by Jihyeon Jeong of the Compsec Lab at Seoul National University, who received a $2,500 reward through the company’s bug bounty program.

Severity Ratings

Five of the resolved vulnerabilities carry critical severity ratings. These include four issues in WebGL related to use-after-free, out-of-bounds write, and buffer overflow flaws, as well as a use-after-free vulnerability in the Cast component. The update also addresses 41 high-severity flaws, such as use-after-free errors, out-of-bounds read conditions, authorization bypasses, and race conditions. Additional patches cover over 180 medium- and low-severity issues, including information leaks, user interface misrepresentations, incorrect reference resolution, uninitialized resources, and clickjacking vulnerabilities.

Bug Bounty and External Contributions

Of the 230 total vulnerabilities fixed, 35 were reported by external researchers. Google allocated approximately $23,000 in bug bounty rewards for these findings but has not yet disclosed the specific amounts paid for around two dozen reports.

User Recommendations

The latest Chrome release is available as versions 153.0.8010.36 and 153.0.8010.37 for Windows and macOS, and version 153.0.8010.36 for Linux. Users are urged to apply the update promptly to mitigate risks associated with the resolved flaws.

Broader Security Context

The release follows recent updates from other major vendors, including Microsoft’s patching of 974 vulnerabilities and Adobe’s resolution of over 170 flaws. Other recent developments include fixes for critical vulnerabilities in SAP, MikroTik, and ICS systems, as well as ongoing investigations into data breaches and ransomware activities.

Google confirmed the existence of an exploit for this issue in real-world attacks, according to its security advisory.



About Author

en_USEnglish