ConicPlex

Start Your Project

A laptop glowing with soft blue, red, yellow, and green light beside a cracked glass cube on a desk, symbolizing a breached browser security boundary

On this Page

Chrome Patches Its Seventh Actively Exploited Zero-Day of 2026 (CVE-2026-87491)

Google patched CVE-2026-87491, Chrome’s seventh actively exploited zero-day of 2026, in Chrome 153. Here’s what changed and how to update.

Sameer Malek

September 10, 2026

Google shipped Chrome 153 on September 9, patching CVE-2026-87491, an out-of-bounds write bug in the V8 JavaScript engine that attackers were already exploiting in the wild. A malicious or compromised webpage could trigger the flaw to run code inside Chrome’s sandbox. It’s the seventh Chrome zero-day Google has had to patch under active attack this year, and the second inside a single week. If you haven’t restarted Chrome in the last day or two, do it now.

What CVE-2026-87491 Actually Does

The bug lives in V8, the engine that runs JavaScript and WebAssembly inside Chrome. It’s a memory-safety flaw called an out-of-bounds write, where code writes data past the edges of a buffer it was allocated, which an attacker can turn into arbitrary code execution. Google’s own advisory says it is “aware that an exploit for CVE-2026-87491 exists in the wild,” about as close to a confirmed active-exploitation statement as the company gets. Security researcher Jihyeon Jeong of Compsec Lab at Seoul National University reported the bug on August 6 and earned a $2,500 bounty for it, according to Help Net Security’s writeup.

The fix landed in Chrome 153.0.8010.36 for Windows and Linux, and 153.0.8010.36 or .37 for macOS, as part of a stable release that also closed 230 other security issues, per The Hacker News. Google rates the severity as medium, which sounds low for an actively exploited remote code execution bug, but that reflects the fact that an attacker still has to break out of Chrome’s sandbox to do real damage, not that the bug itself is minor.

Why This Keeps Happening

This is Chrome’s seventh zero-day patched under active exploitation in 2026, and it landed less than a week after CVE-2026-85046, another V8 bug Google fixed on September 4. Two separate, unrelated V8 flaws getting weaponized in the same week isn’t really a coincidence. V8 is one of the most heavily scrutinized pieces of code on the internet, by defenders and attackers alike, and it sits underneath every Chromium-based browser, not just Chrome itself. CISA added the earlier bug to its Known Exploited Vulnerabilities catalog with a September 18 remediation deadline for federal agencies. Expect CVE-2026-87491 to get the same treatment shortly.

What to Do About It

Chrome updates itself in the background, but the fix only takes effect after a full restart of the browser, not just closing and reopening a tab. Check chrome://settings/help, confirm you’re running 153.0.8010.36 or later on Windows and Linux (153.0.8010.36 or .37 on macOS), and restart if you’re not already there. The same advice applies to Chromium-based browsers like Edge, Brave, Opera, and Vivaldi once their vendors ship the equivalent patch, since they all run on the same V8 engine.

There’s no other action to take. This isn’t a bug you can work around by changing a setting or avoiding certain sites, since the trigger is just a crafted HTML page loading in the browser. Restarting Chrome is the whole fix.

Sources

Sameer Malek is a Senior Full Stack Developer at ConicPlex, working across the stack on projects that don’t fit neatly into one platform or framework. He’s often the person weighing a genuine platform or architecture decision rather than defending one side of it, since his work regularly crosses between WordPress, custom builds, and everything in between. He writes here about the comparisons and tradeoffs that come up when there’s more than one reasonable way to build something.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

News & Updates

A laptop glowing with WordPress blue light on a dark desk at night, surrounded by several identical old brass keys half hidden under a notebook, symbolizing a backdoor that hides duplicate copies of itself.

WordPress Backdoor SC Survives Cleanup by Hiding in Files, Database, and Memory

Sucuri documented a self-healing WordPress backdoor called SC that rebuilds itself from eight hiding spots, including shared memory, after a…

Aftab Memon

October 3, 2026

News & Updates

A laptop glowing with a soft magenta light next to an ID keycard on a wooden desk, symbolizing a WordPress admin access vulnerability

Elementor Patches a Critical CSRF Flaw That Could Hand Attackers Admin Access (CVE-2026-62062)

A CSRF flaw in Elementor 4.3.0 and 4.3.1 (CVE-2026-62062, CVSS 8.8) let attackers create admin accounts with one click. Patched…

Aftab Memon

October 2, 2026

Plugins

Stack of to-do list task cards with checkboxes in front of a faded kanban board, illustrating WordPress dashboard to-do list and task management plugins

How to Add a To-Do List to Your WordPress Dashboard (4 Plugins Compared)

Compare four real WordPress plugins for a dashboard to-do list or task board, from a simple single-person widget to full…

Husen Memon

October 2, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant