Chrome 153 fixes the seventh exploited zero-day of 2026, so relaunch your browser

Reading Time: 5 min
18
techkahwa.net | 10 September 2026

Google has released Chrome 153 with a fix for CVE-2026-87491, a flaw that attackers are already exploiting. According to SecurityWeek and Security Affairs, this is the seventh actively exploited Chrome zero-day of 2026, and the fix only protects you once your browser has actually restarted.

What happened

Google’s statement is short: “Google is aware that an exploit for CVE-2026-87491 exists in the wild.” In plain terms, someone was using the flaw in real attacks before most people had the fix.

According to Security Affairs, CVE-2026-87491 is an out-of-bounds write in V8, the engine Chrome uses to run JavaScript on web pages. It carries a CVSS score of 8.8. A bug in V8 matters because every site you open runs code through it.

Google has not said who was targeted or how the exploit was used, which is normal while most users are still updating. I will not speculate beyond that.

The fix arrives in a large release. SecurityWeek reports that Chrome 153 patches 230 vulnerabilities in total, including five rated critical and 41 rated high severity. Even without the zero-day, that would be a strong reason to update.

Who is affected

Anyone running Chrome on Windows, macOS or Linux below the fixed versions. SecurityWeek lists the patched builds as 153.0.8010.36 or 153.0.8010.37 for Windows and macOS, and 153.0.8010.36 for Linux.

Other browsers built on Chromium, such as Microsoft Edge, Brave and Opera, share much of the same code. Their users should watch for updates from those vendors as they ship their own fixes.

Chrome is the browser most of our readers use every day, at home and at work. That is exactly why attackers invest in finding its flaws.

By the numbers

Item Detail Source
Vulnerability CVE-2026-87491 SecurityWeek, Security Affairs
Type Out-of-bounds write in V8 Security Affairs
CVSS score 8.8 Security Affairs
Exploited in the wild Yes, per Google SecurityWeek, Security Affairs
Fixed version, Windows and macOS 153.0.8010.36 or 153.0.8010.37 SecurityWeek
Fixed version, Linux 153.0.8010.36 SecurityWeek
Total fixes in Chrome 153 230 SecurityWeek
Critical fixes 5 SecurityWeek
High severity fixes 41 SecurityWeek
Exploited Chrome zero-days in 2026 7 SecurityWeek, Help Net Security

Before this one, the reports list six earlier Chrome zero-days this year: CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645 and CVE-2026-85046. The last of those was fixed on 4 September in Chrome 152.0.7977.82 and .83, which means two emergency updates landed within about a week of each other.

What to do now

  1. Open the Chrome menu, go to Help, then About Google Chrome. Let it download the update, then click Relaunch. Chrome often downloads updates quietly but only applies them after a restart.
  2. Check the version number on that same page. It should read 153.0.8010.36 or later.
  3. If you use Edge, Brave or Opera, check for updates there too, and install them as each vendor releases its fix.
  4. If you manage computers for a team, push Chrome 153.0.8010.36 or later through your management tools rather than waiting for each person to restart.
  5. Keep Enhanced Safe Browsing turned on in Chrome’s privacy and security settings.

A small tip for the moment you see the Relaunch button: finish any half-typed form first, then relaunch straight away rather than postponing it to the end of the day.

Why it matters

Seven exploited zero-days in about nine months is a steady rhythm, and I think the right response is a habit, not panic. The weak point is rarely the update itself. It is the browser that stays open for weeks with a pending update that never gets applied.

The detail that stands out to me is the short gap between 4 September and this release. Anyone who relaunched for the previous fix and then felt done would already be behind again within days. That is not a failure on their part, just the reality of a browser that is also a target.

My suggestion is simple: make relaunching Chrome part of your weekly routine, the same way you might restart your phone. If you look after family members’ devices, show them where the Relaunch button is. It is one of the cheapest security wins available.

Sources

  • SecurityWeek, Chrome 153 patches seventh zero-day of 2026, September 2026, https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/
  • Security Affairs, Google fixes the seventh actively exploited Chrome zero-day of 2026, September 2026, https://securityaffairs.com/198757/security/google-fixes-the-seventh-actively-exploited-chrome-zero-day-of-2026.html
  • Help Net Security, report on Chrome zero-day CVE-2026-87491, 9 September 2026, https://www.helpnetsecurity.com/2026/09/09/google-chrome-cve-2026-87491-zero-day-flaw/
  • Google, Chrome Releases blog, stable channel updates, https://chromereleases.googleblog.com/