Google: Update Chrome now to protect against an actively exploited vulnerability

Google: Update Chrome now to protect against an actively exploited vulnerability

Chrome Patches Actively Exploited Zero-Day Vulnerability in Latest Update

Google has released an urgent update for its Chrome desktop browser, addressing 230 security fixes, including one actively exploited zero-day vulnerability. The stable channel has been updated to version 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.

The critical flaw, tracked as CVE-2026-87491, is an out-of-bounds write vulnerability in Chrome’s V8 JavaScript engine. A remote attacker could exploit this by tricking users into visiting a maliciously crafted HTML page, allowing arbitrary code execution within Chrome’s sandbox. While the sandbox limits broader system access, the vulnerability provides an initial foothold for further attacks.

The update also resolves five Critical-severity flaws, four of which affect WebGL, a JavaScript API for rendering interactive graphics in the browser. Users are advised to update immediately, either through Chrome’s automatic updates or manually via Settings > About Chrome.

Exploitation via email is unlikely, as most email clients sanitize HTML content, but attackers could still use phishing links to direct victims to malicious sites. The patch underscores the ongoing risks of browser-based attacks and the importance of timely updates.

Source: https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-now-to-protect-against-an-actively-exploited-vulnerability

Google TPRM report: https://www.rankiteo.com/company/google-chrome

"id": "goo1789043523",
"linkid": "google-chrome",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'All Chrome desktop users',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Google Chrome',
                        'type': 'Software'}],
 'attack_vector': 'Maliciously crafted HTML page (phishing links)',
 'customer_advisories': 'Users advised to update Chrome via Settings > About '
                        'Chrome',
 'description': 'Google has released an urgent update for its Chrome desktop '
                'browser, addressing 230 security fixes, including one '
                'actively exploited zero-day vulnerability. The critical flaw, '
                'tracked as CVE-2026-87491, is an out-of-bounds write '
                'vulnerability in Chrome’s V8 JavaScript engine. A remote '
                'attacker could exploit this by tricking users into visiting a '
                'maliciously crafted HTML page, allowing arbitrary code '
                'execution within Chrome’s sandbox.',
 'impact': {'systems_affected': 'Chrome desktop browser (Windows, Mac, Linux)'},
 'lessons_learned': 'Ongoing risks of browser-based attacks and importance of '
                    'timely updates',
 'post_incident_analysis': {'corrective_actions': 'Patch released and users '
                                                  'urged to update',
                            'root_causes': 'Out-of-bounds write vulnerability '
                                           'in V8 JavaScript engine'},
 'recommendations': 'Update Chrome immediately to the latest version',
 'references': [{'source': 'Google Chrome Security Advisory'}],
 'response': {'communication_strategy': 'Public advisory urging users to '
                                        'update',
              'containment_measures': 'Patch released (version '
                                      '153.0.8010.36/.37 for Windows/Mac, '
                                      '153.0.8010.36 for Linux)',
              'remediation_measures': 'Users advised to update immediately via '
                                      'Settings > About Chrome'},
 'title': 'Chrome Patches Actively Exploited Zero-Day Vulnerability in Latest '
          'Update',
 'type': 'Zero-Day Vulnerability',
 'vulnerability_exploited': 'CVE-2026-87491 (Out-of-bounds write in V8 '
                            'JavaScript engine)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.