Chrome 153 Patches Critical Vulnerability Already Being Exploited
Google has released Chrome 153 to fix 230 security flaws, including five critical ones. One of the critical vulnerabilities, CVE-2026-87491, is already being exploited in the wild.
CVE-2026-87491 is an out-of-bounds write in V8, the JavaScript and WebAssembly engine that Chrome uses to run code on web pages. This type of vulnerability allows a remote attacker to run code inside the sandbox with just a crafted HTML page.
The patch will roll out over the coming days and weeks, but users need to restart their browser for it to take effect. The release also changes the update cycle to every two weeks instead of every four.