Google has released Chrome version 153.0.8010.36/37 for Windows. This release includes 230 security fixes, including an actively exploited zero-day vulnerability in the V8 JavaScript and WebAssembly engine. Google has confirmed that an exploit for CVE-2026-87491 exists in the wild.
Applying this update is strongly recommended to protect systems against known vulnerabilities and active exploitation.
The following are the key critical and actively exploited vulnerabilities addressed in this release:
CVE ID | Vulnerability | Severity |
CVE-2026-87491 | Out-of-bounds write in V8 | Medium – Actively Exploited |
CVE-2026-87464 | Use after free in WebGL | Critical |
CVE-2026-87488 | Use after free in WebGL | Critical |
CVE-2026-87438 | Out-of-bounds write in WebGL | Critical |
CVE-2026-87527 | Buffer overflow in WebGL | Critical |
CVE-2026-87628 | Use after free in Cast | Critical |
In addition to these vulnerabilities, the release addresses numerous other security issues across Chrome and Chromium components.
https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html
Patch ID: 363523
Bulletin ID: TU-017
Patch Description: Google Chrome (x64) (153.0.8010.36,153.0.8010.37)
Patch ID: 363522
Bulletin ID: TU-017
Patch Description: Google Chrome (153.0.8010.36,153.0.8010.37)
We recommend deploying these patches as soon as possible, particularly because CVE-2026-87491 is being actively exploited in the wild. Updating to Chrome 153.0.8010.36/37 helps protect systems against this zero-day and several other critical security vulnerabilities.