Patch Release: Google Chrome 153.0.8010.36/37 for Windows

Patch Release: Google Chrome 153.0.8010.36/37 for Windows

Google has released Chrome version 153.0.8010.36/37 for Windows. This release includes 230 security fixes, including an actively exploited zero-day vulnerability in the V8 JavaScript and WebAssembly engine. Google has confirmed that an exploit for CVE-2026-87491 exists in the wild.

Applying this update is strongly recommended to protect systems against known vulnerabilities and active exploitation.


Security Highlights  


The following are the key critical and actively exploited vulnerabilities addressed in this release:

CVE ID

Vulnerability

Severity

CVE-2026-87491

Out-of-bounds write in V8

Medium – Actively Exploited

CVE-2026-87464

Use after free in WebGL

Critical

CVE-2026-87488

Use after free in WebGL

Critical

CVE-2026-87438

Out-of-bounds write in WebGL

Critical

CVE-2026-87527

Buffer overflow in WebGL

Critical

CVE-2026-87628

Use after free in Cast

Critical


CVE-2026-87491 can allow a remote attacker to execute arbitrary code inside the Chrome sandbox through a crafted HTML page. Google has acknowledged that this vulnerability is being actively exploited.

In addition to these vulnerabilities, the release addresses numerous other security issues across Chrome and Chromium components.


For more information, refer to:

https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html


Patch Details  

Windows 64-bit Patch Details  

Patch ID: 363523
Bulletin ID: TU-017
Patch Description: Google Chrome (x64) (153.0.8010.36,153.0.8010.37)


Windows 32-bit Patch Details  

Patch ID: 363522
Bulletin ID: TU-017
Patch Description: Google Chrome (153.0.8010.36,153.0.8010.37)


To install this update on your Windows machines, initiate a sync between the Central Patch Repository and the Patch Manager Plus server. Once the sync is complete, search for the above Patch IDs or Bulletin ID and deploy them to your target systems.

We recommend deploying these patches as soon as possible, particularly because CVE-2026-87491 is being actively exploited in the wild. Updating to Chrome 153.0.8010.36/37 helps protect systems against this zero-day and several other critical security vulnerabilities.


Regards,
The ManageEngine Team