High · 7.9 Browsers CVE-2026-87491 CVE-2026-87534 CVE-2026-87595 CVE-2026-87544 Actively exploited
Google Chrome Stable Update Fixes Five Vulnerabilities, Including One Known Exploited Flaw
Google has released Chrome 153.0.8010.36 for desktop, fixing five vulnerabilities. One of them, CVE-2026-87491, a V8 out-of-bounds write bug, is listed as known exploited. Users and administrators should update immediately.
AI summary
Google has published a Stable Channel update for Chrome on desktop, addressing five distinct vulnerabilities disclosed under CVE-2026-87491, CVE-2026-87534, CVE-2026-87595, CVE-2026-87544, and CVE-2026-87492. The update is documented in Google's official Chrome Releases blog post. One of these vulnerabilities, CVE-2026-87491, is flagged as known exploited, which raises the urgency of applying this update promptly. All five issues are fixed in Chrome 153.0.8010.36.
What happened
Google released a Stable Channel update for Chrome on desktop that resolves five vulnerabilities across different components of the browser. The flaws affect V8 (the JavaScript engine), WebView, Mobile components, Extensions, and DevTools. According to the vendor's release notes, all fixed versions point to Chrome 153.0.8010.36.
Technical causes
The five vulnerabilities stem from different root causes: CVE-2026-87491 is an out-of-bounds write in V8 (CWE-787) that could allow a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. CVE-2026-87534 is a missing authorization issue in WebView on Android (CWE-862) that could let an attacker bypass system access restrictions via crafted network traffic, combined with social engineering. CVE-2026-87595 is a server-side request forgery in Mobile (CWE-918) that could bypass access restrictions via a crafted HTML page, also requiring social engineering. CVE-2026-87544 is an incorrect authorization issue in Extensions (CWE-863) that could allow access to a privileged page via a crafted HTML page. CVE-2026-87492 is an incorrect authorization issue in DevTools (CWE-863) that could potentially allow code execution outside the sandbox via a crafted HTML page.
Why it matters
CVE-2026-87491 is marked as known exploited, meaning there is confirmed evidence of real-world exploitation of this flaw. It carries a CVSS score of 8.8 and could allow a remote attacker to execute arbitrary code within Chrome's sandbox through a specially crafted web page, requiring user interaction (such as visiting a malicious page). The other four vulnerabilities carry high CVSS scores (9.8 and 9.6) reflecting severe potential impact on confidentiality, integrity, and availability, though none of them are currently flagged as known exploited or having public exploit code. CVE-2026-87492, involving DevTools, is particularly notable because Chromium rates its severity as High and it could potentially allow code execution outside the browser's sandbox.
Who is affected
Users and organizations running Google Chrome on desktop prior to version 153.0.8010.36 are affected by these vulnerabilities. CVE-2026-87534 specifically concerns Chrome's WebView component on Android, meaning Android-based deployments using WebView are also relevant.
Affected versions
All five vulnerabilities affect Google Chrome versions prior to 153.0.8010.36. No specific starting version for the affected range was provided in the vendor release notes.
Fixes and mitigation
Google has fixed all five vulnerabilities in Chrome version 153.0.8010.36, released via the Stable Channel for desktop. No alternative mitigations or workarounds were specified in the vendor's release notes; updating to the fixed version is the documented remedy.
Recommended action
Update Google Chrome to version 153.0.8010.36 or later as soon as possible. Given that CVE-2026-87491 is known exploited, this update should be treated as high priority, particularly for desktop users. Organizations managing Chrome deployments at scale should verify that automatic updates are enabled or push the update through their endpoint management tools without delay.
PatchBriefing score
7.9 / 10 · High
Official CVSS: 8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Listed in CISA KEV since September 9, 2026
Why this score
The highest patchwire score among these five vulnerabilities is 7.9, assigned to CVE-2026-87491. This score reflects its CVSS base score of 8.8, combined with a significant contribution from its known-exploited status (+2 points) and smaller contributions from being remotely exploitable without authentication and affecting a widely used product. The other four vulnerabilities score between 6.4 and 6.7, driven primarily by their high CVSS base scores (9.6–9.8), but lack the known-exploited or public-exploit contributions that elevate CVE-2026-87491's overall risk rating. None of the five vulnerabilities have an available EPSS score in this fact package.
Affected versions
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
Reported fixes
Google has fixed all five vulnerabilities in Chrome version 153.0.8010.36, released via the Stable Channel for desktop. No alternative mitigations or workarounds were specified in the vendor's release notes; updating to the fixed version is the documented remedy.
How this was built
6 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email