Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

High · 7.9 Browsers CVE-2026-87491 CVE-2026-87534 CVE-2026-87595 CVE-2026-87544 Actively exploited

Google Chrome Stable Update Fixes Five Vulnerabilities, Including One Known Exploited Flaw

Google has released Chrome 153.0.8010.36 for desktop, fixing five vulnerabilities. One of them, CVE-2026-87491, a V8 out-of-bounds write bug, is listed as known exploited. Users and administrators should update immediately.

AI summary

Google has published a Stable Channel update for Chrome on desktop, addressing five distinct vulnerabilities disclosed under CVE-2026-87491, CVE-2026-87534, CVE-2026-87595, CVE-2026-87544, and CVE-2026-87492. The update is documented in Google's official Chrome Releases blog post. One of these vulnerabilities, CVE-2026-87491, is flagged as known exploited, which raises the urgency of applying this update promptly. All five issues are fixed in Chrome 153.0.8010.36.

What happened

Google released a Stable Channel update for Chrome on desktop that resolves five vulnerabilities across different components of the browser. The flaws affect V8 (the JavaScript engine), WebView, Mobile components, Extensions, and DevTools. According to the vendor's release notes, all fixed versions point to Chrome 153.0.8010.36.

Technical causes

The five vulnerabilities stem from different root causes: CVE-2026-87491 is an out-of-bounds write in V8 (CWE-787) that could allow a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. CVE-2026-87534 is a missing authorization issue in WebView on Android (CWE-862) that could let an attacker bypass system access restrictions via crafted network traffic, combined with social engineering. CVE-2026-87595 is a server-side request forgery in Mobile (CWE-918) that could bypass access restrictions via a crafted HTML page, also requiring social engineering. CVE-2026-87544 is an incorrect authorization issue in Extensions (CWE-863) that could allow access to a privileged page via a crafted HTML page. CVE-2026-87492 is an incorrect authorization issue in DevTools (CWE-863) that could potentially allow code execution outside the sandbox via a crafted HTML page.

Why it matters

CVE-2026-87491 is marked as known exploited, meaning there is confirmed evidence of real-world exploitation of this flaw. It carries a CVSS score of 8.8 and could allow a remote attacker to execute arbitrary code within Chrome's sandbox through a specially crafted web page, requiring user interaction (such as visiting a malicious page). The other four vulnerabilities carry high CVSS scores (9.8 and 9.6) reflecting severe potential impact on confidentiality, integrity, and availability, though none of them are currently flagged as known exploited or having public exploit code. CVE-2026-87492, involving DevTools, is particularly notable because Chromium rates its severity as High and it could potentially allow code execution outside the browser's sandbox.

Who is affected

Users and organizations running Google Chrome on desktop prior to version 153.0.8010.36 are affected by these vulnerabilities. CVE-2026-87534 specifically concerns Chrome's WebView component on Android, meaning Android-based deployments using WebView are also relevant.

Affected versions

All five vulnerabilities affect Google Chrome versions prior to 153.0.8010.36. No specific starting version for the affected range was provided in the vendor release notes.

Fixes and mitigation

Google has fixed all five vulnerabilities in Chrome version 153.0.8010.36, released via the Stable Channel for desktop. No alternative mitigations or workarounds were specified in the vendor's release notes; updating to the fixed version is the documented remedy.

Recommended action

Update Google Chrome to version 153.0.8010.36 or later as soon as possible. Given that CVE-2026-87491 is known exploited, this update should be treated as high priority, particularly for desktop users. Organizations managing Chrome deployments at scale should verify that automatic updates are enabled or push the update through their endpoint management tools without delay.

PatchBriefing score

7.9 / 10 · High

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Listed in CISA KEV since September 9, 2026

Why this score

The highest patchwire score among these five vulnerabilities is 7.9, assigned to CVE-2026-87491. This score reflects its CVSS base score of 8.8, combined with a significant contribution from its known-exploited status (+2 points) and smaller contributions from being remotely exploitable without authentication and affecting a widely used product. The other four vulnerabilities score between 6.4 and 6.7, driven primarily by their high CVSS base scores (9.6–9.8), but lack the known-exploited or public-exploit contributions that elevate CVE-2026-87491's overall risk rating. None of the five vulnerabilities have an available EPSS score in this fact package.

Affected versions

≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched

Reported fixes

Google has fixed all five vulnerabilities in Chrome version 153.0.8010.36, released via the Stable Channel for desktop. No alternative mitigations or workarounds were specified in the vendor's release notes; updating to the fixed version is the documented remedy.

How this was built

6 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Five Vulnerabilities, Including One Known Exploited Flaw
1 article · 6 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email