Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.4 Browsers CVE-2026-87609 CVE-2026-87529 CVE-2026-87607 CVE-2026-87500

Google Chrome 153.0.8010.36 Fixes Eight High-Severity Memory Safety Vulnerabilities

Google has released Chrome 153.0.8010.36 for desktop, patching eight vulnerabilities — including several rated Critical and High by Chromium's own severity classification — that could allow remote code execution outside the browser sandbox.

AI summary

Google has published a Stable Channel update for Chrome on desktop, version 153.0.8010.36, addressing eight distinct vulnerabilities discovered across multiple browser components. All eight issues carry a CVSS base score of 9.6 and share similar exploitation characteristics: a remote attacker could potentially execute arbitrary code outside the browser's sandbox by getting a user to visit a crafted HTML page, interact with a crafted UI element, or in one case, process crafted network traffic. Chromium's internal severity ratings for these issues range from Medium to Critical. This briefing summarizes the fixed issues, who is affected, and the recommended action.

What Happened

Google released Chrome 153.0.8010.36 for desktop (and a corresponding iOS fix) to address eight separate memory-safety vulnerabilities identified in the browser: CVE-2026-87609 (use-after-free in Sharing, iOS), CVE-2026-87529 (numeric truncation error in Media), CVE-2026-87607 (use-after-free in Device, Mac), CVE-2026-87500 (improper array index validation in ANGLE), CVE-2026-87464 (use-after-free in WebGL, rated Critical by Chromium), CVE-2026-87650 (out-of-bounds read in WebGL), CVE-2026-87455 (use-after-free in Aura), and CVE-2026-87526 (use-after-free in Passwords, requiring social engineering and UI interaction). All were disclosed and fixed in the same vendor release.

Technical Cause

The vulnerabilities stem from several distinct memory-safety weaknesses: use-after-free conditions (CWE-416) in the Sharing, Device, WebGL, Aura, and Passwords components; a numeric truncation error (CWE-197) in Media; improper validation of an array index (CWE-129) in ANGLE; and an out-of-bounds read (CWE-125) in WebGL. Each flaw could, under the right conditions, allow a remote attacker to execute arbitrary code outside Chrome's security sandbox.

Why It Matters

All eight issues share a CVSS base score of 9.6, reflecting a network attack vector, low attack complexity, no privileges required, and high impact to confidentiality, integrity, and availability if exploited. Most require the victim to visit a crafted HTML page; CVE-2026-87526 additionally requires social engineering and UI interaction, and CVE-2026-87609 is triggered via crafted network traffic rather than a webpage. Chromium's own severity ratings range from Medium to Critical, with CVE-2026-87464 (WebGL use-after-free) rated Critical. No evidence of active exploitation or public proof-of-concept code has been reported for any of these issues.

Who Is Affected

Users and organizations running Google Chrome on desktop prior to version 153.0.8010.36 are affected by the majority of these issues. CVE-2026-87609 specifically affects Chrome on iOS prior to the same version, and CVE-2026-87607 specifically affects Chrome on Mac prior to the same version. Given Chrome's extremely broad installed base, the practical exposure is significant across consumer and enterprise environments alike.

Discovery and Timeline

Google published the Stable Channel update announcement on 2026-09-08, with the corresponding CVE records appearing in NVD on 2026-09-09. The fact package does not name any individual researchers or credit any discoverer, so no attribution is made in this report.

Affected Versions

All eight vulnerabilities affect Google Chrome versions prior to 153.0.8010.36. This is the single fixed version referenced across all vendor and database sources for this release.

Fixes and Mitigation

Google has shipped fixes for all eight vulnerabilities in Chrome version 153.0.8010.36. No workarounds or mitigations beyond updating to this version have been described in the available source material.

Recommended Action

Update Google Chrome to version 153.0.8010.36 or later as soon as possible. Chrome typically updates automatically on restart, but administrators managing fleets of devices should verify that the update has been applied, particularly on macOS and iOS deployments where device- and platform-specific fixes are included.

PatchBriefing score

6.4 / 10 · Medium

Official CVSS: 9.6

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

The PatchBriefing score of 6.4 for each of these eight vulnerabilities reflects a high CVSS base score of 9.6 (contributing 5.28 points), combined with additional contributions for unauthenticated remote exploitability (0.6 points) and Chrome's very large installed base as a widely used product (0.5 points). No points were added for known exploitation, public exploit code, or EPSS data, as none of these factors are present or available in the fact package. The score reflects substantial technical severity tempered by the absence of confirmed in-the-wild exploitation.

Affected versions

≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched

Reported fixes

Google has shipped fixes for all eight vulnerabilities in Chrome version 153.0.8010.36. No workarounds or mitigations beyond updating to this version have been described in the available source material.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome 153.0.8010.36 Fixes Eight High-Severity Memory Safety Vulnerabilities
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email