Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google has released Chrome version 153 to the stable channel for Windows, Mac, and Linux to address 230 security vulnerabilities. The update includes a fix for a V8 JavaScript engine zero-day flaw that is actively targeted in attacks. This represents the seventh exploited zero-day vulnerability patched by Google since the start of the year. Users must update their browsers immediately to version 153.0.8010.36 on Linux and versions 153.0.8010.36 or 153.0.8010.37 on Windows and Mac to prevent potential arbitrary code execution and system compromise.
What changed
Google officially identified the V8 zero-day tracked as CVE-2026-87491 and rolled out Chrome 153 to fix it along with 229 other security flaws.
Live updates
-
Google Issues Chrome 153 Patch for Seventh Zero-Day Vulnerability
Google has released Chrome version 153 to the stable channel for Windows, Mac, and Linux to address 230 security vulnerabilities. The update includes a fix for a V8 JavaScript engine zero-day flaw that is actively targeted in attacks. This represents the seventh exploited zero-day vulnerability patched by Google since the start of the year. Users must update their browsers immediately to version 153.0.8010.36 on Linux and versions 153.0.8010.36 or 153.0.8010.37 on Windows and Mac to prevent potential arbitrary code execution and system compromise.
Why it matters
Active browser exploitation campaigns threaten users who visit malicious websites, making rapid software deployment critical for defense. The V8 engine vulnerability allows attackers to target foundational browser components that process JavaScript. Google continues to issue rapid security updates to address heavily targeted flaws in the stable channel.
What is confirmed
- Google has released Chrome 153 to the stable channel for Windows, Mac, and Linux.
- The update fixes 230 vulnerabilities, including a zero-day flaw in the V8 JavaScript engine.
- This security update addresses the seventh actively exploited Chrome zero-day patched since the start of the year.
- The zero-day flaw is tracked under the identifier CVE-2026-87491.
- The stable channel update ships as version 153.0.8010.36 on Linux and versions 153.0.8010.36 and 153.0.8010.37 on Windows and Mac.
- The V8 bug could let attackers run arbitrary code.
Still unconfirmed
- The vulnerability is connected to threat actor groups utilizing specific campaign targets.
What to watch next
- Disclosures regarding the specific threat actors or campaign targets behind CVE-2026-87491
- Additional technical analysis detailing how attackers bypass the browser sandbox using this V8 flaw
- Adoption rates of Chrome 153 across the global user base
confidence 95%Sources used for this update (7)
- www.bleepingcomputer.com — Google warns of new Chrome zero-day bug exploited in attacks
- cyberinsider.com — Google fixes second actively exploited Chrome zero-day in under five days
- www.securityweek.com — Chrome 153 Patches Seventh Zero-Day of 2026
- cybersecuritynews.com — Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild
- www.mirror.co.uk — Urgent new warning for all Chrome users and why you must restart your browser now
- www.pcquest.com — Hackers are exploiting a new Chrome zero day and Google wants you patched now
- securityaffairs.com — Google fixes the seventh actively exploited Chrome zero-day of 2026
-
CISA Adds Chromium V8 Type Confusion Zero-Day to Known Exploited Catalog
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities Catalog. This flaw is being actively used in attacks, prompting Google to release an urgent software update for Chrome. The patch addresses this zero-day alongside several other browser bugs. Users risk compromise by visiting malicious websites and should update their browsers immediately to mitigate the threat. Google has not identified the specific targets or the groups responsible for the attacks.
Why it matters
The V8 engine is the open-source JavaScript and WebAssembly engine used by Chrome and other Chromium-based browsers. Type confusion vulnerabilities can allow attackers to execute arbitrary code or bypass security boundaries. CISA inclusion in the KEV catalog mandates federal agencies to patch the flaw within specific timeframes.
What is confirmed
- The Google Chromium V8 type confusion vulnerability is tracked as CVE-2026-85046.
- CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities Catalog.
- The V8 vulnerability is being actively exploited in attacks.
- Google released a software update to patch this zero-day and other browser bugs.
What to watch next
- Identification of the threat actors responsible for the V8 attacks
- Disclosure of specific targets affected by the type confusion exploit
confidence 100%Sources used for this update (6)
- thehackernews.com — The Hacker News | #1 Trusted Source for Cybersecurity News
- cybersecuritynews.com — Weekly Cybersecurity Newsletter Bulletin – CrowdStrike Falcon, Chrome 0-Day, GPT-6 Astra, Dropbox Breach and 20+ Stories
- securityaffairs.com — Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
- cybersecuritynews.com — CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks
- www.bleepingcomputer.com — Latest Actively Exploited news
- securityaffairs.com — Security Affairs
-
Google Issues Chrome Update to Fix Active V8 Zero-Day
Google has released an urgent software update for Chrome to address a critical security flaw in the V8 engine that malicious actors are actively exploiting in the wild. Multiple security advisories warn that visiting malicious websites puts users at high risk from these critical browser vulnerabilities. Google has issued patches for multiple browser bugs alongside the zero-day exploit, prompting industry calls for users to update their browsers immediately. The company has not disclosed specific details regarding the targets or perpetrators of the active attacks.
Why it matters
Zero-day vulnerabilities in core browser components like the V8 JavaScript engine present immediate risks because attackers can execute arbitrary code before users realize an exploit is underway. Prompt patching by vendors like Google is vital to block ongoing attacks on unsuspecting web users. Security researchers track these exploits closely to understand evolving threat techniques.
What is confirmed
- Google has released a Chrome update to patch a zero-day vulnerability in the V8 engine that is under active exploitation.
- Two critical Chrome flaws put users at risk on malicious websites.
Still unconfirmed
- Google has not revealed who is using the V8 zero-day exploit or whom they targeted.
What to watch next
- Google releasing additional technical details regarding the exploit targets or threat actor identity.
- Further security advisories detailing the exact nature of the critical browser flaws.
confidence 100%Sources used for this update (8)
- The Hacker News — Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
- Malwarebytes — Two critical Chrome flaws put users at risk on malicious websites
- cybersecuritynews.com — Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild
- tech.yahoo.com — Google patches multiple browser bugs including one that was under active exploitation — so update now
- Hong Kong Computer Emergency Response Team Coordination Centre — Google Chrome Multiple Vulnerabilities
- Forbes — Google Update For Actively Exploited Chrome Security Flaw Confirmed
- decrypt.co — Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using
- securityaffairs.com — Security Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITION