Google warns of new Chrome zero-day flaw exploited in attacks
Google has pushed out Chrome 153 to fix 230 security flaws, which includes the seventh actively exploited zero-day vulnerability patched this year. The newly released stable channel update applies to Windows, Mac, and Linux systems. Cybersecurity authorities have flagged the underlying issue in the V8 engine as an active threat, adding the tracked identifier to catalog listings. Users are urged to apply the software updates immediately to protect against malicious attacks targeting the browser.
Listen to Live Briefing
Real-time synthesized voice briefing Β· Live Feeds Desk
- β Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.
- β Google has released Chrome 153 to the stable channel with fixes for 230 security vulnerabilities, including a zero-day flaw in the V8 engine.
- β Google has rolled out Chrome 153 to the stable channel for Windows, Mac, and Linux, shipping as version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.
What changed
Google released Chrome 153 on Tuesday to fix 230 vulnerabilities, marking the second actively exploited zero-day patched in under five days.
Live updates
-
Google Patches Seventh Chrome Zero-Day Vulnerability of 2026
Google has pushed out Chrome 153 to fix 230 security flaws, which includes the seventh actively exploited zero-day vulnerability patched this year. The newly released stable channel update applies to Windows, Mac, and Linux systems. Cybersecurity authorities have flagged the underlying issue in the V8 engine as an active threat, adding the tracked identifier to catalog listings. Users are urged to apply the software updates immediately to protect against malicious attacks targeting the browser.
Why it matters
This release follows a rapid sequence of patches deployed by Google to address high-risk security flaws in the V8 JavaScript engine. The latest updates target vulnerabilities that put users at risk when browsing the web. Security agencies track these weaponized exploits closely to prevent wider network compromises.
What is confirmed
- Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.
- Google has released Chrome 153 to the stable channel with fixes for 230 security vulnerabilities, including a zero-day flaw in the V8 engine.
- Google has rolled out Chrome 153 to the stable channel for Windows, Mac, and Linux, shipping as version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.
Still unconfirmed
- CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities Catalog, warning that the flaw is being actively exploited in attacks.
What to watch next
- Additional technical details regarding threat actor campaigns exploiting CVE-2026-87491 or CVE-2026-85046.
- Further updates from CISA or security vendors tracking Chromium browser exploitation.
confidence 90%Sources used for this update (5)
- cybersecuritynews.com β CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks
- www.bleepingcomputer.com β Google warns of new Chrome zero-day bug exploited in attacks
- cyberinsider.com β Google fixes second actively exploited Chrome zero-day in under five days
- www.securityweek.com β Chrome 153 Patches Seventh Zero-Day of 2026
- cybersecuritynews.com β Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild
-
Google Patches Actively Exploited Chrome V8 Zero-Day
Google has released a security update for Chrome to fix a V8 zero-day vulnerability that attackers were actively exploiting. The update addresses multiple browser bugs, including two critical flaws that placed users at risk when visiting malicious websites. Users are urged to update their browsers immediately to mitigate these risks. This patch is part of a broader series of updates addressing dozens of vulnerabilities across different web browsers.
Why it matters
Zero-day vulnerabilities are flaws unknown to the vendor until they are exploited by attackers. Because the V8 engine handles JavaScript execution, flaws in this component can often lead to remote code execution.
What is confirmed
- Google released a Chrome update to patch an actively exploited V8 zero-day vulnerability.
- The security update addresses multiple browser bugs.
- Two critical Chrome flaws put users at risk on malicious websites.
What to watch next
- Confirmation of the specific CVE identifier for the V8 flaw
- Reports on the scale of the active exploitation attacks
confidence 100%Sources used for this update (13)
- The Hacker News β Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
- Malwarebytes β Two critical Chrome flaws put users at risk on malicious websites
- TechRadar β Google patches multiple browser bugs including one that was under active exploitation β so update now
- Forbes β Google Update For Actively Exploited Chrome Security Flaw Confirmed
- BleepingComputer β Google warns of new Chrome zero-day flaw exploited in attacks
- SecurityWeek β Chrome and Firefox Updates Patch Dozens of Vulnerabilities
- www.seroundtable.com β Daily Search Forum Recap: September 7, 2026
- thehackernews.com β β‘ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
- thehackernews.com β Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE β Public Exploit Released
- www.bleepingcomputer.com β ConnectWise warns of new ScreenConnect flaw without patch
- www.securityweek.com β Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- thecyberexpress.com β Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores
Community Sentiment: How do you assess this situation?
Voice your perspective Β· Real-time aggregated sentiment from the Live Feeds community