Google has released crucial updates for its Chrome browser to address 230 security vulnerabilities, one of which is actively exploited. The affected vulnerability, tagged as CVE-2026-87491, is a medium-severity out-of-bounds issue within Chrome’s V8 JavaScript and WebAssembly engine.
Details of the V8 Flaw
The identified flaw allows attackers to execute arbitrary code within the browser’s sandbox by exploiting a crafted HTML page. Security expert Jihyeon Jeong from Compsec Lab, Seoul National University, reported the issue on August 6, 2026, earning a $2,500 reward for their responsible disclosure.
Google confirmed awareness of the exploit’s existence but refrained from disclosing further details on its real-world usage. The company stated that access to detailed bug information would remain restricted until most users have updated their browsers.
Additional Security Patches
In addition to CVE-2026-87491, Google addressed several critical vulnerabilities, notably in the WebGL and Cast components. These include use-after-free and buffer overflow issues, with identifiers CVE-2026-87464, CVE-2026-87488, CVE-2026-87438, CVE-2026-87527, and CVE-2026-87628, respectively.
Google also acknowledged OpenAI Codex Security for identifying a high-severity use-after-free flaw in WebPackaging, CVE-2026-87639. The company relies on various tools for detecting such issues, including AddressSanitizer and libFuzzer.
Recommendations for Users
To safeguard against these vulnerabilities, users should update their Chrome browsers to version 153.0.8010.36/.37 on Windows and macOS, and version 153.0.8010.36 on Linux. Users can check for updates by navigating to More > Help > About Google Chrome and selecting Relaunch.
Other browsers based on Chromium, such as Microsoft Edge, Brave, Opera, and Vivaldi, should also apply these fixes once available.
This update marks the seventh actively exploited Chrome zero-day addressed by Google this year, emphasizing the importance of maintaining up-to-date software to protect against emerging threats.
