Google has released Chrome 153 to the stable channel across Windows, Mac, and Linux platforms. This update, identified as version 153.0.8010.36 on Linux and 153.0.8010.36/.37 for Windows and Mac, brings a significant batch of 230 security fixes, marking one of the most extensive security updates in recent Chrome versions.
Patch Details and Release Schedule
Users can expect to receive this update in the coming days and weeks. Among the numerous fixes, one of the most notable is the patching of a Medium-severity vulnerability, CVE-2026-87491, found in V8, Chrome’s JavaScript and WebAssembly engine. This flaw, which is currently being exploited in the wild, underscores the critical importance of updating to the latest version immediately.
The vulnerability was reported by Jihyeon Jeong from Compsec Lab at Seoul National University, who was awarded a $2,500 bounty. Despite its Medium rating, the active exploitation of this V8 memory-corruption issue is significant, as such vulnerabilities can be combined with others to achieve remote code execution.
Additional Security Vulnerabilities Addressed
In addition to the zero-day vulnerability, Chrome 153 addresses five Critical-rated issues, primarily involving use-after-free and out-of-bounds write vulnerabilities in WebGL and Cast components. These include CVE-2026-87464, CVE-2026-87488, CVE-2026-87438, CVE-2026-87527, and CVE-2026-87628, several of which were discovered by Google’s internal security team.
The update also fixes 43 High-severity vulnerabilities affecting modules such as ANGLE, PDFium, V8, Views, DevTools, Web Authentication, and Payments. Notably, CVE-2026-87512 in ANGLE and CVE-2026-87585 in PDFium were reported by external researchers and carried bounty rewards of up to $2,500. The increasing use of AI-assisted tools, like those from OpenAI’s Codex Security team, highlights the evolving landscape of vulnerability detection in browser security.
Medium and Low-Severity Fixes
The majority of this release comprises 141 Medium-severity and 41 Low-severity fixes, addressing issues like incorrect and missing authorization, UI misrepresentation, and information leaks across components including FileSystem, ServiceWorker, Extensions, SafeBrowsing, and Payments.
Among the notable bounties, CVE-2026-87504, a use-after-free in Core, earned a $5,000 reward, while CVE-2026-87640 in WebView was rewarded with $3,000, both credited to the same researcher.
Significance of the Update
This comprehensive update, addressing 230 vulnerabilities and the active exploitation of a zero-day flaw, makes Chrome 153 a crucial update for both enterprise and individual users. Google’s proactive use of tools like AddressSanitizer, MemorySanitizer, and libFuzzer helps identify vulnerabilities before they are exploited, but the scale of this patch underscores the ongoing threats to browser security.
Users are strongly advised to update to at least build 153.0.8010.36 to ensure their systems are protected against these vulnerabilities.
