Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chrome 153 Updates Address 230 Security Flaws, Including Critical 0-Day

Chrome 153 Updates Address 230 Security Flaws, Including Critical 0-Day

Posted on September 9, 2026 By CWS

Google has released Chrome 153 to the stable channel across Windows, Mac, and Linux platforms. This update, identified as version 153.0.8010.36 on Linux and 153.0.8010.36/.37 for Windows and Mac, brings a significant batch of 230 security fixes, marking one of the most extensive security updates in recent Chrome versions.

Patch Details and Release Schedule

Users can expect to receive this update in the coming days and weeks. Among the numerous fixes, one of the most notable is the patching of a Medium-severity vulnerability, CVE-2026-87491, found in V8, Chrome’s JavaScript and WebAssembly engine. This flaw, which is currently being exploited in the wild, underscores the critical importance of updating to the latest version immediately.

The vulnerability was reported by Jihyeon Jeong from Compsec Lab at Seoul National University, who was awarded a $2,500 bounty. Despite its Medium rating, the active exploitation of this V8 memory-corruption issue is significant, as such vulnerabilities can be combined with others to achieve remote code execution.

Additional Security Vulnerabilities Addressed

In addition to the zero-day vulnerability, Chrome 153 addresses five Critical-rated issues, primarily involving use-after-free and out-of-bounds write vulnerabilities in WebGL and Cast components. These include CVE-2026-87464, CVE-2026-87488, CVE-2026-87438, CVE-2026-87527, and CVE-2026-87628, several of which were discovered by Google’s internal security team.

The update also fixes 43 High-severity vulnerabilities affecting modules such as ANGLE, PDFium, V8, Views, DevTools, Web Authentication, and Payments. Notably, CVE-2026-87512 in ANGLE and CVE-2026-87585 in PDFium were reported by external researchers and carried bounty rewards of up to $2,500. The increasing use of AI-assisted tools, like those from OpenAI’s Codex Security team, highlights the evolving landscape of vulnerability detection in browser security.

Medium and Low-Severity Fixes

The majority of this release comprises 141 Medium-severity and 41 Low-severity fixes, addressing issues like incorrect and missing authorization, UI misrepresentation, and information leaks across components including FileSystem, ServiceWorker, Extensions, SafeBrowsing, and Payments.

Among the notable bounties, CVE-2026-87504, a use-after-free in Core, earned a $5,000 reward, while CVE-2026-87640 in WebView was rewarded with $3,000, both credited to the same researcher.

Significance of the Update

This comprehensive update, addressing 230 vulnerabilities and the active exploitation of a zero-day flaw, makes Chrome 153 a crucial update for both enterprise and individual users. Google’s proactive use of tools like AddressSanitizer, MemorySanitizer, and libFuzzer helps identify vulnerabilities before they are exploited, but the scale of this patch underscores the ongoing threats to browser security.

Users are strongly advised to update to at least build 153.0.8010.36 to ensure their systems are protected against these vulnerabilities.

Cyber Security News Tags:0-day vulnerability, browser security, Chrome 153, critical vulnerabilities, Cybersecurity, Google Chrome, Linux, Mac, security update, software patches, web security, Windows

Post navigation

Previous Post: Critical N-able N-central Flaw Exploited, Urgent Patch Required
Next Post: Microsoft Resolves Record 974 Vulnerabilities in September

Related Posts

U.S. Secret Service Dismantles 300 SIM Servers and 100,000 SIM Cards U.S. Secret Service Dismantles 300 SIM Servers and 100,000 SIM Cards Cyber Security News
Cl0p Hackers Target Windchill Servers for Data Theft Cl0p Hackers Target Windchill Servers for Data Theft Cyber Security News
Critical Apple 0-Day Flaw Targets High-Profile Users Critical Apple 0-Day Flaw Targets High-Profile Users Cyber Security News
Docker Open Sources Production-Ready Hardened Images for Free Docker Open Sources Production-Ready Hardened Images for Free Cyber Security News
Critical AWS-LC Vulnerabilities Expose Security Risks Critical AWS-LC Vulnerabilities Expose Security Risks Cyber Security News
Critical SonicWall Vulnerability Exploited by Hackers Critical SonicWall Vulnerability Exploited by Hackers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows Defender Vulnerability: New Flaw Discovered
  • Ivanti Releases Vital Security Updates for Key Products
  • Critical cPanel Vulnerability Allows Root Access
  • Chrome Users Urged to Update Amid V8 Security Flaw
  • Microsoft Resolves Record 974 Vulnerabilities in September

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows Defender Vulnerability: New Flaw Discovered
  • Ivanti Releases Vital Security Updates for Key Products
  • Critical cPanel Vulnerability Allows Root Access
  • Chrome Users Urged to Update Amid V8 Security Flaw
  • Microsoft Resolves Record 974 Vulnerabilities in September

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark