Google on Tuesday released Chrome 153 to the stable channel with patches for 230 vulnerabilities, including an exploited zero-day.
Tracked as CVE-2026-87491, the medium-severity security defect is described as an out-of-bounds write issue in Chrome’s V8 JavaScript and WebAssembly engine.
“Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the internet giant notes in its advisory.
The flaw was reported by Jihyeon Jeong of Compsec Lab, Seoul National University, who received a $2,500 bug bounty reward for the finding.
This is the seventh zero-day vulnerability patched in Chrome in 2026. The other six are: CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and CVE-2026-85046.













