top of page

Executive Security Advisory: Google Chrome CVE-2026-87491 – zero-day actively exploited

7 days ago
2 min read

Management summary

Google released Chrome 153 for Windows, macOS, and Linux on September 8, 2026 and confirmed that an exploit for CVE-2026-87491 exists in the wild. The flaw is an out-of-bounds write in the V8 JavaScript engine. Organizations should therefore verify installed browser versions instead of relying only on the normal background update cycle.

What is affected?

Google Chrome is affected. Fixed Stable versions are 153.0.8010.36 for Linux and 153.0.8010.36/.37 for Windows and macOS. Google notes that rollout may take days or weeks.

Why is this dangerous?

V8 processes JavaScript content from web pages. An out-of-bounds write is a memory-corruption class that can be abused to manipulate process memory. The key prioritization signal is that Google confirms exploitation in the wild. Exploit details remain restricted while users update.

Recommended actions

Priority 1: Update Chrome on all managed Windows, macOS, and Linux endpoints immediately. Priority 2: Use Intune, RMM, or another endpoint-management platform to identify devices still running older versions. Priority 3: Ensure the browser is restarted after the update so the fixed build is actually loaded. Prompt users of unmanaged systems to update immediately.

What to ask your IT provider

1. Are all managed Chrome installations already on 153.0.8010.36/.37 or later? 2. Can we centrally identify devices that remain on an older build? 3. Do we verify or enforce a browser restart after updates?

Our assessment

The severity score alone would not justify an Executive Security Advisory. Confirmed exploitation combined with Chrome's extremely broad deployment makes this update time-critical, especially where browser patch levels are not centrally enforced.

Sources

Google Chrome Releases, Stable Channel Update for Desktop, September 8, 2026: https://chromereleases.googleblog.com/2026/09/ | BleepingComputer, September 9, 2026: https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/

 
 

Contact us

vNext GmbH, Patschär 7, 7306 Fläsch

Phone: +41 81 710 50 85

Ihr Profi für Websites und unbeschreibliches Foto Design
Ihr Partner für unvergessliche Events und Momente mit Ihren liebsten.
Wenn es Vertrauen braucht ist PSD Ihr Partner.

We work with the best partners

© 2023 by vNext GmbH

bottom of page