
Executive Security Advisory: Google Chrome CVE-2026-87491 – zero-day actively exploited
Management summary
Google released Chrome 153 for Windows, macOS, and Linux on September 8, 2026 and confirmed that an exploit for CVE-2026-87491 exists in the wild. The flaw is an out-of-bounds write in the V8 JavaScript engine. Organizations should therefore verify installed browser versions instead of relying only on the normal background update cycle.
What is affected?
Google Chrome is affected. Fixed Stable versions are 153.0.8010.36 for Linux and 153.0.8010.36/.37 for Windows and macOS. Google notes that rollout may take days or weeks.
Why is this dangerous?
V8 processes JavaScript content from web pages. An out-of-bounds write is a memory-corruption class that can be abused to manipulate process memory. The key prioritization signal is that Google confirms exploitation in the wild. Exploit details remain restricted while users update.
Recommended actions
Priority 1: Update Chrome on all managed Windows, macOS, and Linux endpoints immediately. Priority 2: Use Intune, RMM, or another endpoint-management platform to identify devices still running older versions. Priority 3: Ensure the browser is restarted after the update so the fixed build is actually loaded. Prompt users of unmanaged systems to update immediately.
What to ask your IT provider
1. Are all managed Chrome installations already on 153.0.8010.36/.37 or later? 2. Can we centrally identify devices that remain on an older build? 3. Do we verify or enforce a browser restart after updates?
Our assessment
The severity score alone would not justify an Executive Security Advisory. Confirmed exploitation combined with Chrome's extremely broad deployment makes this update time-critical, especially where browser patch levels are not centrally enforced.
Sources
Google Chrome Releases, Stable Channel Update for Desktop, September 8, 2026: https://chromereleases.googleblog.com/2026/09/ | BleepingComputer, September 9, 2026: https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/





