VYPR
Vypr IntelligenceAI-generatedSep 9, 2026· 27 CVEs

Google Chrome: 25 Vulnerabilities Patched, Including Exploited V8 Zero-Day

Google Chrome 153.0.8010.36 addresses 25 vulnerabilities, including a critical zero-day exploited in the wild, patched on September 9, 2026.

Key findings

  • Google Chrome 153.0.8010.36 patches 25 vulnerabilities disclosed on September 9, 2026.
  • Batch includes critical flaws like buffer overflows, use-after-free, and out-of-bounds writes.
  • CVE-2026-87639, a V8 engine vulnerability, was actively exploited in the wild as a zero-day.
  • Vulnerabilities span across various components including ANGLE, WebGL, V8, and Extensions.
  • Immediate update to Chrome 153.0.8010.36 is recommended for all users.

On September 9, 2026, Google released Chrome 153.0.8010.36 (and .37 on Windows/Mac) to address a significant batch of 230 security vulnerabilities. This release included 25 CVEs disclosed together, ranging in severity from Low to Critical, with a notable focus on memory corruption and authorization bypass flaws. The update is crucial for all users due to the active exploitation of at least one vulnerability.

Several vulnerabilities fall into common exploit categories:

The batch includes two critical vulnerabilities with a CVSSv3 score of 9.6: CVE-2026-87654 (Buffer overflow in ANGLE), CVE-2026-87650 (Out of bounds read in WebGL), CVE-2026-87646 (Use after free in Web Authentication), and CVE-2026-87638 (Out of bounds write in Media), CVE-2026-87637 (Use after free in Extensions), CVE-2026-87634 (Use after free in WebPackaging). Additionally, CVE-2026-87636 (Type confusion in XML) is rated High at 8.8.

Notably, at least one vulnerability, CVE-2026-87639 (an out-of-bounds write in V8), was being actively exploited in the wild prior to the patch release. This zero-day vulnerability, reported by Jihyeon Jeong of Compsec Lab, allowed for arbitrary code execution inside the sandbox. While initially described as medium severity by some sources, its in-the-wild exploitation underscores its significant risk.

Google Chrome version 153.0.8010.36 (and .37 on Windows/Mac) addresses all 25 of these vulnerabilities. Users are strongly advised to update their browsers immediately to the latest version to mitigate these risks. The update window for automatic updates may vary, making manual checks essential for prompt protection.

This coordinated disclosure of numerous vulnerabilities, including a zero-day, highlights the ongoing efforts by Google to secure Chrome and the persistent threats faced by web browsers. Users should remain vigilant and ensure their browsers are updated promptly to protect against potential exploitation.

The vulnerabilities patched include: CVE-2026-87658, CVE-2026-87657, CVE-2026-87656, CVE-2026-87655, CVE-2026-87654, CVE-2026-87653, CVE-2026-87652, CVE-2026-87651, CVE-2026-87650, CVE-2026-87649, CVE-2026-87648, CVE-2026-87647, CVE-2026-87646, CVE-2026-87645, CVE-2026-87644, CVE-2026-87643, CVE-2026-87642, CVE-2026-87641, CVE-2026-87640, CVE-2026-87639, CVE-2026-87638, CVE-2026-87637, CVE-2026-87636, CVE-2026-87635, CVE-2026-87634.

AI-written article. Grounded in 27 CVE records listed below.