Google Chrome: 25 Vulnerabilities Patched, Including Exploited V8 Zero-Day
Google Chrome 153.0.8010.36 addresses 25 vulnerabilities, including a critical zero-day exploited in the wild, patched on September 9, 2026.

Key findings
- Google Chrome 153.0.8010.36 patches 25 vulnerabilities disclosed on September 9, 2026.
- Batch includes critical flaws like buffer overflows, use-after-free, and out-of-bounds writes.
- CVE-2026-87639, a V8 engine vulnerability, was actively exploited in the wild as a zero-day.
- Vulnerabilities span across various components including ANGLE, WebGL, V8, and Extensions.
- Immediate update to Chrome 153.0.8010.36 is recommended for all users.
On September 9, 2026, Google released Chrome 153.0.8010.36 (and .37 on Windows/Mac) to address a significant batch of 230 security vulnerabilities. This release included 25 CVEs disclosed together, ranging in severity from Low to Critical, with a notable focus on memory corruption and authorization bypass flaws. The update is crucial for all users due to the active exploitation of at least one vulnerability.
Several vulnerabilities fall into common exploit categories:
- Memory Corruption: A significant number of flaws involve memory safety issues. These include multiple "Use after free" vulnerabilities (CVE-2026-87652, CVE-2026-87648, CVE-2026-87646, CVE-2026-87637, CVE-2026-87634), "Buffer overflow" (CVE-2026-87654), "Out of bounds read" (CVE-2026-87650, CVE-2026-87647, CVE-2026-87640), and "Out of bounds write" (CVE-2026-87638, CVE-2026-87621). These types of vulnerabilities often lead to arbitrary code execution or memory disclosure.
- Authorization and Validation Issues: Flaws in authorization and state validation allowed attackers to bypass restrictions or access data they shouldn't. Examples include improper state validation in Safebrowsing (CVE-2026-87656, CVE-2026-87645), incorrect authorization in PushAPI (CVE-2026-8752) and Paint (CVE-2026-87651), and UI misrepresentation in FullScreen (CVE-2026-87653), Downloads (CVE-2026-87649), and Payments (CVE-2026-87635).
- Other Vulnerabilities: The batch also included an information leak in Extensions (CVE-2026-87658), a use after free in V8 (CVE-2026-87657), clickjacking in Downloads (CVE-2026-87655), type confusion in XML (CVE-2026-87636), and a race condition in the Browser (CVE-2026-87641).
The batch includes two critical vulnerabilities with a CVSSv3 score of 9.6: CVE-2026-87654 (Buffer overflow in ANGLE), CVE-2026-87650 (Out of bounds read in WebGL), CVE-2026-87646 (Use after free in Web Authentication), and CVE-2026-87638 (Out of bounds write in Media), CVE-2026-87637 (Use after free in Extensions), CVE-2026-87634 (Use after free in WebPackaging). Additionally, CVE-2026-87636 (Type confusion in XML) is rated High at 8.8.
Notably, at least one vulnerability, CVE-2026-87639 (an out-of-bounds write in V8), was being actively exploited in the wild prior to the patch release. This zero-day vulnerability, reported by Jihyeon Jeong of Compsec Lab, allowed for arbitrary code execution inside the sandbox. While initially described as medium severity by some sources, its in-the-wild exploitation underscores its significant risk.
Google Chrome version 153.0.8010.36 (and .37 on Windows/Mac) addresses all 25 of these vulnerabilities. Users are strongly advised to update their browsers immediately to the latest version to mitigate these risks. The update window for automatic updates may vary, making manual checks essential for prompt protection.
This coordinated disclosure of numerous vulnerabilities, including a zero-day, highlights the ongoing efforts by Google to secure Chrome and the persistent threats faced by web browsers. Users should remain vigilant and ensure their browsers are updated promptly to protect against potential exploitation.
The vulnerabilities patched include: CVE-2026-87658, CVE-2026-87657, CVE-2026-87656, CVE-2026-87655, CVE-2026-87654, CVE-2026-87653, CVE-2026-87652, CVE-2026-87651, CVE-2026-87650, CVE-2026-87649, CVE-2026-87648, CVE-2026-87647, CVE-2026-87646, CVE-2026-87645, CVE-2026-87644, CVE-2026-87643, CVE-2026-87642, CVE-2026-87641, CVE-2026-87640, CVE-2026-87639, CVE-2026-87638, CVE-2026-87637, CVE-2026-87636, CVE-2026-87635, CVE-2026-87634.