Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.
“Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory.
The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University’s Compsec Lab, reported it to Google.
Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.
Those who prefer not to update manually can rely on Chrome to automatically check for updates and install them at the next launch.
This high-severity zero-day vulnerability (CVE-2026-87491) stems from an out-of-bounds write weakness in the Chrome V8 JavaScript and WebAssembly engine, which remote attackers can exploit to execute arbitrary code inside the web browser’s sandbox via crafted HTML pages.
Successful exploitation can also let them access data beyond the memory buffer through heap corruption, exposing sensitive information or triggering a crash.
While Google said it was aware of CVE-2026-87491 zero-day exploits used in the wild, the company has yet to share further details about these attacks.
“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” Google said. “We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”
Since the start of the year, Google addressed five more actively exploited zero-days:
Google fixed eight other zero-days exploited in the wild in 2025, many of them reported by its Threat Analysis Group (TAG), known for tracking zero-day exploits used in spyware attacks.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Google warns of new Chrome zero-day flaw exploited in attacks
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
N-able patches max severity N-central flaw amid ongoing attacks
SonicWall warns of actively exploited SMA1000 zero-day flaws
Sonicwall warns of new SMA1000 zero-day exploited in attacks
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
N-able patches max severity N-central flaw amid ongoing attacks
Overdue a password health-check? Audit your Active Directory for free
Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions.
See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.


