← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

Chrome's September 8 release addresses an exploited vulnerability

Google's Chrome 153 release note acknowledges in-the-wild exploitation of CVE-2026-87491.

Source published 2026-09-08BrowsersChromeSecurity updates
Original publication preview: Chrome's September 8 release addresses an exploited vulnerability
Chrome Releases ↗

What was reported

Google's 8 September desktop release note lists 230 security fixes and says an exploit for CVE-2026-87491 exists in the wild. The release introduced Chrome 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.

These are the versions in that dated release note, not a recommendation to stop updating at that version. Subsequent stable updates may contain additional fixes.

Defensive perspective

Use the current stable update offered for the platform, complete the relaunch and confirm the installed version. In managed environments, check update success and devices waiting for restart, rather than relying only on deployment intent.

Forensic focus

If a browser incident is suspected, record the version and preserve relevant profile, download and endpoint records under the case collection plan. The presence of an affected version alone is not evidence that exploitation occurred.

Source published 8 September 2026. Briefing prepared 26 September 2026.

Read Google's release note.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC