Google has released a major security update for its Chrome browser that fixes 230 vulnerabilities in total. According to the company, at least one of them is already being actively exploited in attacks, so users should update their browser as soon as possible.
The critical flaw, tracked as CVE-2026-87491, sits in the V8 JavaScript engine. It stems from an out-of-bounds write, meaning data gets written outside the memory area it was meant for. Attackers can use this to run their own code inside the Chrome sandbox. All it takes for a successful attack is for a victim to open a specially crafted web page, for example through a link in an email, a chat message, or a social media post. Google says no further interaction is required from the victim.
Five critical and 41 high-severity flaws
Of the 230 fixed vulnerabilities, Google rates five as critical, 41 as high, 133 as medium, and 51 as low severity. Eleven of the bugs were reported by outside security researchers and rewarded through the bug bounty program, and payouts for 20 more submissions may still follow. The highest single reward so far, 5,000 dollars, went to a medium-severity use-after-free flaw tracked as CVE-2026-87504. In total, Google has paid out roughly 23,000 dollars in bounties for this update.
Update available for all platforms
The fixes ship in Chrome versions 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux. Since many other browsers, including Microsoft Edge, Brave, and Vivaldi, are built on the same Chromium base as Chrome, they should receive matching updates soon as well. Anyone running Chrome or a Chromium-based browser should check their settings to confirm the latest version is installed and trigger the update manually if needed.