Writer
Fact-Checker
Teck Hustlers Where tech meets hustle!
Chrome 153 fixes 230 bugs, including CVE-2026-87491, a zero-day already being used in real attacks before Google shipped the patch. It is the seventh actively exploited Chrome zero-day of 2026.

Published: October 7, 2026 · Last updated: October 7, 2026
TL;DR: Chrome 153 fixes 230 bugs, but only one really matters if you haven’t updated yet: a zero-day tracked as CVE-2026-87491 that was already being used in real attacks before Google shipped the patch.

Seven. That’s how many zero-days Google has had to patch in Chrome so far this year, each one found or reported after someone was already using it against real targets rather than in a lab. The latest, CVE-2026-87491, landed in the Chrome 153 update alongside 229 other fixes, and it’s the one worth caring about.
A zero-day, for anyone who hasn’t had to think about this before, just means a vulnerability that was being exploited in the wild before a patch existed. There was no window where defenders had the fix and attackers didn’t. By the time Google’s security team confirmed the bug and pushed 153 out the door, it had already been used against somebody.
What makes this one worth a headline isn’t the number by itself so much as the trend behind it. Chrome has now needed an emergency, out-of-cycle patch for an actively exploited bug roughly once every seven weeks this year. That’s not Chrome getting worse. It’s more likely a sign of how much money now sits behind browser exploit development, since a working Chrome zero-day is one of the most valuable things a serious attacker, state-level or otherwise, can own. Browsers sit between a user and basically everything they do online, which makes a reliable exploit worth far more than most other categories of bug.
Google hasn’t published deep technical detail on how 87491 was being used, which is standard practice while a patch is still rolling out to the roughly three billion devices running Chrome. Security researchers who track these disclosures expect more specifics once adoption of 153 is further along, typically a few weeks out.
For regular users, the fix is almost insultingly simple. Chrome updates itself in the background most of the time, but it only actually applies the update the next time you fully close and reopen the browser. If you’ve had the same Chrome window open for a few days, which plenty of people do, you’re probably still running the vulnerable version right now. Open a new tab, type chrome://settings/help, and check the version number. If it isn’t 153, relaunch the browser.
Businesses running managed Chrome deployments through Google Workspace or an MDM tool have less excuse to be behind, since those updates typically push on a schedule IT sets rather than on whether an employee feels like restarting their browser. If your organization is still on a staged rollout policy for Chrome, this is a good week to push 153 through faster than usual.
Related: Microsoft and Nvidia’s hardware event today and WordPress’s own critical patch this week.
Bottom Line: Seven actively exploited Chrome bugs in roughly nine months isn’t a reason to panic, but it is a reason to stop treating browser updates as optional. Relaunch the browser today, not whenever you next restart your computer anyway.
Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest
]]>