Chrome CVE-2026-87491 is being exploited in the wild, according to Google. Chrome desktop users should verify their installed version and update if they are still below the fixed Chrome 153 builds. Google released version 153.0.8010.36 for Linux and 153.0.8010.36/.37 for Windows and macOS.
Current answer: if your Chrome desktop build is older than the fixed version for your operating system, update Chrome, relaunch the browser and check the version again. Do not assume an automatic update has finished until the installed build reflects the fixed release.
Chrome CVE-2026-87491 fixed versions
Google identifies CVE-2026-87491 as an out-of-bounds write vulnerability in the V8 JavaScript engine and says an exploit exists in the wild. The fixed desktop builds reviewed for this article are Chrome 153.0.8010.36 for Linux and Chrome 153.0.8010.36 or 153.0.8010.37 for Windows and macOS.
CERT-In separately issued a HIGH-severity Chrome desktop advisory and identified CVE-2026-87491 as actively exploited. That HIGH rating applies to the broader CERT-In Chrome advisory. Google’s Chromium release notes classify this individual CVE as Medium severity, so the two labels should not be collapsed into a claim that Google rated CVE-2026-87491 Critical.
What the vulnerability can do
The reviewed evidence describes CVE-2026-87491 as a V8 memory-safety flaw that can be triggered through crafted web content. Current government security guidance says successful exploitation can allow arbitrary code execution inside the Chrome sandbox.
That does not by itself establish full-device or administrator-level compromise. The reviewed primary evidence does not confirm that CVE-2026-87491 alone escapes the Chrome sandbox, and TPS has not verified a separate exploit-chain vulnerability that should be treated as part of this specific issue.
How to check whether your Chrome version is fixed
Open Chrome’s About Chrome page and note the full version number shown after the browser checks for updates.
Linux should be on 153.0.8010.36 or later. Windows and macOS should be on 153.0.8010.36, 153.0.8010.37 or a later stable build.
If Chrome offers an update, allow it to complete. A downloaded update is not fully active until the browser has been relaunched where required.
Return to About Chrome and confirm that the installed version now meets or exceeds the fixed version for your operating system.
What active exploitation changes
The important change is not simply that another Chrome vulnerability was patched. Google has explicitly said that an exploit for CVE-2026-87491 exists in the wild. That moves the issue from a theoretical vulnerability into an active-exploitation state and makes version verification more urgent for users and organizations running affected Chrome desktop builds.
TPS has not verified how many systems have been targeted, who is operating the exploit, whether Indian users are specifically being targeted or whether public indicators of compromise are available. Those details should remain unresolved unless Google, CERT-In or another controlling security source publishes additional evidence.
Does this affect Edge, Brave or other Chromium browsers?
This article does not assume that every Chromium-based browser has the same affected or fixed version state as Google Chrome. Those browsers package Chromium on their own release schedules, so users should rely on the relevant browser vendor’s current security advisory or fixed-build information rather than applying Chrome’s version number directly.
Verification note
ThePulseSignal reviewed Google’s Chrome Stable Channel release, CERT-In’s current Chrome advisory and corroborating government cyber guidance. The fixed Chrome desktop builds and active-exploitation statement are confirmed. Campaign scope, public IOCs, full-device compromise, direct CISA KEV status and vendor-specific impact outside Google Chrome remain unresolved.



