LATEST View all updates

Chrome CVE-2026-87491 Exploited in the Wild: Check Your Version and Update

Google confirms active exploitation of CVE-2026-87491. Check your Chrome desktop version and update to a fixed build.

Chrome CVE-2026-87491 editorial security image with browser update and active exploitation theme

Signal Brief

  • Google says an exploit for Chrome CVE-2026-87491 exists in the wild.
  • Fixed desktop builds include Chrome 153.0.8010.36 for Linux and 153.0.8010.36/.37 for Windows and macOS.
  • Check About Chrome, install any available update, relaunch and verify the installed version again.
  • The reviewed evidence confirms code execution inside the Chrome sandbox but does not establish full-device compromise from this flaw alone.

Chrome CVE-2026-87491 is being exploited in the wild, according to Google. Chrome desktop users should verify their installed version and update if they are still below the fixed Chrome 153 builds. Google released version 153.0.8010.36 for Linux and 153.0.8010.36/.37 for Windows and macOS.

Current answer: if your Chrome desktop build is older than the fixed version for your operating system, update Chrome, relaunch the browser and check the version again. Do not assume an automatic update has finished until the installed build reflects the fixed release.

Chrome CVE-2026-87491 fixed versions

Google identifies CVE-2026-87491 as an out-of-bounds write vulnerability in the V8 JavaScript engine and says an exploit exists in the wild. The fixed desktop builds reviewed for this article are Chrome 153.0.8010.36 for Linux and Chrome 153.0.8010.36 or 153.0.8010.37 for Windows and macOS.

CERT-In separately issued a HIGH-severity Chrome desktop advisory and identified CVE-2026-87491 as actively exploited. That HIGH rating applies to the broader CERT-In Chrome advisory. Google’s Chromium release notes classify this individual CVE as Medium severity, so the two labels should not be collapsed into a claim that Google rated CVE-2026-87491 Critical.

What the vulnerability can do

The reviewed evidence describes CVE-2026-87491 as a V8 memory-safety flaw that can be triggered through crafted web content. Current government security guidance says successful exploitation can allow arbitrary code execution inside the Chrome sandbox.

That does not by itself establish full-device or administrator-level compromise. The reviewed primary evidence does not confirm that CVE-2026-87491 alone escapes the Chrome sandbox, and TPS has not verified a separate exploit-chain vulnerability that should be treated as part of this specific issue.

How to check whether your Chrome version is fixed

Check the installed version

Open Chrome’s About Chrome page and note the full version number shown after the browser checks for updates.

Compare it with the fixed build

Linux should be on 153.0.8010.36 or later. Windows and macOS should be on 153.0.8010.36, 153.0.8010.37 or a later stable build.

Install the available update

If Chrome offers an update, allow it to complete. A downloaded update is not fully active until the browser has been relaunched where required.

Verify again after relaunch

Return to About Chrome and confirm that the installed version now meets or exceeds the fixed version for your operating system.

What active exploitation changes

The important change is not simply that another Chrome vulnerability was patched. Google has explicitly said that an exploit for CVE-2026-87491 exists in the wild. That moves the issue from a theoretical vulnerability into an active-exploitation state and makes version verification more urgent for users and organizations running affected Chrome desktop builds.

TPS has not verified how many systems have been targeted, who is operating the exploit, whether Indian users are specifically being targeted or whether public indicators of compromise are available. Those details should remain unresolved unless Google, CERT-In or another controlling security source publishes additional evidence.

Does this affect Edge, Brave or other Chromium browsers?

This article does not assume that every Chromium-based browser has the same affected or fixed version state as Google Chrome. Those browsers package Chromium on their own release schedules, so users should rely on the relevant browser vendor’s current security advisory or fixed-build information rather than applying Chrome’s version number directly.

Verification note

ThePulseSignal reviewed Google’s Chrome Stable Channel release, CERT-In’s current Chrome advisory and corroborating government cyber guidance. The fixed Chrome desktop builds and active-exploitation statement are confirmed. Campaign scope, public IOCs, full-device compromise, direct CISA KEV status and vendor-specific impact outside Google Chrome remain unresolved.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial guidance to help readers verify the current Chrome CVE-2026-87491 security state. Google confirms exploitation in the wild, but the reviewed evidence does not establish campaign scope, India-specific victim numbers, public compromise indicators or full-device compromise from this flaw alone. Verify your installed Chrome version and follow the controlling current Google or organizational security guidance before consequential security decisions.