INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Chrome Zero-Day Exploit Enables Code Execution Inside Sandbox
| 2026-09-10 10:52 CRITICAL HIGHExecutive Summary AI-generated
The latest incident data reveals a critical update to the Chrome browser, addressing 230 security vulnerabilities including one actively exploited in the wild as CVE-2026-87491. This vulnerability allows remote attackers to execute arbitrary code inside the browser's sandbox via a crafted HTML page. The update also fixes five other vulnerabilities rated Critical and includes 230 security fixes, with one known to be actively exploited. Google is aware of the issue and has been working on addressing it since the start of the year, including fixing flaws like CVE-2026-2441 and CVE-2026-3909.
Technical Mitigations AI-generated
* Use a reputable antivirus software and keep your operating system (Windows, macOS, or Linux) up to date with the latest security patches.
* Be cautious when clicking on links from unknown sources, as they may contain malicious websites that can exploit vulnerabilities like CVE-2026-87491.
* Regularly update extensions and add-ons installed in Chrome, such as Malwarebytes Browser Guard, which can help block phishing pages and malicious sites automatically.
* Use a web application firewall (WAF) or a security software to scan your browser for potential threats before they can do any harm.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
CVE-2026-87491CVE-2026-87491
CVE-2026-87639CVE-2026-87639
CVE-2026-87464CVE-2026-87464
CVE-2026-87488CVE-2026-87488
CVE-2026-5281CVE-2026-5281
CVE-2026-3910CVE-2026-3910
CVE-2026-85046CVE-2026-85046
CVE-2026-87628CVE-2026-87628
CVE-2026-3909CVE-2026-3909
CVE-2026-87527CVE-2026-87527
CVE-2026-2441CVE-2026-2441
CVE-2026-11645CVE-2026-11645
CVE-2026-87438CVE-2026-87438
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
technologytechnology
Incident Timeline
2016 August
Threat actors exploited a zero-day vulnerability in the Chrome browser to target Windows Server 2016.
Click on any entity below to view its context and source!
infrastructure
Windows
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
tactic
T1584.004 - Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
infrastructure
2016 Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
February 2026
Threat actors exploited a use after free vulnerability in the CSS rendering engine of Google Chrome.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-2441
Since the start of the year, Google has addressed the following zero-day flaws exploited in attacks in the wild:
February 2026 –
CVE-2026-2441
(CVSS score: 8.8) – Use after free in CSS.
organisation
CSS
Since the start of the year, Google has addressed the following zero-day flaws exploited in attacks in the wild:
February 2026 –
CVE-2026-2441
(CVSS score: 8.8) – Use after free in CSS.
general_metric
8.8 score
Since the start of the year, Google has addressed the following zero-day flaws exploited in attacks in the wild:
February 2026 –
CVE-2026-2441
(CVSS score: 8.8) – Use after free in CSS.
March 2026
Threat actors exploited a zero-day vulnerability in the Skia 2D graphics library to target Chrome browsers.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-3909
March 2026 –
CVE-2026-3909
(CVSS score: 8.8) – Out-of-bounds write in the Skia 2D graphics library and
CVE-2026-3910
(CVSS score: 8.8) –
vulnerability
CVE-2026-3910
March 2026 –
CVE-2026-3909
(CVSS score: 8.8) – Out-of-bounds write in the Skia 2D graphics library and
CVE-2026-3910
(CVSS score: 8.8) –
general_metric
8.8 score
March 2026 –
CVE-2026-3909
(CVSS score: 8.8) – Out-of-bounds write in the Skia 2D graphics library and
CVE-2026-3910
(CVSS score: 8.8) –
organisation
Skia 2D
March 2026 –
CVE-2026-3909
(CVSS score: 8.8) – Out-of-bounds write in the Skia 2D graphics library and
CVE-2026-3910
(CVSS score: 8.8) –
April 2026
Threat actors exploited a use-after-free bug in Dawn, the WebGPU component used for graphics processing.
Click on any entity below to view its context and source!
tactic
T1059.007 - JavaScript
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
vulnerability
CVE-2026-5281
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn,
vulnerability
CVE-2026-11645
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
vulnerability
CVE-2026-85046
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
general_metric
8.8 score
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn,
organisation
WebGPU
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
organisation
CVSS
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
June 2026
Google has released an updated version of Chrome Stable to address multiple zero-day vulnerabilities in its WebGPU component.
Click on any entity below to view its context and source!
tactic
T1059.007 - JavaScript
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
vulnerability
CVE-2026-5281
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
vulnerability
CVE-2026-11645
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
vulnerability
CVE-2026-85046
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
general_metric
8.8 score
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
organisation
WebGPU
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
organisation
CVSS
April 2026 –
CVE-2026-5281
(CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
September –
CVE-2026-85046
(CVSS score: 8.8) – V8 type confusion flaw.
infrastructure
Windows
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
infrastructure
Linux
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
organisation
Windows and Mac
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
infrastructure
8.8
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
infrastructure
152.0.7977
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
August 4, 2026
Security researcher Salvatore Gulizia reported the Chrome zero-day flaw on August 4, 2026.
Click on any entity below to view its context and source!
financial
$1,000 $ bug bounty
Security researcher Salvatore Gulizia, known as Serotav, reported the flaw on August 4, 2026, and received a $1,000 bug bounty.
August 6, 2026
Seoul National University's researchers were informed of the vulnerability on August 6, 2026.
Click on any entity below to view its context and source!
organisation
Seoul National University
Security researcher Jihyeon Jeong of Compsec Lab, Seoul National University, has been acknowledged for discovering and reporting the flaw on August 6, 2026.
2026/08/06
Seoul National University researchers reported a zero-day vulnerability in Chrome on August 6, 2026.
Click on any entity below to view its context and source!
organisation
Seoul National University
Researcher Jihyeon Jeong from Seoul National University reported the vulnerability on 2026-08-06.
September 04, 2026
Google fixes the sixth actively exploited Chrome zero-day of 2026.
Sep 04, 2026
Threat actors exploited a previously unknown zero-day vulnerability in the Google Chrome browser.
Sep 09, 2026
Threat actors exploited a previously unknown zero-day vulnerability in the Google Chrome browser to target users.
September 9, 2026
Threat actors exploited a zero-day vulnerability in the Google Chrome browser.
Click on any entity below to view its context and source!
data_breach
0 September
Sergiu Gatlan
* September 9, 2026
* 02:25 AM
* 0
!
September 09, 2026
Google fixes the seventh actively exploited Chrome zero-day of 2026.
2026/09/09
Threat actors exploited a zero-day vulnerability in the Google Chrome browser to target users.
Click on any entity below to view its context and source!
general_metric
7 Windows
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.
organisation
BleepingComputer
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.
general_metric
1 Video
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.
general_metric
2 Video
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.
general_metric
3 Video
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.
general_metric
4 Video
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.
general_metric
5 Video
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.
general_metric
6 Video
1/1 Skip Ad Continue watching after the ad!Image 36: Loading PodsVisit Advertiser websiteGO TO PAGE
Video 1
Video 2
Video 3
Video 4
Video 5
Video 6
Video 7
Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.
2003 - 2026
Threat actors used a zero-day exploit in the Chrome browser to target users through social media and feeds.
Click on any entity below to view its context and source!
organisation
Social & Feeds
* Advertising
* Write for BleepingComputer
* Social & Feeds
* Changelog
Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure
Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved
[]( "Back to Top")
2026/09/10
Google released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.
Click on any entity below to view its context and source!
organisation
Malwarebytes Browser Guard
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically.
infrastructure
Microsoft 365
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
BigBear Microsoft 365
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
MFA
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
victims
258 organizations
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
Unicode
[Image 43: Phishing Attackers conceal phishing lures using invisible Unicode characters](
S ponsor Posts
* !
infrastructure
Windows
The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.
For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux.
Google has updated Chrome Stable to version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it to Google.
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout..
For optimal protection, users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux.
infrastructure
Linux
The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.
For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux.
Google has updated Chrome Stable to version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.
The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it to Google.
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout..
For optimal protection, users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux.
Get the report
### Related Articles:
Google warns of new Chrome zero-day flaw exploited in attacks
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
N-able patches max severity N-central flaw amid ongoing attacks
SonicWall warns of actively exploited SMA1000 zero-day flaws
Sonicwall warns of new SMA1000 zero-day exploited in attacks
* Actively Exploited
* Emergency Update
* Google
* Google Chrome
* Web Browser
* Zero-Day
*
infrastructure
153.0.8010
The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.
For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux.
Google has updated Chrome Stable to version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.
The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it to Google.
Chrome 153.0.8010.36/.37 is up to date
You can find an explanation of the version numbering system and step-by-step instructions in our guide:
How to update Chrome on every operating system
.
"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a
description
of the flaw on the NIST National Vulnerability Database (NVD).
Google fixed the issue in Chrome 153.0.8010.36 and later versions.
organisation
Windows and Mac
The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.
Google has updated Chrome Stable to version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.
infrastructure
Macos
For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux.
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout..
For optimal protection, users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux.
organisation
Stack Protection
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
organisation
Windows Registry
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
organisation
the Windows Registry
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
organisation
Stable Desktop
The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it to Google.
organisation
Seoul National University's
The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it to Google.
infrastructure
152.0.7977
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout..
For optimal protection, users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux.
"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a
description
of the flaw in CVE.org.
organisation
SonicWall
Get the report
### Related Articles:
Google warns of new Chrome zero-day flaw exploited in attacks
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
N-able patches max severity N-central flaw amid ongoing attacks
SonicWall warns of actively exploited SMA1000 zero-day flaws
Sonicwall warns of new SMA1000 zero-day exploited in attacks
* Actively Exploited
* Emergency Update
* Google
* Google Chrome
* Web Browser
* Zero-Day
*
organisation
HTML
"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a
description
of the flaw on the NIST National Vulnerability Database (NVD).
Image 37: Google Chrome 153.0.8010.37
This high-severity zero-day vulnerability (CVE-2026-87491) stems from an out-of-bounds write weakness in the Chrome V8 JavaScript and WebAssembly engine, which remote attackers can exploit to execute arbitrary code inside the web browser's sandbox via crafted HTML pages.
The description says it’s an out-of-bounds write vulnerability in Chrome’s V8 engine that could allow a remote attacker to execute arbitrary code inside the browser’s sandbox via a crafted HTML page.
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page.
Hence, CVE-2026-85046 could potentially be triggered by a specially crafted HTML page containing malicious JavaScript, potentially allowing remote code execution within Chrome's sandboxed renderer process.
The bug affects Chrome’s JavaScript and WebAssembly engine and could let a remote attacker execute arbitrary code inside the browser sandbox by using a specially crafted HTML page.
"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a
description
of the flaw in CVE.org.
organisation
Google Chrome
"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a
description
of the flaw on the NIST National Vulnerability Database (NVD).
"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a
description
of the flaw in CVE.org.
organisation
the NIST National Vulnerability Database
"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a
description
of the flaw on the NIST National Vulnerability Database (NVD).
organisation
NVD
"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a
description
of the flaw on the NIST National Vulnerability Database (NVD).
organisation
CVE
The medium-severity vulnerability, assigned the CVE identifier
CVE-2026-87491
(CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.
organisation
Chrome
The medium-severity vulnerability, assigned the CVE identifier
CVE-2026-87491
(CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.
Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8).
The high-severity vulnerability, tracked as
CVE-2026-85046
(CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine.
A similar action is recommended for users of Chrome-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, though it may take a couple of extra days for fixes to arrive on those apps.
Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw.
organisation
WebAssembly
The medium-severity vulnerability, assigned the CVE identifier
CVE-2026-87491
(CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.
Image 37: Google Chrome 153.0.8010.37
This high-severity zero-day vulnerability (CVE-2026-87491) stems from an out-of-bounds write weakness in the Chrome V8 JavaScript and WebAssembly engine, which remote attackers can exploit to execute arbitrary code inside the web browser's sandbox via crafted HTML pages.
The bug affects Chrome’s JavaScript and WebAssembly engine and could let a remote attacker execute arbitrary code inside the browser sandbox by using a specially crafted HTML page.
The medium-severity flaw affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine.
V8 is Chrome’s open-source JavaScript and WebAssembly engine, which compiles and executes code used by websites.
The high-severity vulnerability, tracked as
CVE-2026-85046
(CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine.
organisation
Google
Google acknowledged it is "aware that an exploit for CVE-2026-87491 exists in the wild," but has not disclosed any additional specific information related to how it's being weaponized in real-world attacks and who is behind them.
Google fixes the seventh actively exploited Chrome zero-day of 2026.
[Image 7: Google warns of new Chrome zero-day bug exploited in attacks Google warns of new Chrome zero-day bug exploited in attacks](
* !
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.
Google fixes the sixth actively exploited Chrome zero-day of 2026.
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day.
organisation
CVE-2026
Google acknowledged it is "aware that an exploit for CVE-2026-87491 exists in the wild," but has not disclosed any additional specific information related to how it's being weaponized in real-world attacks and who is behind them.
“Google is aware that an exploit for CVE-2026-87491 exists in the wild.”
"Google is aware that an exploit for CVE-2026-87491 exists in the wild," the company said in a Tuesday security advisory.
“Google is aware that an exploit for CVE-2026-85046 exists in the wild,”
the advisory reads
.
“Google is aware that an exploit for CVE-2026-85046 exists in the wild.”
"
As is usual in these cases, Google acknowledged that an "exploit for CVE-2026-85046 exists in the wild," but did not reveal any details about the nature of the attacks so as to ensure that a majority of the users are updated with a fix and to prevent further exploitation.
organisation
WebGL
Besides CVE-2026-87491, the latest update also fixes five critical security flaws in WebGL and Cast components -
CVE-2026-87464 - Use-after-free in WebGL
CVE-2026-87488 - Use-after-free in WebGL
CVE-2026-87438 - Out-of-bounds write in WebGL
CVE-2026-87527 - Buffer overflow in WebGL
CVE-2026-87628 - Use-after-free in Cast
Google said it reported 195 out of the 230 flaws that have been addressed in the update.
Besides this medium-severity flaw, the update fixes five vulnerabilities rated Critical, four of which were found in WebGL (Web Graphics Library).
organisation
Cast
Besides CVE-2026-87491, the latest update also fixes five critical security flaws in WebGL and Cast components -
CVE-2026-87464 - Use-after-free in WebGL
CVE-2026-87488 - Use-after-free in WebGL
CVE-2026-87438 - Out-of-bounds write in WebGL
CVE-2026-87527 - Buffer overflow in WebGL
CVE-2026-87628 - Use-after-free in Cast
Google said it reported 195 out of the 230 flaws that have been addressed in the update.
infrastructure
8.8
Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8).
Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw.
organisation
Chrome’s V8
The description says it’s an out-of-bounds write vulnerability in Chrome’s V8 engine that could allow a remote attacker to execute arbitrary code inside the browser’s sandbox via a crafted HTML page.
organisation
Skia 2D
* Two other Chrome zero-day bugs exploited in attacks in March: an out-of-bounds write weakness in the Skia 2D graphics library (CVE-2026-3909), and an inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine (CVE-2026-3910).
Two additional Chrome zero-days
exploited in March attacks
: an out-of-bounds write flaw in the Skia 2D graphics library (CVE-2026-3909) and an inappropriate implementation issue in the V8 JavaScript and WebAssembly engine (CVE-2026-3910).
organisation
Chrome’s
Previous fixes include:
An out-of-bounds read and write vulnerability in Chrome’s V8 JavaScript engine (CVE-2026-11645), exploited in the wild and
patched in June
.
organisation
Critical
Besides this medium-severity flaw, the update fixes five vulnerabilities rated Critical, four of which were found in WebGL (Web Graphics Library).
organisation
Vulnerability / Browser Security
Ravie Lakshmanan
Sep 09, 2026
Vulnerability / Browser Security
Google on Thursday
released
updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.
Ravie Lakshmanan
Sep 04, 2026
Vulnerability / Browser Security
Google on Thursday
released
security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.
organisation
Microsoft Edge, Brave,
A similar action is recommended for users of Chrome-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, though it may take a couple of extra days for fixes to arrive on those apps.
Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available.
organisation
CVE-2026-85046
Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw.
CVE-2026-85046 is the sixth actively exploited bug Google has fixed in Chrome since the start of the year.
organisation
Patch Actively
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day.
organisation
CSS
"
Since the start of the year, Google addressed five more actively exploited zero-days:
* An iterator invalidation bug (CVE-2026-2441) in CSSFontFeatureValuesMap (Chrome's implementation of CSS font feature values), which Google addressed in mid-February.
An iterator invalidation vulnerability (CVE-2026-2441) in CSSFontFeatureValuesMap, Chrome’s implementation of CSS font feature values,
fixed in mid-February
.
organisation
Chromium
A use-after-free weakness in Dawn (CVE-2026-5281), the underlying cross-platform implementation of the WebGPU standard used by the Chromium project, which Google patched in April.
Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available.
organisation
WebGPU
A use-after-free weakness in Dawn (CVE-2026-5281), the underlying cross-platform implementation of the WebGPU standard used by the Chromium project, which Google patched in April.
A use-after-free vulnerability in Dawn (CVE-2026-5281), the cross-platform implementation of the WebGPU standard used by Chromium, was
patched in April
.
organisation
WebPackaging
One high use-after-free flaw in WebPackaging (CVE-2026-87639) is credited to OpenAI Codex Security.
organisation
OpenAI Codex Security
One high use-after-free flaw in WebPackaging (CVE-2026-87639) is credited to OpenAI Codex Security.
financial
$2,500 $ bug bounty
The researcher received a $2,500 bug bounty reward for responsible disclosure.
Google rewarded the researcher with a $2,500 bounty for responsibly disclosing the vulnerability.
organisation
EU CRA
Check your EU CRA readiness in 5 questions.
organisation
Magento
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
organisation
Adobe
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
threat_actor
ShinyHunters
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
organisation
DMV
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
organisation
ShieldCrash
[Image 6: New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access](
* !
organisation
New Microsoft Defender '
[Image 6: New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access](
* !
organisation
DoppelCart
[Image 9: DoppelCart fraud network uses 119,000 fake shops to steal credit cards DoppelCart fraud network uses 119,000 fake shops to steal credit cards]
organisation
IP
[Image 31: How to change IP address.jpg) How to change IP address](
* !
organisation
safely.jpg
Access the dark web safely.jpg)
organisation
ThreatLocker
[Image 34: ThreatLocker](
* Home
* News
*
organisation
Threat Analysis Group
Google fixed eight other zero-days exploited in the wild in 2025, many of them reported by its Threat Analysis Group (TAG), known for tracking zero-day exploits used in spyware attacks.
!
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
CTI
[Image 44: CTI Starter Kit + 2026 SANS CTI Survey CTI Starter Kit + 2026 SANS CTI Survey](
* !
organisation
Upcoming Webinar
[Image 39: ThreatLocker](
Upcoming Webinar
!
organisation
Astra
[Image 42: ChatGPT ChatGPT Astra is now rolling out to $20 Plus subscription](
* !
financial
$20 $ subscription
[Image 42: ChatGPT ChatGPT Astra is now rolling out to $20 Plus subscription](
* !
organisation
Freestar.com
Image 50!Image 51!Image 52!Image 53!Image 54!Image 55!Image 56!Image 57!Image 58!Image 59!Image 60!Image 61
Freestar.com
!
organisation
CacheStorage
The update also addresses nine other high-severity vulnerabilities, including use-after-free and out-of-bounds memory flaws in Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, Skia, and a race condition in V8.
organisation
DevTools
The update also addresses nine other high-severity vulnerabilities, including use-after-free and out-of-bounds memory flaws in Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, Skia, and a race condition in V8.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Chrome)
September 2026
Microsoft released patches for 966 vulnerabilities in its software on September 2026.
Click on any entity below to view its context and source!
general_metric
2 Video
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
organisation
Microsoft
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
general_metric
966 flaws
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.
For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux.
Google has updated Chrome Stable to version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it to Google.
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout..
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
For optimal protection, users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux.
Metrics
infrastructure
Linux
Affected Product
The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.
For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux.
Google has updated Chrome Stable to version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.
The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it to Google.
Get the report
### Related Articles:
Google warns of new Chrome zero-day flaw exploited in attacks
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
N-able patches max severity N-central flaw amid ongoing attacks
SonicWall warns of actively exploited SMA1000 zero-day flaws
Sonicwall warns of new SMA1000 zero-day exploited in attacks
* Actively Exploited
* Emergency Update
* Google
* Google Chrome
* Web Browser
* Zero-Day
*
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout..
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
For optimal protection, users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux.
Metrics
infrastructure
153.0.8010
Software Version
The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.
Chrome 153.0.8010.36/.37 is up to date
You can find an explanation of the version numbering system and step-by-step instructions in our guide:
How to update Chrome on every operating system
.
"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a
description
of the flaw on the NIST National Vulnerability Database (NVD).
For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux.
Google fixed the issue in Chrome 153.0.8010.36 and later versions.
Google has updated Chrome Stable to version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.
The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it to Google.
Metrics
infrastructure
Macos
Affected Product
For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux.
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout..
For optimal protection, users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux.
Metrics
financial
2,500
$ Bug Bounty
The researcher received a $2,500 bug bounty reward for responsible disclosure.
Google rewarded the researcher with a $2,500 bounty for responsibly disclosing the vulnerability.
Metrics
infrastructure
8.8
Software Version
Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8).
Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw.
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
Metrics
infrastructure
Microsoft 365
Affected Product
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
victims
258
Organizations
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
infrastructure
2,016
Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
Metrics
data_breach
0
September
Sergiu Gatlan
* September 9, 2026
* 02:25 AM
* 0
!
Metrics
financial
20
$ Subscription
[Image 42: ChatGPT ChatGPT Astra is now rolling out to $20 Plus subscription](
* !
Metrics
infrastructure
152.0.7977
Software Version
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout..
the WebGPU component used for graphics processing.
June 2026 –
CVE-2026-11645
(CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.
"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a
description
of the flaw in CVE.org.
For optimal protection, users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux.
Metrics
financial
1,000
$ Bug Bounty
Security researcher Salvatore Gulizia, known as Serotav, reported the flaw on August 4, 2026, and received a $1,000 bug bounty.
Intelligence Sources
Security Affairs
2026-09-04
Google fixes the sixth actively exploited Chrome zero-day of 2026
Security Affairs
The Hacker News
2026-09-04
BleepingComputer
2026-09-04
Google warns of new Chrome zero-day flaw exploited in attacks
BleepingComputer
BleepingComputer
2026-09-09
Google warns of new Chrome zero-day bug exploited in attacks
BleepingComputer
The Hacker News
2026-09-09
Security Affairs
2026-09-09
Google fixes the seventh actively exploited Chrome zero-day of 2026
Security Affairs
Malware Bytes
2026-09-10
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-11T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
59x
organisation
Identified Entity
Malwarebytes Browser Guard
entity
18x
timeline
Temporal Reference
Sep 09, 2026
date
13x
vulnerability
Exploited CVE
CVE-2026-87491
cve
7x
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
6x
general metric
Video
1
video
4x
tactic
Cyber Operation Type
Phishing
tactic
4x
infrastructure
Affected Product
Windows
software
3x
infrastructure
Software Version
153.0.8010
version
2x
financial
$ Bug Bounty
2,500
$ bug bounty
2x
general metric
Windows
11
windows
Contextual Telemetry
Context Block
21 METRICS
general metric
Security Fixes
230
security fixes
general metric
Cve-2026
87,491
cve-2026
general metric
Google
195
google
general metric
Sep
9
sep
vulnerability
CVSS Score
9
score
general metric
Score
9
score
target region
Target Country
United States
country
industry
Targeted Sector
Technology
sector
general metric
Microsoft
365
microsoft
victims
Organizations
258
organizations
infrastructure
Windows Server
2,016
windows server
general metric
Flaws
966
flaws
threat actor
APT Group
ShinyHunters
actor
general metric
Fake Shops
119,000
fake shops
data breach
September
0
september
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
financial
$ Subscription
20
$ subscription
general metric
Freestar.Com
61
freestar.com
general metric
%
37
%
general metric
Chrome Flaws
12
chrome flaws
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.