Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Chrome zero-day most likely behind this report is CVE-2026-87491, an actively exploited out-of-bounds write in Chrome’s V8 engine. Google fixed it in Chrome 153 in September 2026. The attacker and the scope of observed targeting have not been publicly identified in the sources describing the incident. If Chrome is still on an older version, update it to the latest version available for your device.

Is there another Chrome zero-day?

Google’s September 8, 2026 stable release identified CVE-2026-87491 as an out-of-bounds write in V8, Chrome’s JavaScript and WebAssembly engine. Google credited Jihyeon Jeong of Seoul National University’s Compsec Lab with reporting the flaw on August 6. The Chrome 153 release listed 230 security fixes; that is the release’s total, not a count of zero-days or attacks. Google Chrome Releases, September 8, 2026.

The identification is the best-supported match for the headline, but the headline itself does not specify a date or CVE. Chrome had other reported zero-days during 2026, so CVE-2026-87491 should not be confused with separate incidents.

Is the Chrome flaw being exploited?

Yes. A September 15 Cloud Security Alliance note says Google patched the flaw on September 9 after confirming an exploit existed in the wild. It describes a crafted HTML page as the route to remote code execution within Chrome’s sandbox. That describes code execution in the browser’s security boundary; it does not establish automatic compromise of the entire operating system. Cloud Security Alliance, September 15, 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Which Chrome version fixes the zero-day?

The fix was included in Chrome 153.0.8010.36 for Linux and Chrome 153.0.8010.36 or .37 for Windows and Mac. Google said the release would roll out over the coming days or weeks, so availability could vary by device and rollout timing. Google Chrome Releases, September 8, 2026.

Google’s October 1 stable release was Chrome 154.0.8037.97 or .98 for Windows and Mac, and 154.0.8037.97 for Linux. It listed 11 security fixes and did not identify an actively exploited zero-day among those listed. This is newer version context, not the original CVE-2026-87491 fix release. Google also described this release as rolling out over the coming days or weeks. Google Chrome Releases, October 1, 2026.

Rank #2
Cryptnox FIDO2 Security Key with MIFARE DESFire NFC Smart Card for 2FA MFA
  • HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
  • BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
  • CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
  • DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
  • SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty

Separately, CERT-In’s October 1 advisory covers multiple Chrome desktop vulnerabilities and identifies versions before 154.0.8037.92/.93 on Windows and Mac, and before 154.0.8037.92 on Linux, as affected. Those thresholds belong to that broader advisory; they are not the original fix-version numbers for CVE-2026-87491. CERT-In advisory, October 1, 2026.

How to update Chrome

  1. Open Chrome and select the three-dot menu in the upper-right corner.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    Rank #3
    Cryptnox FIDO2 Security Key NFC Smart Card for 2FA MFA Passwordless Login
    • FIDO2 CERTIFIED: FIDO Alliance Certified FIDO2 v2.1 and CTAP Level 1 for 2FA and MFA on Google Microsoft Apple GitHub login.gov AGOV SwissID and any WebAuthn service
    • PASSKEY READY: Works as a hardware passkey for passwordless sign-in where the service enables it and as a U2F and WebAuthn security key everywhere else
    • CERTIFIED SECURITY: NXP JCOP 4.5 secure element rated Common Criteria EAL6+ (augmented)
    • TAP OR INSERT: Dual NFC ISO 14443 and contact ISO 7816 interface in an ID-1 format smart card that is passive and battery-free
    • BUILT TO LAST: Passive smart card made in Switzerland designed by Swiss company Cryptnox and backed by a 2 year manufacturer warranty
  2. Choose Help > About Google Chrome. Chrome checks for an update on this page.

  3. If an update is available, allow it to download, then select Relaunch when prompted. Save any work in open tabs first.

    Rank #4
    Kensington FIDO U2F and FID02 USB-A Security Key and Fingerprint Reader - Windows, macOs, Chrome
    • FIDO2 and FIDO U2F certified USB-A security key and fingerprint reader provides password-less and biometric single-factor, two factor, and multi-factor authentication; compatible with Windows, macOS, and Chrome. Windows ARM-based computers are currently not supported. Please check back for future updates on compatibility
    • Fingerprint reader exceeds industry standards for false rejection rate and false acceptance rate; supports up to 10 fingerprints
    • TAA-compliant for use in U.S. Federal Government institutions and organizations
    • Compact design features protective cover and tether; can be used in a docking station or usb hub
    • Two year coverage and lifetime Kensington technical support included
  4. Return to About Google Chrome after relaunch and confirm the browser reports that it is up to date. If the update is not offered yet, check again later; stable releases can roll out gradually.

Keep Chrome’s automatic updates enabled where your device or organization permits it. Singapore’s Cyber Security Agency recommends prompt updating and automatic updates as general guidance for a different Chrome zero-day, rather than as incident-specific instructions for CVE-2026-87491. Cyber Security Agency of Singapore, April 2, 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
KEY-BAK Quick Release Side Slide Key Chain, Chrome Cylinder
  • Made in the USA with globally sourced materials and lasts up to 10x longer
  • High quality import designed by the company that invented the original key security device
  • Chrome plated brass pull apart key holder allows keys to be separated
  • Cylinder quick release measures 3 inches (7.6 cm) long from split ring to split ring
  • Nickel plated tempered steel .875 inch (2.2 cm) split-ring returns to original shape after expansion; Sport Type: Hunting
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who is behind the Chrome attack?

The public information cited here does not name an attacker or establish who was targeted. The Cloud Security Alliance note says Google had not disclosed the scope of observed targeting. There is not enough evidence here to attribute the attack to a particular group, motive, victim set, or delivery campaign.

Quick Recap

Bestseller No. 3
Cryptnox FIDO2 Security Key NFC Smart Card for 2FA MFA Passwordless Login
Cryptnox FIDO2 Security Key NFC Smart Card for 2FA MFA Passwordless Login
CERTIFIED SECURITY: NXP JCOP 4.5 secure element rated Common Criteria EAL6+ (augmented)
$30.99
Bestseller No. 4
Kensington FIDO U2F and FID02 USB-A Security Key and Fingerprint Reader - Windows, macOs, Chrome
Kensington FIDO U2F and FID02 USB-A Security Key and Fingerprint Reader - Windows, macOs, Chrome
TAA-compliant for use in U.S. Federal Government institutions and organizations; Two year coverage and lifetime Kensington technical support included
$56.99
Bestseller No. 5
KEY-BAK Quick Release Side Slide Key Chain, Chrome Cylinder
KEY-BAK Quick Release Side Slide Key Chain, Chrome Cylinder
Made in the USA with globally sourced materials and lasts up to 10x longer; High quality import designed by the company that invented the original key security device
$11.36

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.