Google shipped Chrome 153 on September 8, 2026, patching a V8 engine flaw that attackers were already using in the wild. It’s the seventh actively exploited Chrome zero-day of the year, and the second one in under a week. If you’re checking world news feedworldtech for browser security updates today, this is the one to act on.
The bug, tracked as CVE-2026-87491, is an out-of-bounds write in V8 — the engine that handles JavaScript and WebAssembly inside every Chrome tab. A crafted HTML page can trigger it and run code inside the browser’s sandbox. Jihyeon Jeong of Compsec Lab at Seoul National University reported it on August 6. Google turned around a fix in two days, landing it in version 153.0.8010.36 for Linux, and .36/.37 for Windows and Mac. The same update closes 230 other issues, five of them critical. The Hacker News broke down the technical details the day the patch landed, and it’s worth a read if you want the full vulnerability writeup.
What World News Feedworldtech Is Actually Reporting
Google’s advisory doesn’t say who’s exploiting the flaw or against whom. That’s standard practice, honestly — the company usually stays quiet on attribution while the patch propagates, so copycats don’t get a head start reverse-engineering it. Users following world news feedworldtech on this story shouldn’t expect more detail soon. What’s known is narrower and more useful: update, and do it now. If you want a broader rundown of basic patch hygiene before diving into anything else, this rundown of everyday security habits covers the fundamentals. SecurityWeek’s own count of the update — 230 fixes in a single release — gives a sense of just how much ships in a routine Chrome cycle now.
Why V8 Keeps Getting Hit

Four of the seven exploited zero-days patched in Chrome this year live inside V8. February brought a CSS use-after-free bug. March had two — one in the Skia graphics library, one in V8. April hit the Dawn WebGPU component. June was V8 again. Then September delivered two in a single week: CVE-2026-85046 on the 3rd, and this one five days later. Every single one carried, or would have carried, a CVSS score around 8.8. This is a pattern world news feedworldtech readers have seen build all year, not a one-off.
That’s not random. V8 is where Chrome executes untrusted code pulled straight from the open web, and Chrome still runs on something like two out of every three browsers globally. A working exploit chain there reaches almost anyone who clicks a link. Commercial exploit brokers and state-linked groups both know this, and they keep finding new corners of the engine to break.
What This Means If You Manage IT or You’re Studying It

For working admins, this is another entry in the “patch immediately” pile — and the pile keeps growing, which is exactly the kind of thing world news feedworldtech exists to flag before it turns into an incident report. Seven browser zero-days by early September puts 2026 on pace with, or ahead of, recent years. If your org still pushes browser updates on a monthly cycle instead of letting Chrome auto-update, that gap is exactly where attackers live.
Students eyeing a career in this field should pay attention too: incident response and vulnerability management are the fastest-growing lanes in security work right now, and this kind of rapid-turnaround patching is the daily reality of the job, not an edge case. Anyone weighing an entry point into that career track could do worse than studying exactly how this disclosure-to-patch timeline played out.
And for smaller teams without dedicated security staff, incidents like this are usually the argument for handing patch management to someone else entirely — which is a big part of why outsourced security coverage keeps growing as a line item, even at companies that never thought they’d need it.
What Happens Next
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-87491 to its Known Exploited Vulnerabilities catalog on September 9, giving federal civilian agencies until September 23 to apply the fix. That’s a hard deadline for government systems, but it’s a decent benchmark for everyone else too. CISA doesn’t add things to that list casually.
Coverage circulating under world news feedworldtech tags this week has mostly focused on the pace, not the payload — seven confirmed zero-days with roughly four months left in the year. If that rate holds, 2026 could end above where 2025 landed. Nobody’s publicly speculating on an eighth yet. Give it time.
Do I need to do anything besides update Chrome?
No — updating to 153.0.8010.36 (or .37 on Windows/Mac) closes this specific hole. Just don’t delay it.
Is this the worst Chrome flaw this year, according to world news feedworldtech coverage?
Severity-wise, no — it’s rated medium, lower than several of the 8.8-scored bugs earlier in 2026. It’s notable mainly for how fast it was weaponized.
Should students worry this reflects badly on Chrome specifically?
Not really. Every major browser engine has this problem; Chrome’s just the biggest target because it has the most users.
Final Thoughts
Seven exploited zero-days in nine months isn’t a crisis on its own, but it’s a pattern worth watching if you work anywhere near browser security. Update Chrome today, check your org’s patch cadence, and don’t assume the eighth one won’t show up before winter.

An IT career coach with 7 years of experience helping beginners map out certification paths that actually lead to interviews, not just another resume line. He’s guided dozens of career-switchers through their first AWS or CompTIA exam and writes for itechnova.io, covering IT certifications, cybersecurity, and the software tools people actually need to know.