Google released Chrome 153 to the Stable channel, fixing 42 security vulnerabilities, including three Critical memory-safety flaws: use-after-free vulnerabilities in Internals (CVE-2026-91721) and Workers (CVE-2026-91749), plus an out-of-bounds read in WebGL (CVE-2026-91726). The update also addresses 27 High-severity issues affecting components including V8, ServiceWorker, Core, Extensions, Skia, ANGLE, PDF, WebPackaging, and Input. High-severity use-after-free bugs include CVE-2026-87639 in WebPackaging, reported by amyb of OpenAI Codex Security, and CVE-2026-87542 in Input, reported by BigSleep@Grape.
Google has not reported active exploitation of any of the fixed vulnerabilities and withheld technical exploit details. Organizations should deploy Chrome 153.0.8010.47/.48 on Windows and macOS or 153.0.8010.47 on Linux, confirm managed endpoints have completed the update and restarted the browser, and investigate devices delayed by update policies or incomplete rollout.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
On September 18, 2026, the Canadian Cyber Centre issued advisory AV26-939, warning that Google was affected by unspecified vulnerabilities and referring users to Google's Stable Channel Update for Desktop. It recommended that users and administrators review the update information and apply necessary updates when available.
Google's September 17, 2026 stable-channel update remediated multiple vulnerabilities in Chrome versions earlier than 153.0.8010.52, including critical WebGL buffer-overflow CVE-2026-93372 and critical Dawn use-after-free CVE-2026-93374. The update also fixed high-severity PDFium and Extensions use-after-free flaws; no known public exploits were reported.
The Canadian Cyber Centre issued advisory AV26-926 stating that Google Chrome versions prior to 153.0.8010.48 are affected by unspecified vulnerabilities. It advised users and administrators to consult Google's Stable Channel Update information and apply available updates.
Google's September 15, 2026 Chrome stable-channel advisory identified CVE-2026-91724, a high-severity Input use-after-free, and CVE-2026-91728, a high-severity V8 integer overflow. Affected macOS installations should upgrade to Chrome 153.0.8010.47 or later; the Nessus advisory reported no known exploits.
Chrome 153 addressed CVE-2026-87542, a High-severity use-after-free vulnerability in Chrome's Input component. Google credited BigSleep@Grape with reporting the vulnerability.
Chrome 153 addressed CVE-2026-87639, a High-severity use-after-free vulnerability in the WebPackaging component. Google credited researcher “amyb,” working with OpenAI Codex Security, for reporting the issue.
On September 8, 2026, Google released Chrome 153 to the Stable channel. The update addressed 42 reported vulnerabilities, including three Critical flaws—CVE-2026-91721, CVE-2026-91749, and CVE-2026-91726—and 27 High-severity issues; the advisory did not report active exploitation of the fixed flaws.
Mozilla released Firefox 156 to remediate 73 vulnerabilities, including 29 rated high severity. The company also shipped corresponding fixes for Thunderbird 156 and 140.16 and Firefox ESR 153.3, 140.16, and 115.41; Mozilla reported no evidence of in-the-wild exploitation.
Google published a September 17, 2026 security advisory for vulnerabilities affecting Chrome versions earlier than 153.0.8010.53 and recommended updating to the current release. The notice did not identify CVEs, severity ratings, vulnerability types, or active exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
21 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourceacn.gov.it
Open sourcebugflation.com
Open sourcebugflation.com
Open sourcecirt.gy
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.