Chrome users face a seventh exploited zero-day this year
This is a Daily Cyber dot News update, brought to you by Bare Metal Cyber dot com, for Thursday, September 10th, 2026.
Chrome users are exposed to an actively exploited browser weakness until the latest update is installed. Google’s Chrome 153 release includes 230 security fixes, including a repair for an out-of-bounds write in the V8 engine. A crafted HTML page could use the issue to execute code inside the browser sandbox. The fixed versions are 153.0.8010.36 for Linux and Windows and 153.0.8010.37 for Mac. CISA has also added the issue to its exploited-vulnerability catalog.
Browsers handle untrusted internet content throughout the workday, which makes delayed updates a broad endpoint risk. Google hasn’t disclosed details about the observed attacks while the update is still rolling out. Leaders should verify that browser updates are centrally enforced instead of assuming automatic updates have completed. Defenders should measure installed versions, require managed browsers to restart, and investigate unusual browser activity. This is the seventh actively exploited Chrome zero-day patched in 2026. Force the update and restart now, then verify the fixed version through endpoint inventory.
For the sources and the full Daily Cyber newsletter, visit Daily Cyber dot news.