Published Wednesday, September 09, 2026 at 11:29 AM PT

<strong>CHROME 153: SEVENTH ZERO-DAY OF 2026 ACTIVELY EXPLOITED β€” IMMEDIATE PATCH REQUIRED</strong>

Google Chrome 153, released to stable channel Tuesday, patches 230 security vulnerabilities including an actively exploited zero-day β€” the seventh confirmed zero-day breach of 2026. All Chrome users must update immediately. Specific CVE, attack vector, and affected component unconfirmed in available reporting.

DETAILS β€’ Chrome 153 shipped Tuesday with 230 total security fixes; at least one is an actively exploited zero-day vulnerability. β€’ This marks the 7th zero-day of 2026, continuing a pattern of escalating in-the-wild exploitation: Chrome 152 patched the 6th zero-day; CVE-2026-85046 and CVE-2026-11645 (both in earlier Chrome versions) confirmed active exploitation. β€’ Chrome version number for the zero-day, specific CVE identifier, and technical details (attack vector, component, CVSS score) not yet disclosed in available advisories. β€’ Active exploitation timeline, affected systems, and campaign attribution not specified.

IMPACT All Chrome users on version 152 or earlier are potentially at risk. The scope of active exploitation is unconfirmed but presumed broad β€” no constraint to specific versions, regions, or user types has been identified. Given the pattern of weaponization of prior zero-days this year (85046, 11645), in-the-wild attacks on 153’s vulnerability are likely concurrent with or imminent after patch release.

RECOMMENDED ACTIONS

  1. Immediate: All users update Chrome to 153+. Auto-update users should verify completion at chrome://version; manually managed deployments must push 153 to all endpoints today.
  2. Enterprise/SOC: Deploy via Chrome Enterprise policy or MDM immediately. Treat as critical-severity patching, not routine.
  3. Threat intel: Cross-reference threat feeds for exploitation indicators; correlate Chrome crash reports and unusual process behavior post-update.
  4. Escalation: This is the 7th zero-day of 2026 β€” brief leadership. Attack volume and campaign details to follow as advisories mature.

UNCERTAINTY FLAGS Specific CVE, attack vector, affected component, and timeline of active exploitation remain unconfirmed in public reporting as of alert generation. Full technical details expected in Google’s official Chrome Release Notes; advisory will firm up impact scope.

SOURCES

  • news4hackers, securityweek, securityaffairs: Chrome 153 patching 7th zero-day of 2026
  • Historical: Chrome 152 (6th zero-day), CVE-2026-85046, CVE-2026-11645 (both confirmed active exploitation)

Recent high-severity events at publish time:

Recent high-severity events