Tendvane

← All articles

SecuritySeptember 9, 2026

Chrome's new fortnightly schedule opened with an emergency

Yesterday we wrote that Chrome had switched to a two-week release cycle, and that the gap between a fix being written and a fix reaching your laptop is effectively a security setting. Chrome 153, the first release on that new clock, makes the point better than we did. It shipped with 230 security fixes, and one of them was already being exploited.

CVE-2026-87491 is an out-of-bounds write in V8, the engine that runs the JavaScript on every page you open. Google's wording is the usual careful formula: it "is aware that an exploit for CVE-2026-87491 exists in the wild". The bug is rated Medium, which sounds reassuring and mostly reflects that it lands inside Chrome's sandbox rather than straight onto your PC. Real attacks chain their way out of sandboxes, so treat it as urgent regardless. Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it on 6 August and collected a $2,500 bounty.

The running total is the part that should get your attention. Seven Chrome flaws have been exploited before a fix existed in 2026, and this is the second in five days: CVE-2026-85046, another V8 bug, went onto CISA's known-exploited list on 4 September. Edge, Brave, Opera and Vivaldi are built on the same code and get the same fix on their own schedules, so this is not a reason to switch browsers.

The version you want is 153.0.8010.36 on Windows and .37 on Mac. Chrome fetches it quietly and then waits for a restart, which is the step people skip; a window left open since last week is running last week's code. Menu, then Help, then About Google Chrome shows your number and forces the check. Tendvane's app-update tool reads your installed programs through winget, Windows' own package manager, and lists what is behind, which is a useful backstop for the browser you never close.

Sources

Download Tendvane