On September 8, 2026, Google shipped an emergency Chrome update to patch CVE-2026-87491, a vulnerability that attackers were already exploiting in the wild. It is the seventh actively exploited Chrome zero-day Google has had to patch this year, more than in any prior year on record, and it lands just four days after the sixth one. If you browse, bank, or run a business from a laptop or Android phone, here is what actually happened and what to do about it.
What Google patched, in plain terms
CVE-2026-87491 is an out-of-bounds write bug in V8, the engine that runs JavaScript inside Chrome. In practice, that means a specially crafted web page, one you could be sent as an ordinary-looking link, could corrupt Chrome's memory and let an attacker run code inside the browser sandbox. Google has not disclosed who is behind the attacks or who has been targeted, which is standard practice while the update rolls out. The fix shipped in Chrome 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux. The researcher who reported it, Jihyeon Jeong of Seoul National University's Compsec Lab, earned a $2,500 bug bounty for the find on August 6, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog, with a September 23, 2026 patch deadline for U.S. federal agencies. That deadline does not apply to ordinary users, but CISA only adds a vulnerability to that list when it has confirmed real-world exploitation, so it is a useful signal of how seriously to take it.
Why this matters for Kenyan browsers, not just IT departments
Chrome is the default browser on the vast majority of Android phones sold in Kenya, and it is the browser most people use for M-Pesa's web portal, KRA iTax, mobile banking, and everyday WhatsApp Web sessions. A V8 exploit like this one does not need you to download anything. It only needs you to open a page, which is exactly why browser zero-days are attractive to attackers running phishing links over SMS or WhatsApp. Keeping Chrome current is one of the few security habits that meaningfully lowers that risk, and it costs nothing.
How to check you are updated
On a laptop or desktop, open Chrome, click the three-dot menu, go to Help, then About Google Chrome. Chrome checks for updates automatically when you open that page and will prompt you to relaunch once the update is downloaded. You want to see version 153.0.8010.36 or later. On Android, open the Play Store, tap your profile icon, go to Manage apps and device, and update Chrome from there if an update is pending. If you use Microsoft Edge, Brave, Opera, or Vivaldi, the same V8 flaw affects those browsers too since they are all built on Chromium, so check their update pages as well.
When the real problem is the laptop, not the browser
Updating Chrome takes two minutes and fixes this specific flaw. But if your laptop is running an operating system that is several years past its own support window, or its storage is too full to download updates, or it is simply old enough that every security patch makes it noticeably slower, the browser update is a band-aid on a bigger issue. Seven actively exploited zero-days in nine months is a reasonable point to ask whether your current machine can keep pace. A current-generation business laptop with a modern chipset, a fingerprint reader, and a TPM security chip, the hardware component that stores encryption keys separately from the OS, makes it meaningfully harder for an attacker to do anything useful even if a browser exploit does get through.
FAQ
Do I need to pay for the Chrome update?
No. Chrome updates itself for free. You only need to relaunch the browser once it has downloaded the new version, which happens automatically in the background.
Is my Android phone's Chrome app affected too?
Yes. This flaw is in Chrome's core engine, which runs the same way on Android as on Windows or Mac. Update the Chrome app from the Play Store to be safe.
Do I actually need a new laptop over this one issue?
Not because of this specific patch alone. But if your laptop struggles to install routine updates, is out of official OS support, or is more than four to five years old, it is worth treating this as a prompt to plan for a replacement rather than waiting for a bigger problem.
trewrld | Queensway House, Kaunda Street, 2nd Floor Room 13, Nairobi | 0722 700 018 | @trewrldke
M-Pesa, Visa/Mastercard & Bank Transfer accepted | Same-day delivery in Nairobi, 1 to 4 days countrywide, and delivery across East Africa (Uganda, Tanzania, Rwanda, Burundi, South Sudan)




