< Back to all clusters
[TECHNOLOGY] · United States, South Korea, Germany · 11 sources

started · updated

Google issues critical security updates for Chrome and Android

Google has released major security updates for Chrome and Android to address hundreds of vulnerabilities. The Chrome update, version 153, patches 230 flaws, including a zero-day vulnerability (CVE-2026-87491) in the V8 JavaScript engine that is being actively exploited in the wild. This V8 flaw is an out-of-bounds write that could allow remote attackers to execute arbitrary code within the browser sandbox.

Additionally, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity V8 vulnerability (CVE-2026-85046) to its Known Exploited Vulnerabilities catalog. This follows a pattern of recent zero-day threats targeting Chromium-based browsers.

For mobile users, Google's September security patch for Android addresses approximately 180 to 200 vulnerabilities. Among these, 32 are classified as critical, with eight allowing for remote code execution (RCE). Some of these flaws are particularly dangerous because they can be exploited without any user interaction. The updates affect Android versions 14 through 17. While Google and Samsung have begun rolling out patches to Pixel and Galaxy devices, other manufacturers like Motorola, Xiaomi, and Oppo may take longer to distribute the updates.

Entities

Android · CISA · Chrome · Google · Jihyeon Jeong · Seoul National University · V8