Cyber Resilience
← All news
Confirmed

Google security advisory (AV26-904)

Our takeCISA reports active exploitation of CVE-2026-87491 in Chrome versions prior to 153.0.8010.37. Update now — same advice whatever size org you run.
Sources (1)
What this means for you — Security leader:Google's AV26-904 advisory and CISA KEV listing confirm active exploitation of CVE-2026-87491 in Chrome prior to 153.0.8010.37. Update all Chrome browsers immediately and enable auto-updates.
What this means for you — Lean IT orgs:If you or your team use Chrome, update it now to version 153.0.8010.37 or later. This is a known exploited vulnerability and takes just a few clicks.
What this means for you — MSP:Confirm all client endpoints and servers running Chrome are updated past 153.0.8010.37. Prioritize any that cannot use auto-update and verify via fleet inventory.
What this means for you — Researcher:Google AV26-904 and CISA KEV addition confirm in-the-wild exploitation of CVE-2026-87491 in Chrome < 153.0.8010.37.