Google released Chrome 153 to the stable channel on September 8, 2026. The desktop builds are 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac. The release includes multiple security fixes, including memory-safety vulnerabilities. One of the vulnerabilities, CVE-2026-87491, is reported as an out-of-bounds write in V8 and has been listed as actively exploited.
Chrome 153 also marks the start of Google's new two-week major release schedule, reducing the time between major stable releases from four weeks to two. For security teams, the important question is not only how quickly Google releases a fix, but how quickly organizations can get that fix onto their endpoints.
1. What Changed With the Two-Week Release Schedule?
Google announced earlier this year that Chrome would move to a two-week major release cycle, beginning with Chrome 153. Previously, Chrome followed a four-week major release cycle. Under the new schedule, stable releases arrive more frequently, giving Google the ability to deliver security and feature updates to users sooner. However, faster releases also mean security teams need to review and deploy updates more frequently. The challenge is especially important for organizations with:
- Strict change-control processes
- Large numbers of managed endpoints
- Extended Stable deployments
- Delayed browser restarts
- Limited visibility into browser versions
A faster vendor release cycle can improve security, but only if the organization can keep pace with it.
2. Security Details May Follow the Code Release
Chrome's release process also highlights an important challenge for defenders. The Chrome 153 advisory includes a list of code changes between Chrome 152 and Chrome 153. Security details for individual vulnerabilities may not all be available at the same time as the code changes. This creates a short period where security researchers and attackers may be able to study the changes before organizations have complete information about the vulnerabilities.
Patch analysis is a well-established technique in vulnerability research. Security teams should therefore treat the period between a security fix becoming available and that fix being deployed across endpoints as an important part of their exposure window.
The goal is not to suggest that Google is failing to protect users. Rather, it highlights a practical challenge created by faster software release cycles: defenders need equally fast visibility and response.
3. The Bigger Problem: "When the Fix Exists but the Browser Is Still Old"
Once Google releases a security update, the next step depends largely on the organization's environment. Chrome can download updates automatically, but users may still need to restart the browser before the new version becomes active.
If a browser remains open for several days, an endpoint can continue running an older version even though a patched version is already available. This becomes more important when the vulnerability is being actively exploited.
For example, CISA added CVE-2026-85046, a V8 type-confusion vulnerability fixed in Chrome 152, to its Known Exploited Vulnerabilities catalog on September 4, 2026. For organizations, this is a reminder that available patches are not deployed patches.
4. How Security Teams Can Check Their Browser Exposure
Almost every modern organization relies heavily on web browsers, which makes browser security an important part of endpoint security. Security teams should be able to answer basic questions such as:
- Which Chrome versions are currently installed?
- How many endpoints are running outdated versions?
- How long does it take for a new Chrome release to reach endpoints?
- Do browser restart being enforced where necessary?
- Are vulnerable versions still present on high-value systems?
- Can endpoint security tools detect suspicious processes following browser activity?
A vulnerability assessment or penetration testing engagement can also help to identify outdated browser versions and weaknesses in update policies. Continuous monitoring can be helpful for security teams to detect suspicious activity.

The Real Security Question
For security teams, the important metric is not simply: "Has Google released the patch?" It is: "How quickly did our organization deploy it?" That gap between patch availability and patch deployment is where avoidable exposure can remain.
If you want to understand how effectively your organization detects and manages vulnerabilities across endpoints, applications, and infrastructure, reach out to us and book a FREE security assessment.