CTIPilot

Google Chrome V8 out-of-bounds write, exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026)

cve · CVE-2026-87491

Coverage timeline
1
first 2026-09-10 → last 2026-09-10
Peak priority
high
1 high
Sources cited
8
7 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1189Drive-by Compromise×1

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Evidence: 2026-09-10/cve-2026-87491-chrome-v8-oob-write-seventh-2026-zero-day · ATT&CK page ↗

Execution TA0002

T1203Exploitation for Client Execution×1

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Evidence: 2026-09-10/cve-2026-87491-chrome-v8-oob-write-seventh-2026-zero-day · ATT&CK page ↗

Story timeline

  1. 2026-09-10CVE-2026-87491, Google Chrome: V8 out-of-bounds write exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026)
    trending-vulnerabilitiesGoogle ships an emergency Chrome fix for a seventh actively exploited V8 zero-day this year

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cisa.gov2 (25%)
  • advisories.ncsc.nl1 (12%)
  • cert.ssi.gouv.fr1 (12%)
  • chromereleases.googleblog.com1 (12%)
  • euvdservices.enisa.europa.eu1 (12%)
  • helpnetsecurity.com1 (12%)
  • thehackernews.com1 (12%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Google Chrome V8 out-of-bounds write, exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026) (1)

2026-09-10 · view entry permalink →

HIGHCVE-2026-87491exploitedNATOA2

CVE-2026-87491, Google Chrome: V8 out-of-bounds write exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026)

Google's Chrome 153 stable release (2026-09-08, versions 153.0.8010.36/.37 Windows/Mac, 153.0.8010.36 Linux) fixes 230 security bugs, including CVE-2026-87491, an out-of-bounds write in V8 that Google confirms is being exploited: "Google is aware that an exploit for CVE-2026-87491 exists in the wild" (Google, via Help Net Security, 2026-09-09). NVD describes the mechanism as allowing "a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page" (NVD, via The Hacker News, 2026-09-09), user interaction (visiting or being served the page) is required, but no authentication or special access. ENISA's EUVD records a CVSS 3.1 base score of 8.8 (ENISA EUVD, 2026-09-09); Google has disclosed no detail on the exploitation vector, victims, or actor, consistent with its practice of withholding detail until most users have updated. CERT-FR and NCSC-NL both independently issued advisories within a day of release ("Google reports that the vulnerability tracked as CVE-2026-87491 is being actively exploited," translated from Dutch, NCSC-NL, advisory NCSC-2026-0354, 2026-09-09), and CISA added the CVE to KEV the same day (CISA, 2026-09-09), with a due date of 2026-09-23 (CISA KEV catalog, 2026-09-09). This is the seventh Chrome zero-day Google has confirmed under active exploitation in 2026; every Chromium-derived browser (Edge, Brave, Opera, Vivaldi) inherits the same V8 engine and needs the equivalent update.

Google is aware that an exploit for CVE-2026-87491 exists in the wild.

Google (via Help Net Security)

Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

NVD (via The Hacker News)

Google reports that the vulnerability tracked as CVE-2026-87491 is being actively exploited.

NCSC-NL (advisory NCSC-2026-0354)
vulnerability10 Sep 04:35Zmulti-sourceOpen finding ↗