2026-09-10 · view entry permalink →
CVE-2026-87491, Google Chrome: V8 out-of-bounds write exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026)
Google's Chrome 153 stable release (2026-09-08, versions 153.0.8010.36/.37 Windows/Mac, 153.0.8010.36 Linux) fixes 230 security bugs, including CVE-2026-87491, an out-of-bounds write in V8 that Google confirms is being exploited: "Google is aware that an exploit for CVE-2026-87491 exists in the wild" (Google, via Help Net Security, 2026-09-09). NVD describes the mechanism as allowing "a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page" (NVD, via The Hacker News, 2026-09-09), user interaction (visiting or being served the page) is required, but no authentication or special access. ENISA's EUVD records a CVSS 3.1 base score of 8.8 (ENISA EUVD, 2026-09-09); Google has disclosed no detail on the exploitation vector, victims, or actor, consistent with its practice of withholding detail until most users have updated. CERT-FR and NCSC-NL both independently issued advisories within a day of release ("Google reports that the vulnerability tracked as CVE-2026-87491 is being actively exploited," translated from Dutch, NCSC-NL, advisory NCSC-2026-0354, 2026-09-09), and CISA added the CVE to KEV the same day (CISA, 2026-09-09), with a due date of 2026-09-23 (CISA KEV catalog, 2026-09-09). This is the seventh Chrome zero-day Google has confirmed under active exploitation in 2026; every Chromium-derived browser (Edge, Brave, Opera, Vivaldi) inherits the same V8 engine and needs the equivalent update.
Google is aware that an exploit for CVE-2026-87491 exists in the wild.
Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
Google reports that the vulnerability tracked as CVE-2026-87491 is being actively exploited.