CTIPilot
← Back to the live brief
HIGHCVE-2026-87491exploitedNATOA2vulnerability

CVE-2026-87491, Google Chrome: V8 out-of-bounds write exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026)

Google ships an emergency Chrome fix for a seventh actively exploited V8 zero-day this year

Defender actions

  • Update Chrome, Edge and every other Chromium-based browser in the fleet to ≥153.0.8010.36 now; this is the seventh actively-exploited Chrome zero-day patched in 2026, and Google has disclosed no interim mitigation short of the update.

Analysis

Google's Chrome 153 stable release (2026-09-08, versions 153.0.8010.36/.37 Windows/Mac, 153.0.8010.36 Linux) fixes 230 security bugs, including CVE-2026-87491, an out-of-bounds write in V8 that Google confirms is being exploited: "Google is aware that an exploit for CVE-2026-87491 exists in the wild" (Google, via Help Net Security, 2026-09-09). NVD describes the mechanism as allowing "a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page" (NVD, via The Hacker News, 2026-09-09), user interaction (visiting or being served the page) is required, but no authentication or special access. ENISA's EUVD records a CVSS 3.1 base score of 8.8 (ENISA EUVD, 2026-09-09); Google has disclosed no detail on the exploitation vector, victims, or actor, consistent with its practice of withholding detail until most users have updated. CERT-FR and NCSC-NL both independently issued advisories within a day of release ("Google reports that the vulnerability tracked as CVE-2026-87491 is being actively exploited," translated from Dutch, NCSC-NL, advisory NCSC-2026-0354, 2026-09-09), and CISA added the CVE to KEV the same day (CISA, 2026-09-09), with a due date of 2026-09-23 (CISA KEV catalog, 2026-09-09). This is the seventh Chrome zero-day Google has confirmed under active exploitation in 2026; every Chromium-derived browser (Edge, Brave, Opera, Vivaldi) inherits the same V8 engine and needs the equivalent update.

Cited evidence

Google is aware that an exploit for CVE-2026-87491 exists in the wild.

Google (via Help Net Security)

Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

NVD (via The Hacker News)

Google reports that the vulnerability tracked as CVE-2026-87491 is being actively exploited.

NCSC-NL (advisory NCSC-2026-0354)

Sources8

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.