CVE-2026-87491

Published Sep 9, 2026

Last updated 6 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-87491 is an out-of-bounds write vulnerability found in V8, Google Chrome's JavaScript and WebAssembly engine. This flaw allows a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. The vulnerability was reported by Jihyeon Jeong of the Compsec Lab at Seoul National University on August 6, 2026. Google has confirmed that an exploit for CVE-2026-87491 exists in the wild, making it an actively exploited zero-day vulnerability. The issue has been addressed in Chrome version 153.0.8010.36 for Windows, macOS, and Linux, and is the seventh actively exploited Chrome zero-day patched by Google in 2026.

Description
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Source
chrome-cve-admin@google.com
NVD status
Modified
Products
chrome

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Google Chromium V8 Out of Bounds Write Vulnerability
Exploit added on
Sep 9, 2026
Exploit action due
Sep 23, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

chrome-cve-admin@google.com
CWE-787

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

10

  1. CVE-2026-87491 (CVSS 8.8): actively exploited out-of-bounds write in Chrome's V8 engine. Added to CISA's KEV catalog — the 7th actively exploited Chrome zero-day patched this year. Affected: Chrome versions prior to 153.0.8010.36 Update now. Details: https://t.co/QdBfkEiGdZ

    @vuln_tracker

    10 Sept 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Chinese 🇨🇳 APT31/TA412 first exploited BlueMoon zero-day chain CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 on Aug. 28, dropping a fake Google Gemini browser extension to steal credentials. Patch Chrome now and hunt for unsigned extensions. #DFIR_Radar https://t.co/Y

    @DFIR_Radar

    10 Sept 2026

    154 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 🔒 #CyberSecurity CISA KEV Adds CVE-2025-25249, CVE-2026-19490, CVE-2026-87491, CVE-2026-20079: F… "On September 9, 2026, CISA added four vulnerabilities to its Known Exploited Vulnerabilities…" 🔗 https://t.co/U9Ok5n6M9t #CyberSecurity #ThreatIntel #critical #zeroday

    @SecurityAr58409

    10 Sept 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔒 #CyberSecurity CVE-2026-87491: Chromium V8 Out-of-Bounds Write Added to CISA KEV — Detection a… "On September 9, 2026, CISA added CVE-2026-87491 to the Known Exploited…" 🔗 https://t.co/E9uqEZ6Nky #CyberSecurity #ThreatIntel #cve202687491 #critical #cisakev

    @SecurityAr58409

    10 Sept 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2025-25249 (Fortinet複数製品) - CVE-2026-19490 (Citrix Netscaler) - CVE-2026-87491 (Chromium) - CVE-2026-20079 (Cisco

    @__kokumoto

    9 Sept 2026

    732 Impressions

    1 Retweet

    9 Likes

    4 Bookmarks

    1 Reply

    0 Quotes

  6. Earlier this month, @Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). Volexity observed threat actors it tracks as

    @Volexity

    9 Sept 2026

    3674 Impressions

    29 Retweets

    52 Likes

    16 Bookmarks

    0 Replies

    1 Quote

  7. N-able N-central (CVE-2026-86218) and F5 BIG-IP APM are under active exploitation, while a Chrome V8 zero-day (CVE-2026-87491) rounds out today's high-signal patch-now list. #CyberSecurity #BlueTeam #ZeroDay https://t.co/cdeOHqWLhq

    @itsalreadywhen

    9 Sept 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. 🚨 7TH CHROME ZERO-DAY OF 2026 — ACTIVELY EXPLOITED CVE-2026-87491: V8 out-of-bounds write → RCE inside sandbox UPDATE TO CHROME 153.0.8010.36/.37 NOW → https://t.co/tut70NKy15 #Chrome #ZeroDay #CVE #V8 #CyberSecurity #PatchNow #ThreatIntel

    @ThreatAft

    9 Sept 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2026-87491, an out-of-bounds write in V8, was exploited in the wild for remote code execution inside the Chrome sandbox. Google shipped the fix in 153.0.8010.36. The same update closed 229 additional issues, including CVE-2026-87464, CVE-2026-87488, CVE-2026-87438,

    @SecureChap

    9 Sept 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🐦 🚨 Active exploitation: Chrome V8 0-day CVE-2026-87491 patched in-the-wild. N-able N-central CVE-2026-86218 (CVSS 10.0) pre-auth RCE hits CISA KEV. Adobe Magento CVE-2026-75650 zero-day (StyleSmuggler) exploited since Sept 4 - patch now. #infosec #CVE #0day

    @ita_ipo

    9 Sept 2026

    93 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds h

    @OffensiveLab

    9 Sept 2026

    111 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. @Google ships Chrome 153 fixing 230 vulnerabilities, including five critical issues and one actively exploited zero-day. The update resolves use-after-free flaws in WebGL (CVE-2026-87464, CVE-2026-87488), an out-of-bounds write in V8 (CVE-2026-87491) already seen in attacks,

    @WorldCyberNewsX

    9 Sept 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491): Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491… https://t.co/LihfBbKtqP h

    @shah_sheikh

    9 Sept 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Google patched a Chrome zero-day, CVE-2026-87491, exploited in the wild. Chrome 153 fixes 230 flaws including critical WebGL bugs. Update now. #Chrome #ZeroDay #Google #CyberSecurity #CVE #V8 #BrowserSecurity #Infosec https://t.co/lxdx0OpotX

    @Daily_CyberSec

    9 Sept 2026

    220 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations