AI description
CVE-2026-87491 is an out-of-bounds write vulnerability found in V8, Google Chrome's JavaScript and WebAssembly engine. This flaw allows a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. The vulnerability was reported by Jihyeon Jeong of the Compsec Lab at Seoul National University on August 6, 2026. Google has confirmed that an exploit for CVE-2026-87491 exists in the wild, making it an actively exploited zero-day vulnerability. The issue has been addressed in Chrome version 153.0.8010.36 for Windows, macOS, and Linux, and is the seventh actively exploited Chrome zero-day patched by Google in 2026.
- Description
- Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Source
- chrome-cve-admin@google.com
- NVD status
- Modified
- Products
- chrome
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Google Chromium V8 Out of Bounds Write Vulnerability
- Exploit added on
- Sep 9, 2026
- Exploit action due
- Sep 23, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- chrome-cve-admin@google.com
- CWE-787
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
10
CVE-2026-87491 (CVSS 8.8): actively exploited out-of-bounds write in Chrome's V8 engine. Added to CISA's KEV catalog — the 7th actively exploited Chrome zero-day patched this year. Affected: Chrome versions prior to 153.0.8010.36 Update now. Details: https://t.co/QdBfkEiGdZ
@vuln_tracker
10 Sept 2026
86 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Chinese 🇨🇳 APT31/TA412 first exploited BlueMoon zero-day chain CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 on Aug. 28, dropping a fake Google Gemini browser extension to steal credentials. Patch Chrome now and hunt for unsigned extensions. #DFIR_Radar https://t.co/Y
@DFIR_Radar
10 Sept 2026
154 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔒 #CyberSecurity CISA KEV Adds CVE-2025-25249, CVE-2026-19490, CVE-2026-87491, CVE-2026-20079: F… "On September 9, 2026, CISA added four vulnerabilities to its Known Exploited Vulnerabilities…" 🔗 https://t.co/U9Ok5n6M9t #CyberSecurity #ThreatIntel #critical #zeroday
@SecurityAr58409
10 Sept 2026
75 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-87491: Chromium V8 Out-of-Bounds Write Added to CISA KEV — Detection a… "On September 9, 2026, CISA added CVE-2026-87491 to the Known Exploited…" 🔗 https://t.co/E9uqEZ6Nky #CyberSecurity #ThreatIntel #cve202687491 #critical #cisakev
@SecurityAr58409
10 Sept 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2025-25249 (Fortinet複数製品) - CVE-2026-19490 (Citrix Netscaler) - CVE-2026-87491 (Chromium) - CVE-2026-20079 (Cisco
@__kokumoto
9 Sept 2026
732 Impressions
1 Retweet
9 Likes
4 Bookmarks
1 Reply
0 Quotes
Earlier this month, @Volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). Volexity observed threat actors it tracks as
@Volexity
9 Sept 2026
3674 Impressions
29 Retweets
52 Likes
16 Bookmarks
0 Replies
1 Quote
N-able N-central (CVE-2026-86218) and F5 BIG-IP APM are under active exploitation, while a Chrome V8 zero-day (CVE-2026-87491) rounds out today's high-signal patch-now list. #CyberSecurity #BlueTeam #ZeroDay https://t.co/cdeOHqWLhq
@itsalreadywhen
9 Sept 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 7TH CHROME ZERO-DAY OF 2026 — ACTIVELY EXPLOITED CVE-2026-87491: V8 out-of-bounds write → RCE inside sandbox UPDATE TO CHROME 153.0.8010.36/.37 NOW → https://t.co/tut70NKy15 #Chrome #ZeroDay #CVE #V8 #CyberSecurity #PatchNow #ThreatIntel
@ThreatAft
9 Sept 2026
86 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-87491, an out-of-bounds write in V8, was exploited in the wild for remote code execution inside the Chrome sandbox. Google shipped the fix in 153.0.8010.36. The same update closed 229 additional issues, including CVE-2026-87464, CVE-2026-87488, CVE-2026-87438,
@SecureChap
9 Sept 2026
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🐦 🚨 Active exploitation: Chrome V8 0-day CVE-2026-87491 patched in-the-wild. N-able N-central CVE-2026-86218 (CVSS 10.0) pre-auth RCE hits CISA KEV. Adobe Magento CVE-2026-75650 zero-day (StyleSmuggler) exploited since Sept 4 - patch now. #infosec #CVE #0day
@ita_ipo
9 Sept 2026
93 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds h
@OffensiveLab
9 Sept 2026
111 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
@Google ships Chrome 153 fixing 230 vulnerabilities, including five critical issues and one actively exploited zero-day. The update resolves use-after-free flaws in WebGL (CVE-2026-87464, CVE-2026-87488), an out-of-bounds write in V8 (CVE-2026-87491) already seen in attacks,
@WorldCyberNewsX
9 Sept 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491): Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491… https://t.co/LihfBbKtqP h
@shah_sheikh
9 Sept 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google patched a Chrome zero-day, CVE-2026-87491, exploited in the wild. Chrome 153 fixes 230 flaws including critical WebGL bugs. Update now. #Chrome #ZeroDay #Google #CyberSecurity #CVE #V8 #BrowserSecurity #Infosec https://t.co/lxdx0OpotX
@Daily_CyberSec
9 Sept 2026
220 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7BC1B89D-DEB1-48BD-8602-0869B89600FD",
"versionEndExcluding": "153.0.8010.36",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]