Google Chrome V8 out-of-bounds write security flaw (CVE-2026-87491)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-87491 is an out-of-bounds write in V8 inside Google Chrome that can let a remote attacker run code inside the browser sandbox through a crafted HTML page. Google says the flaw is actively exploited in the wild, making the exposed Chrome and Chromium-based browser base at immediate risk until updated. The fix is included in Chrome 153.0.8010.36/.37 for Windows and macOS and 153.0.8010.36 for Linux.
Related Happenings
Google Chrome V8 type confusion security flaw (CVE-2026-85046)
Vulnerability
H score34
First: 04.09.2026 10:18
Last: 04.09.2026 10:18
Sources 1
About this happening:
Google patched CVE-2026-85046, a V8 type confusion flaw in Google Chrome that was actively exploited in the wild and could let a remote attacker execute code insid...
Google Chrome V8 type confusion security flaw (CVE-2026-85046)
VulnerabilityAbout this happening: Google patched CVE-2026-85046, a V8 type confusion flaw in Google Chrome that was actively exploited in the wild and could let a remote attacker execute code insid...
Chrome V8 JavaScript engine out-of-bounds read/write zero-day exploited in the wild (CVE-2026-11645)
Vulnerability
H score45
First: 09.06.2026 09:56
Last: 09.06.2026 09:56
Sources 1
About this happening:
Google has patched CVE-2026-11645, a Chrome V8 JavaScript engine zero-day that was exploited in the wild and could let remote attackers run code inside the browser...
Chrome V8 JavaScript engine out-of-bounds read/write zero-day exploited in the wild (CVE-2026-11645)
VulnerabilityAbout this happening: Google has patched CVE-2026-11645, a Chrome V8 JavaScript engine zero-day that was exploited in the wild and could let remote attackers run code inside the browser...
Chromium JavaScript background RCE flaw
Vulnerability
H score16
First: 21.05.2026 21:13
Last: 21.05.2026 21:13
Sources 1
About this happening:
The unfixed Chromium flaw keeps JavaScript running after the browser is closed, creating remote code execution risk across Chromium-based browsers. A malicious sit...
Chromium JavaScript background RCE flaw
VulnerabilityAbout this happening: The unfixed Chromium flaw keeps JavaScript running after the browser is closed, creating remote code execution risk across Chromium-based browsers. A malicious sit...
Chrome/Dawn actively exploited use-after-free flaw (CVE-2026-5281)
Vulnerability
H score1
First: 01.04.2026 13:25
Last: 01.04.2026 13:25
Sources 1
About this happening:
Google Chrome Stable Desktop on Windows, macOS, and Linux is getting an emergency fix for CVE-2026-5281, a use-after-free flaw in Dawn/WebGPU. Google says...
Chrome/Dawn actively exploited use-after-free flaw (CVE-2026-5281)
VulnerabilityAbout this happening: Google Chrome Stable Desktop on Windows, macOS, and Linux is getting an emergency fix for CVE-2026-5281, a use-after-free flaw in Dawn/WebGPU. Google says...
Chrome Skia and V8 exploited zero-days (multiple vulnerabilities)
Vulnerability
H score31
First: 13.03.2026 11:17
Last: 13.03.2026 11:17
Sources 1
About this happening:
Chrome on Windows, macOS, and Linux is affected by two high-severity zero-days, CVE-2026-3909 and CVE-2026-3910, that Google says were exploited in the wild*...
Chrome Skia and V8 exploited zero-days (multiple vulnerabilities)
VulnerabilityAbout this happening: Chrome on Windows, macOS, and Linux is affected by two high-severity zero-days, CVE-2026-3909 and CVE-2026-3910, that Google says were exploited in the wild*...
Timeline
-
09.09.2026 12:11 1 articles · 3h ago
Security researcher reports CVE-2026-87491 in Chrome V8
Initial DisclosureSecurity researcher Jihyeon Jeong of Compsec Lab, Seoul National University discovered and reported CVE-2026-87491, an out-of-bounds bug in V8, on August 6, 2026.
Show sources
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox — thehackernews.com — 09.09.2026 12:11
-
09.09.2026 12:11 2 articles · 3h ago
Google patches Chrome V8 zero-day exploited in the wild
Mitigation Patch UpdateGoogle released Chrome updates that patch CVE-2026-87491, a V8 out-of-bounds write in Chrome prior to 153.0.8010.36 that can let a remote attacker execute arbitrary code inside the sandbox via a crafted HTML page. Google said it is aware an exploit exists in the wild and directed users to install versions 153.0.8010.36/.37 on Windows and macOS, or 153.0.8010.36 on Linux, then relaunch Chrome.
Show sources
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox — thehackernews.com — 09.09.2026 12:11
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox — thehackernews.com — 09.09.2026 12:11