thehackernews.com 9 Sept 2026, 09:11 UTC

Chrome Patches Exploited V8 Zero Day Allowing Code Execution

GOOGLE Chrome has patched a zero‑day vulnerability in its V8 JavaScript and WebAssembly engine that has been exploited in the wild. The flaw, CVE-2026-87491, is described as an out-of-bounds write in V8 that could let a remote attacker run arbitrary code inside the browser sandbox via a crafted HTML page. Google notes it is “aware that an exploit for CVE-2026-87491 exists in the wild,” but has not disclosed full details about weaponisation or suspects.

The fixed builds are Chrome 153.0.8010.36/37 for Windows and macOS, and 153.0.8010.36 for Linux, with the update aimed at ensuring users install the latest security fixes. The company emphasises restricting bug details until most users are updated and notes the fix also applies to other Chromium‑based browsers.

In total, Google reports seven actively exploited Chrome zero‑days this year, including CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645 and CVE-2026-85046, alongside CVE-2026-87491. Beyond the primary V8 issue, the update also patches five WebGL and Cast vulnerabilities: CVE-2026-87464, CVE-2026-87488, CVE-2026-87438, CVE-2026-87527 and CVE-2026-87628, with one high‑severity WebPackaging flaw CVE-2026-87639 attributed to OpenAI Codex Security.

The article notes the disclosure and responses underscore continued vigilance around exploits, and urges users of other Chromium‑based browsers to apply fixes when available.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline