securityaffairs.com 9 Sept 2026, 13:47 UTC

Google Patches Chrome’s Seventh Zero Day of 2026 Under Attack

Google Patches Chrome’s Seventh Zero Day of 2026 Under Attack

GOOGLE has released a Chrome update to address a string of actively exploited vulnerabilities in 2026, including the seventh zero-day cased in the wild. The standout flaw is CVE-2026-87491, an out-of-bounds write in the V8 engine with a CVSS score of 8.8, which could allow an attacker to execute arbitrary code via a specially crafted HTML page. Google states that an exploit for this vulnerability exists in the wild, and the advisory notes that the issue was fixed in Chrome 153.0.8010.36 and later.

The vulnerability was reported by Jihyeon Jeong of Seoul National University on 6 August 2026, and as with prior Chrome zero-days, Google did not disclose technical exploit details or attribute the attacks to any specific threat actor. A $2,500 bounty was awarded to the researcher for responsible disclosure.

This CVE-2026-87491 incident is part of a pattern in 2026 in which Chrome has patched multiple actively exploited flaws. The article lists earlier cases: CVE-2026-2441 (February, CSS use-after-free), CVE-2026-3909 and CVE-2026-3910 (March, Skia and V8 engine issues), CVE-2026-5281 (April, Dawn WebGPU use-after-free), CVE-2026-11645 (June, V8 memory access), and CVE-2026-85046 (September, V8 type confusion). Chrome Stable updates affect Linux (153.0.8010.36) and Windows/macOS (153.0.8010.36/37). The rollout is expected to continue over coming days and weeks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline