CVE-2026-87491
published 2026-09-09CVE-2026-87491: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML…
PriorityP185high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-09-23
Exploited in the wild
EPSS
0.29%
21.4th percentile
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 153.0.8010.36 | 153.0.8010.36 | |
| chrome | >= 153.0.8010.36 < 153.0.8010.36 | 153.0.8010.36 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Google Chromium V8 Out of Bounds Write Vulnerability
cisa·2026-09-09·CVSS 8.8
CVE-2026-87491 [HIGH] CWE-787 Google Chromium V8 Out of Bounds Write Vulnerability
Vulnerability: Google Chromium V8 Out of Bounds Write Vulnerability
Affected: Google Chromium V8
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders
Chrome
Stable Channel Update for Desktop: CVE-2026-87491
vendor_chrome·2026-09-08
CVE-2026-87491 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-87491
Stable Channel Update for Desktop
CVE-2026-87491: Out of bounds write in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-06
[$2,000][ 40060525 ] Medium CVE-2026-87478: Observable discrepancy in Autofill
Reported by Maurice Dauer on 2022-08-07
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2026-87593
vendor_chrome·2026-09-08
CVE-2026-87593 [LOW] Stable Channel Update for Desktop: CVE-2026-87593
Stable Channel Update for Desktop
CVE-2026-87593: Information leak in Editing. Reported by Google on 2026-08-27 Google is aware that an exploit for CVE-2026-87491 exists in the wild
Severity: low
VulDB
Google Chrome up to 152.0.7977.82 V8 out-of-bounds write
vuldb·2026-09-09
CVE-2026-87491 [CRITICAL] Google Chrome up to 152.0.7977.82 V8 out-of-bounds write
A vulnerability has been found in Google Chrome and classified as critical. This vulnerability affects unknown code of the component V8. This manipulation causes out-of-bounds write.
This vulnerability appears as CVE-2026-87491. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
VulnCheck
Google Chromium V8 Out of Bounds Write Vulnerability
vulncheck·2026·CVSS 8.8
CVE-2026-87491 [HIGH] CWE-787 Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Affected: Google Chromium V8
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsib
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-87491 chromium-browser: Chromium-browser: Arbitrary code execution via out-of-bounds write in V8
bugzilla·2026-09-09
CVE-2026-87491 [HIGH] CVE-2026-87491 chromium-browser: Chromium-browser: Arbitrary code execution via out-of-bounds write in V8
CVE-2026-87491 chromium-browser: Chromium-browser: Arbitrary code execution via out-of-bounds write in V8
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Hackernews
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
blogs_hackernews·2026-09-09·CVSS 8.8
CVE-2026-87491 [HIGH] Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.
The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.
"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a description of the flaw on the NIST National Vu
2026-09-09
Published
2026-09-09
Added to CISA KEV
Exploited in the wild