Cyber News / Article / Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google on Tuesdayreleasedupdates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.
The medium-severity vulnerability, assigned the CVE identifierCVE-2026-87491(CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.
"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads adescriptionof the flaw on the NIST National Vulnerability Database (NVD).
Security researcher Jihyeon Jeong of Compsec Lab, Seoul National University, has been acknowledged for discovering and reporting the flaw on August 6, 2026. The researcher received a $2,500 bug bounty reward for responsible disclosure.
Google acknowledged it is "aware that an exploit for CVE-2026-87491 exists in the wild," but has not disclosed any additional specific information related to how it's being weaponized in real-world attacks and who is behind them.
"Access to bug details and links may be kept restricted until a majority of users are updated with a fix," the tech giant added. "We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed."
With the latest development, Google has addressed a total of seven actively exploited Chrome zero-days since the start of the year. This includesCVE-2026-2441,CVE-2026-3909, CVE-2026-3910,CVE-2026-5281,CVE-2026-11645, andCVE-2026-85046.
Besides CVE-2026-87491, the latest update also fixes five critical security flaws in WebGL and Cast components -
Google said it reported 195 out of the 230 flaws that have been addressed in the update. One high use-after-free flaw in WebPackaging (CVE-2026-87639) is credited to OpenAI Codex Security.
"Many of our security bugs are detected usingAddressSanitizer,MemorySanitizer,UndefinedBehaviorSanitizer,Control Flow Integrity,libFuzzer, orAFL," the company added.
For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux. To ensure the latest updates are installed, users can navigate to More > Help > About Google Chrome and select Relaunch.
Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 9, 2026,addedCVE-2026-87491 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 23, 2026.
Related articles
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
about 21 hours ago
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
1 day ago
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
2 days ago
You might Also like
Hackers Use Claude AI Agents to Automate Cyberattacks, Develop 0-Days and Evade Detection

New Android malware encrypts files, steals data, and harasses victims

