Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Published September 9, 2026 CVE-2026-87491

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.

Severity
HighCVSS 3.1 · 8.8
Fix
Fixed in 153.0.8010.36
Affected versions
before 153.0.8010.36
Weakness
CWE-787Out-of-bounds Write
Exploit likelihood
0.86% in 30 daysEPSS, higher than 56% of known flaws
Affects
Chrome
Exploited
Yes, in the wildListed by CISA
CISA SSVC
Active exploitationAutomatable: no · Technical impact: total
EU ID
EUVD-2026-74529ENISA vulnerability database
Added to CISA list
Sep 9, 2026
Federal fix deadline
Sep 23, 2026

What to do

Update to 153.0.8010.36 or later.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction Required Requires another user to take an action
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Open in FIRST.org calculator