National Cyber Warfare Foundation (NCWF)

Google fixes the seventh actively exploited Chrome zero-day of 2026


0 user ratings
2026-09-09 14:17:11
milo
Blue Team (CND)
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8). The medium-severity flaw affects V8, Google’s open source high-performance […


Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page.





Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8). The medium-severity flaw affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine.





An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome’s sandbox. Google fixed the issue in Chrome 153.0.8010.36 and later versions.





“CVE-2026-87491: Out of bounds write in V8” reads the advisory. “Google is aware that an exploit for CVE-2026-87491 exists in the wild.”





Researcher Jihyeon Jeong from Seoul National University reported the vulnerability on 2026-08-06.





As usual, Google did not disclose technical details about the attacks exploiting this vulnerability or attribute them to any specific threat actor.





Google rewarded the researcher with a $2,500 bounty for responsibly disclosing the vulnerability.





CVE-2026-87491 is the seventh actively exploited Chrome zero-day of 2026. Since the start of the year, Google has addressed the following zero-day flaws exploited in attacks in the wild:






  • February 2026 – CVE-2026-2441 (CVSS score: 8.8) – Use after free in CSS.




  • March 2026 – CVE-2026-3909 (CVSS score: 8.8) – Out-of-bounds write in the Skia 2D graphics library and CVE-2026-3910 (CVSS score: 8.8) – Flaw in the implementation of the V8 JavaScript/WebAssembly engine.




  • April 2026 – CVE-2026-5281 (CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.




  • June 2026 – CVE-2026-11645 (CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine




  • September – CVE-2026-85046 (CVSS score: 8.8) – V8 type confusion flaw.





Google has updated Chrome Stable to version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac. The release includes several fixes and improvements, with the rollout expected over the coming days and weeks.





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, newsletter)



Source: SecurityAffairs
Source Link: https://securityaffairs.com/198757/security/google-fixes-the-seventh-actively-exploited-chrome-zero-day-of-2026.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.