Google fixes the seventh actively exploited Chrome zero-day of 2026

Google fixes the seventh actively exploited Chrome zero-day of 2026

Google fixes the seventh actively exploited Chrome zero-day of 2026

Google fixes the seventh actively exploited Chrome zero-day of 2026

Google fixes the seventh actively exploited Chrome zero-day of 2026

Pierluigi Paganini
September 09, 2026

Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page.

Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8). The medium-severity flaw affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine.

An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome’s sandbox. Google fixed the issue in Chrome 153.0.8010.36 and later versions.

“CVE-2026-87491: Out of bounds write in V8” reads the advisory. “Google is aware that an exploit for CVE-2026-87491 exists in the wild.”

Researcher Jihyeon Jeong from Seoul National University reported the vulnerability on 2026-08-06.

As usual, Google did not disclose technical details about the attacks exploiting this vulnerability or attribute them to any specific threat actor.

Google rewarded the researcher with a $2,500 bounty for responsibly disclosing the vulnerability.

CVE-2026-87491 is the seventh actively exploited Chrome zero-day of 2026. Since the start of the year, Google has addressed the following zero-day flaws exploited in attacks in the wild:

  • February 2026 – CVE-2026-2441 (CVSS score: 8.8) – Use after free in CSS.
  • March 2026 – CVE-2026-3909 (CVSS score: 8.8) – Out-of-bounds write in the Skia 2D graphics library and CVE-2026-3910 (CVSS score: 8.8) – Flaw in the implementation of the V8 JavaScript/WebAssembly engine.
  • April 2026 – CVE-2026-5281 (CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
  • June 2026 – CVE-2026-11645 (CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
  • September – CVE-2026-85046 (CVSS score: 8.8) – V8 type confusion flaw.

Google has updated Chrome Stable to version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac. The release includes several fixes and improvements, with the rollout expected over the coming days and weeks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.