Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Ravie LakshmananSep 09, 2026Vulnerability / Browser Security

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.

The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome’s JavaScript and WebAssembly engine.

“Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page,” reads a description of the flaw on the NIST National Vulnerability Database (NVD).

Security researcher Jihyeon Jeong of Compsec Lab, Seoul National University, has been acknowledged for discovering and reporting the flaw on August 6, 2026. The researcher received a $2,500 bug bounty reward for responsible disclosure.

Google acknowledged it is “aware that an exploit for CVE-2026-87491 exists in the wild,” but has not disclosed any additional specific information related to how it’s being weaponized in real-world attacks and who is behind them. 

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” the tech giant added. “We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

With the latest development, Google has addressed a total of seven actively exploited Chrome zero-days since the start of the year. This includes CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and CVE-2026-85046.

Besides CVE-2026-87491, the latest update also fixes five critical security flaws in WebGL and Cast components – 

  • CVE-2026-87464 – Use-after-free in WebGL
  • CVE-2026-87488 – Use-after-free in WebGL
  • CVE-2026-87438 – Out-of-bounds write in WebGL
  • CVE-2026-87527 – Buffer overflow in WebGL
  • CVE-2026-87628 – Use-after-free in Cast

Google said it reported 195 out of the 230 flaws that have been addressed in the update. One high use-after-free flaw in WebPackaging (CVE-2026-87639) is credited to OpenAI Codex Security.

“Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL,” the company added.

For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux. To ensure the latest updates are installed, users can navigate to More > Help > About Google Chrome and select Relaunch.

Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available.

Source link

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *