Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

General Security Talk, Announcements and News
Post Reply
Starburst-David
Posts: 314
Joined: Wed Feb 11, 2026 8:31 pm

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Post by Starburst-David »

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.

The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.

"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a description of the flaw on the NIST National Vulnerability Database (NVD).

Full article at:
https://thehackernews.com/2026/09/chrom ... -wild.html

CVE Details can be found at:
https://nvd.nist.gov/vuln/detail/cve-2026-87491

Published Date: Sep 09, 2026

Vulnerabilities has been mentioned in this article:
CVE-2026-87639 CVE-2026-87628 CVE-2026-87527 CVE-2026-87491 CVE-2026-87488 CVE-2026-87464 CVE-2026-87438 CVE-2026-85046 CVE-2026-11645 CVE-2026-5281 CVE-2026-3910 CVE-2026-3909 CVE-2026-2441
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “General”