Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
What happened
Google released Chrome updates to patch CVE-2026-87491, an out-of-bounds write in the V8 engine that allows remote attackers to execute arbitrary code inside the browser sandbox via a crafted HTML page. The company confirmed the vulnerability is under active exploitation in the wild, though it has not disclosed details regarding the specific attack methods or the actors responsible. Users should update to Chrome version 153.0.8010.36 or later to mitigate the risk.
Why it ranks #1
Google confirmed that CVE-2026-87491, an out-of-bounds write in the V8 engine, is under active exploitation in the wild to execute arbitrary code inside the browser sandbox via a crafted HTML page, prompting the release of Chrome version 153.0.8010.36 as the mitigation.
Who should care
CISOs and security leaders, SOC and incident response teams
What to do
Update Chrome to 153.0.8010.36/.37 on Windows and macOS, or 153.0.8010.36 on Linux, for optimal protection.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- actively exploited