Back to feed

Google patches Chrome V8 zero-day exploited in the wild

2 min
Google patches Chrome V8 zero-day exploited in the wild

This digest was compiled by AI from multiple sources — links to the originals are below.

Google released Chrome 153.0.8010.36 on Thursday, patching 230 vulnerabilities including CVE-2026-87491, an out-of-bounds write in the V8 engine that is actively exploited in the wild. The flaw allows remote code execution inside the sandbox via a crafted HTML page. Google acknowledged the exploitation but withheld details on the attacks.

Key Facts

  • CVE-2026-87491 is an out-of-bounds write in Chrome's V8 engine that allows remote code execution inside the sandbox via a crafted HTML page.
  • Google patched 230 vulnerabilities in Chrome 153.0.8010.36, including five critical flaws in WebGL and Cast components.
  • Security researcher Jihyeon Jeong of Seoul National University reported the flaw on August 6, 2026, and received a $2,500 bug bounty.
  • Google has fixed seven actively exploited Chrome zero-days in 2026, including CVE-2026-87491.

The Vulnerability

CVE-2026-87491 is a medium-severity out-of-bounds write in V8, Chrome's JavaScript and WebAssembly engine. The flaw allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. Google acknowledged that an exploit for CVE-2026-87491 exists in the wild but did not disclose how it is being weaponized or who is behind the attacks. Security researcher Jihyeon Jeong of Compsec Lab, Seoul National University, discovered and reported the flaw on August 6, 2026, receiving a $2,500 bug bounty.

Patch Details

The Chrome 153.0.8010.36 update fixes 230 vulnerabilities, including five critical flaws in WebGL and Cast components. Google reported 195 of the 230 flaws addressed in the update, with one high-severity use-after-free in WebPackaging credited to OpenAI Codex Security. Users are advised to update Chrome to versions 153.0.8010.36/.37 for Windows and macOS, and 153.0.8010.36 for Linux. Other Chromium-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, should apply the fixes as they become available.

Zero-Day Trend

With this update, Google has addressed seven actively exploited Chrome zero-days since the start of 2026. The list includes CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and CVE-2026-85046. Google restricts access to bug details until a majority of users are updated, or if the bug exists in a third-party library that other projects depend on.

1 source

Time · lag behind first