[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fe5f3jAvdL-KzRUwOYhHpTy0ZBFnUJgxeVKrgUnfFl9c":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"3556c7cc-8225-4bf0-bb72-4451b9d209f5","Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox","chrome-v8-zero-day-exploited-in-the-wild-enables-code-execution-inside-sandbox-375dd8","Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N\u002FA), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. \"Out-of-bounds write in V8 in Google Chrome prior to","Google has released updates to patch 230 vulnerabilities in Chrome, including a zero-day flaw in the V8 JavaScript engine that was actively exploited. The vulnerability, CVE-2026-87491, is an out-of-bounds write that allows remote attackers to execute arbitrary code within the browser's sandbox via a crafted HTML page. This marks the seventh actively exploited Chrome zero-day this year, highlighting the ongoing threat to browser security.","Chrome V8 zero-day exploited in the wild allows code execution inside sandbox.","Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox Ravie LakshmananSep 09, 2026Vulnerability \u002F Browser Security Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N\u002FA), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. \"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page,\" reads a description of the flaw on the NIST National Vulnerability Database (NVD). Security researcher Jihyeon Jeong of Compsec Lab, Seoul National University, has been acknowledged for discovering and reporting the flaw on August 6, 2026. The researcher received a $2,500 bug bounty reward for responsible disclosure. Google acknowledged it is \"aware that an exploit for CVE-2026-87491 exists in the wild,\" but has not disclosed any additional specific information related to how it's being weaponized in real-world attacks and who is behind them. \"Access to bug details and links may be kept restricted until a majority of users are updated with a fix,\" the tech giant added. \"We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.\" With the latest development, Google has addressed a total of seven actively exploited Chrome zero-days since the start of the year. This includes CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and CVE-2026-85046. Besides CVE-2026-87491, the latest update also fixes five critical security flaws in WebGL and Cast components - CVE-2026-87464 - Use-after-free in WebGL CVE-2026-87488 - Use-after-free in WebGL CVE-2026-87438 - Out-of-bounds write in WebGL CVE-2026-87527 - Buffer overflow in WebGL CVE-2026-87628 - Use-after-free in Cast Google said it reported 195 out of the 230 flaws that have been addressed in the update. One high use-after-free flaw in WebPackaging (CVE-2026-87639) is credited to OpenAI Codex Security. \"Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL,\" the company added. For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36\u002F.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux. To ensure the latest updates are installed, users can navigate to More > Help > About Google Chrome and select Relaunch. Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Google Chrome, Vulnerability, Web Security, Zero-Day ⚡ Top Stories This Week Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon Fake Software Installers Disable Windows Update and Weaken Microsoft Defender Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another ⭐ Featured Resources Get the eBook: Map Enterprise AI Risk Across the Full Lifecycle Give SOC Analysts Visibility Into 90% of Attacks Within 60 Seconds Benchmark Your SOC's AI Adoption With the 2026 Security Operations Report Register for LDR516: Strategic Vulnerability and Threat Management at SANS DC Metro","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fchrome-v8-zero-day-exploited-in-wild.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgZvl2DE9GFM-4rdFgtQOOp1Dk3Xgp7xWysUv5zKTFwxqWYTurcgXgE-PDMn3_2AAIihh4YeiRvmwpb6GVDB1-8kxqasUWwX-FFa4mA41kXpFbzdt9hOvzW4xcyKBFttqIzbFSl-1SSSO0P_URv3Sy9QamkQZ55qzX5Y9Kmv5NdBCBHXCcUziiO6mfrqURE\u002Fs1600\u002Fchrome-zeroday.jpg","2026-09-09T09:11:03+00:00","2026-09-09T10:00:16.067412+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"Chrome","product",{"name":22,"type":23},"V8 JavaScript engine","technology",{"name":25,"type":26},"Google","vendor",{"name":28,"type":20},"WebGL",{"name":30,"type":20},"Cast",{"name":32,"type":20},"WebPackaging","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,44,46],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52,56,59,61,64,67,70],{"type":53,"value":54,"context":55},"cve","CVE-2026-87491","Out-of-bounds write in V8 JavaScript engine.",{"type":53,"value":57,"context":58},"CVE-2026-87464","Use-after-free in WebGL.",{"type":53,"value":60,"context":58},"CVE-2026-87488",{"type":53,"value":62,"context":63},"CVE-2026-87438","Out-of-bounds write in WebGL.",{"type":53,"value":65,"context":66},"CVE-2026-87527","Buffer overflow in WebGL.",{"type":53,"value":68,"context":69},"CVE-2026-87628","Use-after-free in Cast.",{"type":53,"value":71,"context":72},"CVE-2026-87639","Use-after-free in WebPackaging."]