Back to advisories

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zero-day this year.