THREAT OPS › CVEs › CVE-2026-87491
CVE-2026-87491 — Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Vulnerability details
- Affected productsChromium V8
- KEV remediation due2026-09-23
Related reporting
- Update Chrome now to protect against an actively exploited vulnerabilitymalwarebytes_blog
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories
- Google security advisory (AV26-904)cccs_ca
- [CISA KEV] CVE-2026-87491 — Google Chromium V8: Google Chromium V8 Out of Bounds Write Vulnerabilitycisa_kev
- Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windowsvolexity
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandboxthehackernews