CVE Tools

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)

Help Net SecurityBy Sinisa Markovic

Reported exploitedGoogle Chrome

Our summary

Google has addressed an actively exploited zero-day vulnerability, designated as CVE-2026-87491, within the V8 JavaScript and WebAssembly engine of Chrome. This out-of-bounds write flaw enables remote attackers to execute arbitrary code via specifically crafted HTML pages. The security update is available in Chrome versions 153.0.8010.36 and .37 for Windows and macOS, as well as 153.0.8010.36 for Linux.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store