CVE Tools

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

The Hacker NewsBy The Hacker News

Reported exploitedGoogle Chrome

Our summary

Google has released security updates for Chrome, addressing 230 vulnerabilities including a medium-severity out-of-bounds bug in the V8 engine that is currently being exploited in the wild. Identified as CVE-2026-87491, this flaw allows remote attackers to execute arbitrary code within the sandbox via crafted HTML content in versions prior to 153.0.8010.36.
The update also resolves five critical flaws in WebGL and Cast components, bringing the total number of actively exploited Chrome zero-days patched this year to seven. Users are strongly advised to upgrade to version 153.0.8010.36/.37 on Windows and macOS, or 153.0.8010.36 on Linux, to mitigate these risks.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store