Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Reported exploitedGoogle ChromeOur summary
Google has released security updates for Chrome, addressing 230 vulnerabilities including a medium-severity out-of-bounds bug in the V8 engine that is currently being exploited in the wild. Identified as CVE-2026-87491, this flaw allows remote attackers to execute arbitrary code within the sandbox via crafted HTML content in versions prior to 153.0.8010.36.
The update also resolves five critical flaws in WebGL and Cast components, bringing the total number of actively exploited Chrome zero-days patched this year to seven. Users are strongly advised to upgrade to version 153.0.8010.36/.37 on Windows and macOS, or 153.0.8010.36 on Linux, to mitigate these risks.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.