Chrome 153 V8 out-of-bounds write 0-day (CVE-2026-87491) exploited in the wild
Google's Stable Channel Update for Desktop (8 September 2026) promotes Chrome 153 to 153.0.8010.36 (Linux) and 153.0.8010.36/.37 (Windows/Mac). Google lists Medium CVE-2026-87491 as an out-of-bounds write in V8 (reported 6 August 2026 by Jihyeon Jeong, Compsec Lab, Seoul National University) and states an exploit exists in the wild — the seventh Chrome zero-day Google has fixed in 2026 per same-day wire coverage. BleepingComputer (9 September) describes remote code execution inside the sandbox via crafted HTML and heap corruption risk; Google has not published attack details while uptake is incomplete. Distinct from desk card cve-2026-85046 (4 Sep V8 type-confusion 0-day at 152.0.7977.82/.83) and chrome-firefox-20260902. Update Chrome promptly; other Chromium browsers should follow vendor builds. NEW 11 September 2026 (WA SOC advisory 20260911001, TLP:CLEAR): Chromium V8 Known Exploited Vulnerability covers the same CVE-2026-87491 for Google Chrome versions prior to 153.0.8010.36; WASOC table lists CVSS 8.8 High (out-of-bounds write enabling code execution inside the sandbox via crafted HTML). Notes Google is aware of in-the-wild exploit use and CISA KEV listing; WASOC had not received reports of exploitation on Western Australian Government networks at time of writing. Patch Chrome/Chromium browsers to 153.0.8010.36+ per vendor.
- Product
- Google Chrome (V8)
- Versions
- Prior to 153.0.8010.36 (Linux) / 153.0.8010.36/.37 (Windows/Mac)
- CVSS
- 8.8 (WASOC 20260911001 High)
- Exploited in Australia?
- unknown
- Patch to
- Chrome 153.0.8010.36/.37 or later
Primary: Chrome Stable Channel Update for Desktop (8 Sep 2026) · Vendor: Google Chrome Releases · CVE: CVE-2026-87491, CVE-2026-85046 · WA SOC 20260911001 (11 Sep 2026); earlier BC 9 Sep
