Search
Find merged stories by title or summary.
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break
Chromium CVE-2026-87491: Out of bounds write in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases. googleblog. com/20)2)6) for more information. Google is aware that an exploit for CVE-2026-87491 exists in the wild.
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-20079 (CVSS score of 10. 0) is an authentication bypass issue.
Google fixes the seventh actively exploited Chrome zero-day of 2026
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8. 8). The medium-severity flaw affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine. An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome’s sandbox. Google fixed the issue in Chrome 153. 0. 8010. 36 and later versions. “CVE-2026-87491: Out of bounds write in V8” reads the advisory . “Google is aware that an exploit for CVE-2026-87491 exists in the wild.”
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to
Google fixes second actively exploited Chrome zero-day in under five days
Google has released Chrome 153 to the stable channel with fixes for 230 security vulnerabilities, including a V8 memory corruption flaw that Google says is already being exploited in attacks. The actively exploited vulnerability is tracked as CVE-2026-87491 and is described as an out-of-bounds write in V8, Chrome’s JavaScript and WebAssembly engine. It was reported … The post Google fixes second actively exploited Chrome zero-day in under five days appeared first on CyberInsider .
CVE-2026-87491 Detail - National Institute of Standards and Technology (.gov)
CVE-2026-87491 Detail National Institute of Standards and Technology (.gov)
CVE-2026-87491 - Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
You've reached the end of current stories for this search.
