← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 9, 2026 · 13:47via Security Affairs

Google fixes the seventh actively exploited Chrome zero-day of 2026

Brief

Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page.

Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8. 8). The medium-severity flaw affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine.

An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome’s sandbox. Google fixed the issue in Chrome 153.

  • 8010. 36 and later versions.

“CVE-2026-87491: Out of bounds write in V8” reads the advisory . “Google is aware that an exploit for CVE-2026-87491 exists in the wild.”

Read more on Security Affairs