VORANT. Threat Intelligence Sign in Get the full feed

Chrome zero-day CVE-2026-87491 exploited in wild

severe vulnerability

Google patched an actively exploited V8 out-of-bounds write zero-day in Chrome versions before 153.0.8010.36 that allows sandboxed code execution via a crafted webpage.

NCSC-NL published an advisory relaying Google's disclosure of a zero-day vulnerability, CVE-2026-87491, in the V8 JavaScript engine used by Google Chrome. The flaw is an out-of-bounds write caused by improper bounds checking in V8's memory management, affecting all Chrome versions prior to 153.0.8010.36. Google has confirmed active exploitation in the wild.

An attacker can trigger the vulnerability by luring a victim to a specially crafted HTML page, leading to memory corruption that can allow arbitrary code execution within the browser sandbox. Successful exploitation may also allow reading data outside allocated memory buffers, potentially exposing sensitive information or crashing the browser. Google has released updated Chrome builds that remediate the issue; defenders should ensure Chrome (and Chromium-based browsers) are updated to version 153.0.8010.36 or later as a priority given confirmed in-the-wild exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-87491KEV

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0354.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free