Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5520 articles · 213524 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-87491KEVEXPLOITEDPATCHED
google · chrome

CVE-2026-87491: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code in

Description

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Affected Products

VendorProductVersions
googlechrome153.0.8010.36

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googlechromecert_advisory90%

References

  • https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
  • https://issues.chromium.org/issues/543557673

Related News (8 articles)

Tier B
CCCS Canada17h ago
Google security advisory (AV26-904)
→ No new info (linked only)
Tier D
SecurityWeek1d ago
Chrome 153 Patches Seventh Zero-Day of 2026
→ No new info (linked only)
Tier D
Heise Security1d ago
Chrome 153: Google wechselt zu Zweiwochen-Update-Zyklus
→ No new info (linked only)
Tier D
The Hacker News1d ago
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
→ No new info (linked only)
Tier B
BSI Advisories1d ago
[NEU] [hoch] Google Chrome: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
→ No new info (linked only)
Tier D
Help Net Security1d ago
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-87491 | Google Chrome up to 152.0.7977.82 V8 out-of-bounds write
→ No new info (linked only)
Tier B
CERT-FR1d ago
Multiples vulnérabilités dans Google Chrome (09 septembre 2026)
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
153.0.8010.36
CWECWE-787
PublishedSep 9, 2026
Trending Score137🔥
Source articles8
Independent8
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-85046EXPKEV
CVE-2026-85046: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
Trending: 146
CRITICALCVE-2026-41157EXP
GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3D
Trending: 66
CRITICALCVE-2026-49921
CVE-2026-49921: In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote
Trending: 51
CRITICALCVE-2026-58822
CVE-2026-58822: In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to
Trending: 51
HIGHCVE-2026-34192EXP
GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries
Trending: 50

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 9, 2026
Added to CISA KEV
Sep 9, 2026
Discovered by ZDM
Sep 9, 2026
Actively Exploited
Sep 10, 2026
Patch Available
Sep 10, 2026