← back

CVE-2026-87491

KEV EPSS 0.9%
hype LIKELY HACK · 82 hack

KEV-listed, real exploitation reported, vendor patch live, defender action ongoing.

What: Out-of-bounds write in Chrome V8 engine prior to version 153.0.8010.36, allowing remote arbitrary code execution inside the sandbox via crafted HTML. Medium severity (CVSS unavailable).

Why it matters: KEV-listed as of today with confirmed in-the-wild exploitation by Chinese threat actors (per Volexity). Google shipped patch in Chrome 153 containing 230 fixes including 5 critical vulns. Active defender triage underway across multiple vendors.

Where it's seen: Volexity APT report linking this to chained 0-day campaign; vendor advisories; urgent update messaging across security media and threat intel channels in multiple languages. No standalone PoC code posted, but exploitation already attributed to threat actors.

RISK: HIGH — KEV-listed, in-the-wild exploitation confirmed, mass patching required, sandbox bypass potential.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/9/2026, 8:53:08 PM

Description

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Weaknesses