CVE-2026-87491
KEV EPSS 0.9%KEV-listed, real exploitation reported, vendor patch live, defender action ongoing.
What: Out-of-bounds write in Chrome V8 engine prior to version 153.0.8010.36, allowing remote arbitrary code execution inside the sandbox via crafted HTML. Medium severity (CVSS unavailable).
Why it matters: KEV-listed as of today with confirmed in-the-wild exploitation by Chinese threat actors (per Volexity). Google shipped patch in Chrome 153 containing 230 fixes including 5 critical vulns. Active defender triage underway across multiple vendors.
Where it's seen: Volexity APT report linking this to chained 0-day campaign; vendor advisories; urgent update messaging across security media and threat intel channels in multiple languages. No standalone PoC code posted, but exploitation already attributed to threat actors.
RISK: HIGH — KEV-listed, in-the-wild exploitation confirmed, mass patching required, sandbox bypass potential.
Description
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)