Google fixes Chrome security flaw already being used against users

CVE-2026-87491 hits Chrome's V8 engine, and Chromium-based browsers share the same exposure

|
Published September 09, 2026

Chrome has a new zero-day, and it's already being used against real users. Google shipped Chrome 153 on Tuesday, patching 230 vulnerabilities, including a bug attackers found before Google did.

This vulnerability is an out-of-bounds write issue in the V8, the JavaScript and WebAssembly engine of the Chrome browser, but even though the vulnerability is actively exploited, its severity level is medium according to Google.

An attacker is capable of launching heap corruption through a specially created HTML page that will allow running code within the browser’s sandbox or fetching data from memory that shouldn’t have been accessed.

This vulnerability was reported by Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, on August 6, for which he was rewarded with a $2,500 bounty.

As with past zero-days, Google isn't disclosing how the bug is being exploited in the wild. The company's advisory says technical details stay restricted until most users have updated, and the same restriction applies if the flaw touches a third-party library other projects still haven't patched.

CVE-2026-87491 is the seventh zero-day flaw actively exploited in Chrome that Google has addressed in 2026 after CVE-2026-2441 in February, CVE-2026-3909 and CVE-2026-3910 in March, CVE-2026-5281 in April, CVE-2026-11645, and CVE-2026-85046 this month.

The rate is close to the annual one in 2025 when Google managed to address eight zero-day vulnerabilities for the whole year, most of which were disclosed by the company’s Threat Analysis Group as part of its spyware operability monitoring efforts.

Edge, Brave, and Opera, which use Chromium and have the V8 engine, will probably suffer from the same vulnerability until updates to their software become available.

The updated version of 153.0.8010.36 or .37 is now available; the former is the version that was available at the time of writing, just after Tuesday’s notification.

Pareesa Afreen
Pareesa Afreen is a reporter and sub editor specialising in technology coverage, with 3 years of experience. She reports on digital innovation, gadgets, and emerging tech trends while ensuring clarity and accuracy through her editorial role, delivering accessible and engaging stories for a fast-evolving digital audience.
Share this story: