Google fixes Chrome security flaw already being used against users
CVE-2026-87491 hits Chrome's V8 engine, and Chromium-based browsers share the same exposure
Chrome has a new zero-day, and it's already being used against real users. Google shipped Chrome 153 on Tuesday, patching 230 vulnerabilities, including a bug attackers found before Google did.
This vulnerability is an out-of-bounds write issue in the V8, the JavaScript and WebAssembly engine of the Chrome browser, but even though the vulnerability is actively exploited, its severity level is medium according to Google.
An attacker is capable of launching heap corruption through a specially created HTML page that will allow running code within the browser’s sandbox or fetching data from memory that shouldn’t have been accessed.
This vulnerability was reported by Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, on August 6, for which he was rewarded with a $2,500 bounty.
As with past zero-days, Google isn't disclosing how the bug is being exploited in the wild. The company's advisory says technical details stay restricted until most users have updated, and the same restriction applies if the flaw touches a third-party library other projects still haven't patched.
CVE-2026-87491 is the seventh zero-day flaw actively exploited in Chrome that Google has addressed in 2026 after CVE-2026-2441 in February, CVE-2026-3909 and CVE-2026-3910 in March, CVE-2026-5281 in April, CVE-2026-11645, and CVE-2026-85046 this month.
The rate is close to the annual one in 2025 when Google managed to address eight zero-day vulnerabilities for the whole year, most of which were disclosed by the company’s Threat Analysis Group as part of its spyware operability monitoring efforts.
Edge, Brave, and Opera, which use Chromium and have the V8 engine, will probably suffer from the same vulnerability until updates to their software become available.
The updated version of 153.0.8010.36 or .37 is now available; the former is the version that was available at the time of writing, just after Tuesday’s notification.
-
Samsung’s latest Apple ad is weirdly friendly
-
iPhone Duo leak spotted hours before Apple ‘Surprise and Shine’ event
-
Anthropic's AI expert spends half her time saying no: Here's why
-
OpenAI’s Navier-Stokes math breakthrough sparks dispute over who gets credit
-
OpenAI deepens Samsung partnership to co-develop AI chips
-
Apple event 2026 leaks: Phone Duo, iPhone 18 Pro Max, Apple Watch 12
-
Anthropic researcher quits with dire warning: ‘Do not underestimate’ superintelligent AI
-
Instagram's ChatGPT '80s photo trend goes viral: Here’s list of prompt to try
-
OpenAI pushes specialized AI into chip design, touts cost advantage over open-source rivals
-
OpenAI claims breakthrough on century-old Navier-Stokes maths problem
-
Irish media regulator opens formal investigation into X over child safety and age assurance controls
-
Google Cloud, Accenture deploy 1,000 AI-engineers directly with customers