Exploited in the wild Google Chrome zero-day Google web-app
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
CVE Tools coverage
Google has addressed an actively exploited zero-day vulnerability, designated as CVE-2026-87491, within the V8 JavaScript and WebAssembly engine of Chrome. This out-of-bounds write flaw enables remote attackers to execute arbitrary code via specifically crafted HTML pages. The security update is available in Chrome versions 153.0.8010.36 and .37 for Windows and macOS, as well as 153.0.8010.36 for Linux.