CVE Tools
Back to feed
Exploited in the wild Google Chrome zero-day Google web-app

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Google has released security updates for Chrome, addressing 230 vulnerabilities including a medium-severity out-of-bounds bug in the V8 engine that is currently being exploited in the wild. Identified as CVE-2026-87491, this flaw allows remote attackers to execute arbitrary code within the sandbox via crafted HTML content in versions prior to 153.0.8010.36.
The update also resolves five critical flaws in WebGL and Cast components, bringing the total number of actively exploited Chrome zero-days patched this year to seven. Users are strongly advised to upgrade to version 153.0.8010.36/.37 on Windows and macOS, or 153.0.8010.36 on Linux, to mitigate these risks.