CVE-2026-87491
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Coverage 2 sources
-
2026-09-09
Help Net Security
medium
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
Google patches actively exploited Chrome zero-day CVE-2026-87491.
-
2026-09-09
CISA Cybersecurity Advisories
high
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog.
Mentioned with
CVE-2025-25249 CVE-2026-19490 CVE-2026-20079
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands