๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-87491: Google Chromium V8 Out of Bounds Write Vulnerability
Summary
Google Chromium V8 has an out of bounds write vulnerability (a bug where code writes data outside the memory area it's supposed to use), which lets attackers run harmful code inside the browser's sandbox (a restricted environment that limits what code can access) by tricking users into opening a malicious webpage. This affects multiple browsers built on Chromium, including Chrome, Edge, and Opera, and is currently being exploited by attackers.
Solution / Mitigation
Apply mitigations following vendor instructions and CISA's BOD 26-04 guidance for prioritizing security updates based on risk. For cloud services, follow applicable BOD 26-04 guidance or stop using the product if fixes are not available. Organizations must evaluate each system's internet exposure and ensure adherence to BOD 26-04 patching timelines (due date: 2026-09-23). See Chrome releases blog and CISA directives for specific patch information.
Vulnerability Details
EPSS: 0.3%
Yes
๐ฅ Actively Exploited
September 8, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-87491
First tracked: September 9, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%