Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google has released a security update for Chrome to address 230 vulnerabilities, including a zero-day exploit currently being used in the wild. The flaw allows remote attackers to execute arbitrary code within the browser's sandbox.
Why it matters
Active zero-day exploits pose an immediate security risk to millions of users, necessitating urgent software patching.
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.
The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.
"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a description of the flaw on the NIST National Vulnerability Database (NVD).
Security researcher Jihyeon Jeong of Compsec Lab, Seoul National University, has been acknowledged for discovering and reporting the flaw on August 6, 2026. The researcher received a $2,500 bug bounty reward for responsible disclosure.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in