thehackernews.com·4 min read·hard

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

T
The Hacker News
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
AI Summary

Google has released a security update for Chrome to address 230 vulnerabilities, including a zero-day exploit currently being used in the wild. The flaw allows remote attackers to execute arbitrary code within the browser's sandbox.

Why it matters

Active zero-day exploits pose an immediate security risk to millions of users, necessitating urgent software patching.

Dive DeeperCreate a free account to unlock

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.

The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.

"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a description of the flaw on the NIST National Vulnerability Database (NVD).

Security researcher Jihyeon Jeong of Compsec Lab, Seoul National University, has been acknowledged for discovering and reporting the flaw on August 6, 2026. The researcher received a $2,500 bug bounty reward for responsible disclosure.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in