CVE-2026-87491

8.8 CISA KEV

Google · Chrome

A memory corruption vulnerability in the Google Chrome V8 engine allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

Google Chrome is vulnerable to an out of bounds write flaw in the V8 engine that is currently being actively exploited in the wild.

Vulnerability

This vulnerability involves an out of bounds write in the V8 JavaScript engine (CWE-787). The flaw allows an unauthenticated, remote attacker to execute arbitrary code within the browser sandbox when a user navigates to a specifically crafted HTML page.

Business impact

The ability for a remote attacker to execute arbitrary code on end-user systems poses a significant risk to organizational data integrity and confidentiality. While the CVSS score of 8.8 reflects a High severity, the inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities (KEV) catalog elevates the urgency to critical. Successful exploitation could lead to full system compromise, unauthorized access to sensitive corporate credentials, and potential lateral movement within the network.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to resolve the vulnerable V8 component.

Proactive Monitoring: Review endpoint security logs for unusual browser activity or unexpected child processes originating from the Chrome process tree.

Compensating Controls: Ensure that modern browser security features, such as site isolation and sandboxing, remain enabled, and deploy endpoint protection solutions capable of detecting memory corruption patterns.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The active exploitation of this Chrome vulnerability presents an immediate and severe threat to the organization. IT teams must prioritize the deployment of the 153.0.8010.36 update across all browser installations. Given the risk of remote code execution, failure to patch rapidly increases the likelihood of a successful compromise by threat actors currently leveraging this flaw.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. Added to CISA KEV confirmed active exploitation
  4. CVSS score assigned 8.8 (3.1)
  5. Analyst report written
  6. Published in the daily brief kev section

Sources