CVE-2026-87491
8.8 CISA KEVGoogle · Chrome
A memory corruption vulnerability in the Google Chrome V8 engine allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
Google Chrome is vulnerable to an out of bounds write flaw in the V8 engine that is currently being actively exploited in the wild.
Vulnerability
This vulnerability involves an out of bounds write in the V8 JavaScript engine (CWE-787). The flaw allows an unauthenticated, remote attacker to execute arbitrary code within the browser sandbox when a user navigates to a specifically crafted HTML page.
Business impact
The ability for a remote attacker to execute arbitrary code on end-user systems poses a significant risk to organizational data integrity and confidentiality. While the CVSS score of 8.8 reflects a High severity, the inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities (KEV) catalog elevates the urgency to critical. Successful exploitation could lead to full system compromise, unauthorized access to sensitive corporate credentials, and potential lateral movement within the network.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to resolve the vulnerable V8 component.
Proactive Monitoring: Review endpoint security logs for unusual browser activity or unexpected child processes originating from the Chrome process tree.
Compensating Controls: Ensure that modern browser security features, such as site isolation and sandboxing, remain enabled, and deploy endpoint protection solutions capable of detecting memory corruption patterns.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The active exploitation of this Chrome vulnerability presents an immediate and severe threat to the organization. IT teams must prioritize the deployment of the 153.0.8010.36 update across all browser installations. Given the risk of remote code execution, failure to patch rapidly increases the likelihood of a successful compromise by threat actors currently leveraging this flaw.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- Added to CISA KEV confirmed active exploitation
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief kev section