Out of Bounds Write Vulnerability in Google Chrome
CVE-2026-87491
Key Information:
Badges
What is CVE-2026-87491?
CVE-2026-87491 is an out-of-bounds write vulnerability affecting Google Chrome, specifically in the V8 JavaScript engine used within the browser. This vulnerability arises from insufficient validation of data while processing certain types of input. When exploited, it allows a remote attacker to execute arbitrary code inside the browser's sandboxed environment via a specially crafted HTML page. The implications of this vulnerability are significant for organizations, especially those relying on Google Chrome for web access, as it can potentially enable attackers to execute malicious scripts, manipulate data, or perform unauthorized actions with relative ease.
Given that Google Chrome is widely used across various industries for its speed and extensive functionality, the presence of such a vulnerability highlights a critical risk for both user data and system integrity. Organizations that do not adopt timely security updates may find themselves vulnerable to exploitation, leading to various operational disruptions and financial losses.
Potential impact of CVE-2026-87491
-
Remote Code Execution: The primary risk associated with CVE-2026-87491 is the potential for remote code execution. Attackers can exploit this vulnerability to run arbitrary code on users' systems, which might result in the installation of malware, data theft, or further network infiltration.
-
Data Compromise and Integrity Issues: By executing arbitrary code, attackers could manipulate, steal, or delete sensitive data stored within the browser. This includes personal information, credentials, and business-critical data, ultimately compromising the organization's data integrity and confidentiality.
-
Reputation and Trust Damage: Organizations that fall victim to successful exploits could suffer severe reputational damage. Trust is a critical asset for organizations, and any incident linked to security vulnerabilities can lead to lost customer confidence, impacting long-term business relationships and customer retention.
CISA has reported CVE-2026-87491
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-87491 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Chrome 153.0.8010.36
News Articles
Google Fixes 230 Chrome Vulnerabilities, Including Active Zero-Day
Google has fixed 230 Chrome vulnerabilities, including an actively exploited V8 zero-day that can trigger heap corruption.
5 days ago
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) - Help Net Security
Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit.
5 days ago
Google warns of new Chrome zero-day bug exploited in attacks
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.
5 days ago
References
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 👾
Exploit known to exist
- 🦅
CISA Reported
- 📰
First article discovered by Securityweek
Vulnerability published
Vulnerability Reserved