CVE-2026-87491, a CVSS 8.8 out-of-bounds write in Chromium’s V8 engine, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026 — five days after CVE-2026-85046, a separate V8 type-confusion bug, was added to the same catalog. NVD’s vector matches CVE-2026-85046’s: network-exploitable, requires user interaction, no privileges needed, high impact across confidentiality, integrity, and availability.
What the vulnerability does
NVD tracks CVE-2026-87491 under CWE-787 (Out-of-Bounds Write). Per NVD’s description, the flaw affects V8 in Google Chrome prior to version 153.0.8010.36 and allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. Chromium’s own severity classification, cited in NVD’s reference data, rates the underlying bug “Medium” — notably lower than the CVSS 8.8 NVD assigned, a distinction worth noting explicitly rather than treating the two ratings as interchangeable.
Why it’s on KEV
CISA’s September 9 KEV addition requires federal civilian agencies to remediate under BOD 26-04. As with CVE-2026-85046, “inside the sandbox” in Chromium’s own description means this grants renderer-sandbox code execution, not confirmed host-level compromise on its own.
What we don’t yet have
CVSS scoring and the vulnerability description trace to NVD alone in our pipeline. We’re marking severity confidence medium given the single-source scoring, and specifically flag the CVSS-vs-Chromium-severity discrepancy noted above as unresolved in our data — we don’t have enough evidence to say which rating better reflects real-world risk. No EPSS score is ingested for this CVE yet.
Why this matters
Two independently-tracked V8 memory-safety bugs reaching KEV within the same week is a meaningful signal on its own: it indicates active, ongoing attacker interest in Chromium’s JavaScript engine specifically, not a one-off. Fixed in 153.0.8010.36, one version release later than CVE-2026-85046’s fix (152.0.7977.82) — organizations that patched for the first V8 KEV addition should confirm they’re also current for this second, separate release rather than assuming the earlier update already covered it.
Frequently Asked Questions
What is CVE-2026-87491? A CVSS 8.8 out-of-bounds write in Chromium’s V8 engine (Chrome before 153.0.8010.36) that lets a remote attacker execute code inside Chrome’s sandbox via a crafted HTML page.
Is CVE-2026-87491 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 9, 2026.
Is this the same bug as CVE-2026-85046? No. They’re separate V8 memory-safety flaws (type confusion vs. out-of-bounds write) fixed in different Chrome releases, five days apart on CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 12, 2026. See more vulnerability intelligence.