Skip to main content
QUIETLYTIC
Vulnerability

Google Chrome Out-of-Bounds Write (CVE-2026-87491)

CVE-2026-87491, a CVSS 8.8 V8 out-of-bounds write, was added to CISA KEV Sept. 9, 2026 — the second exploited V8 flaw in Chrome within a week.

CVE-2026-87491
Threat Level
HIGH
CVSS
8.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Google Chrome (before 153.0.8010.36), Chromium V8 engine

CVE-2026-87491, a CVSS 8.8 out-of-bounds write in Chromium’s V8 engine, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026 — five days after CVE-2026-85046, a separate V8 type-confusion bug, was added to the same catalog. NVD’s vector matches CVE-2026-85046’s: network-exploitable, requires user interaction, no privileges needed, high impact across confidentiality, integrity, and availability.

What the vulnerability does

NVD tracks CVE-2026-87491 under CWE-787 (Out-of-Bounds Write). Per NVD’s description, the flaw affects V8 in Google Chrome prior to version 153.0.8010.36 and allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. Chromium’s own severity classification, cited in NVD’s reference data, rates the underlying bug “Medium” — notably lower than the CVSS 8.8 NVD assigned, a distinction worth noting explicitly rather than treating the two ratings as interchangeable.

Why it’s on KEV

CISA’s September 9 KEV addition requires federal civilian agencies to remediate under BOD 26-04. As with CVE-2026-85046, “inside the sandbox” in Chromium’s own description means this grants renderer-sandbox code execution, not confirmed host-level compromise on its own.

What we don’t yet have

CVSS scoring and the vulnerability description trace to NVD alone in our pipeline. We’re marking severity confidence medium given the single-source scoring, and specifically flag the CVSS-vs-Chromium-severity discrepancy noted above as unresolved in our data — we don’t have enough evidence to say which rating better reflects real-world risk. No EPSS score is ingested for this CVE yet.

Why this matters

Two independently-tracked V8 memory-safety bugs reaching KEV within the same week is a meaningful signal on its own: it indicates active, ongoing attacker interest in Chromium’s JavaScript engine specifically, not a one-off. Fixed in 153.0.8010.36, one version release later than CVE-2026-85046’s fix (152.0.7977.82) — organizations that patched for the first V8 KEV addition should confirm they’re also current for this second, separate release rather than assuming the earlier update already covered it.

Frequently Asked Questions

What is CVE-2026-87491? A CVSS 8.8 out-of-bounds write in Chromium’s V8 engine (Chrome before 153.0.8010.36) that lets a remote attacker execute code inside Chrome’s sandbox via a crafted HTML page.

Is CVE-2026-87491 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 9, 2026.

Is this the same bug as CVE-2026-85046? No. They’re separate V8 memory-safety flaws (type confusion vs. out-of-bounds write) fixed in different Chrome releases, five days apart on CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 12, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools