ZeroHour

CVE-2026-87489

mass

Memory corruption in V8 in Google Chrome allows sandboxed code execution

CVSS 3.1
8.8 high
EPSS
<1%p14
Published
()
Modified
AI analysis

CVE-2026-87489 is a memory corruption flaw (CWE-119) in the V8 JavaScript engine of Google Chrome, fixed in Chrome 153.0.8010.36. It is triggered remotely when a user loads or runs a crafted Chrome extension, requiring user interaction but no privileges. Successful exploitation could let an attacker execute arbitrary code, but only inside Chrome's renderer sandbox, which limits the blast radius compared with full system compromise. All Google Chrome installations running a version prior to 153.0.8010.36 are affected. Active exploitation of this specific bug is not confirmed: there is no public PoC, it is not in CISA KEV, EPSS is only 0.2%, and Google rates it Low severity (despite the CVSS 8.8 score), although press coverage of the Chrome 153 release separately mentions a zero-day exploited in the wild.

What to do: Upgrade Google Chrome to 153.0.8010.36 or later on all endpoints (via Settings > About Chrome or managed update channels). Because the bug is triggered through a crafted extension, audit installed extensions on high-value systems and restrict untrusted ones. Given Google's Low severity rating and the very low EPSS, treat this as routine patching rather than an emergency.

Affected
google chromeAll versions prior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome runs on roughly 3+ billion devices, nearly all below the 153.0.8010.36 fix) — Chrome holds roughly two-thirds of global browser market share among ~5 billion internet users, implying billions of installations on pre-fix versions, though actual exploitation additionally requires a crafted Chrome extension to be…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs