ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 2 sources: “Google patches actively exploited Chrome V8 flaw CVE-2026-87491 in Chrome 153 stable update” — merged summary and timeline →

Google security advisory (AV26-904)

highAdvisory exploited in the wildimportance 79CVE-2026-87491
AI summary · glm-5.3-flash

Google patches Chrome CVE-2026-87491, exploited in the wild and added to CISA's KEV; users should update to 153.0.8010.37.

Google released a stable channel desktop update fixing vulnerabilities in Chrome prior to 153.0.8010.37. Google confirmed that an exploit for CVE-2026-87491 exists in the wild, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 9, 2026. The Canadian Centre for Cyber Security issued advisory AV26-904 urging users and administrators to apply the update.

  • Exploit for CVE-2026-87491 confirmed in the wild.
  • CISA added CVE-2026-87491 to the KEV catalog on September 9, 2026.
  • Patch via Chrome stable 153.0.8010.37 or later.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87491
Actively Exploited Out-of-Bounds Write in Google Chrome V8

CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown.

Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching.

8.8<1% KEV
  • Google Chrome (V8 JavaScript engine; tracked by CISA as 'Google Chromium V8') prior to 153.0.8010.36
massbillions of installations (Chrome's install base exceeds 3 billion users)
Full article86 words · extracted from cyber.gc.ca · click to collapse

Serial Number: AV26-904
Date: September 9, 2026

As of September 8, 2026, Google is affected by vulnerabilities in the following product:

  • Chrome
    • Prior to 153.0.8010.37

Google is aware that an exploit for CVE-2026-87491 exists in the wild.

On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87491 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-904