ZeroDayAlert

CVE-2026-87491: Google Chromium V8 Out of Bounds Write Vulnerability

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Google Chromium V8 Added to KEV 2026-09-09 Federal due 2026-09-23 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

This vulnerability affects the V8 JavaScript engine used in Chromium-based web browsers. You are potentially exposed if you deploy or use Google Chrome, Microsoft Edge, Opera, or any other browser built on Chromium. The flaw allows remote code execution within the browser sandbox via a malicious HTML page, meaning any user visiting a compromised or attacker-controlled website could be targeted.

How to check whether this touches you

  • Inventory all web browsers in use across your environment, including corporate standard browsers, development tools, and embedded Chromium instances in applications.
  • Confirm whether affected browsers can reach untrusted internet content—either directly (users browsing the web) or indirectly (rendering user-supplied HTML, PDFs, or email).
  • Check the current Chromium version number in each browser (Chrome: About Chrome, Edge: About Microsoft Edge, Opera: About Opera); version information alone does not confirm whether a patch has been applied, as vendors may backport fixes to older release branches.
  • If you use Chromium embedded in line-of-business applications, contact the application vendor to determine their patching status and timeline.

What to do

  1. Consult Google's official security advisory and your browser vendor's patch release notes to confirm the fixed version for your deployment.
  2. Immediately prioritise patching all Chromium-based browsers across your environment; treat this as a critical update under CISA's BOD 26-04 framework given the remote code execution risk.
  3. If you cannot patch within your required compliance window, restrict or disable browser access to untrusted internet content until a fix is deployed, or discontinue use of the affected product if mitigations are unavailable.
  4. Enable logging of browser crashes, sandbox violations, and any unusual JavaScript engine behaviour if your security tools support it; this may aid detection of exploitation attempts.
  5. If you operate cloud services using Chromium (such as headless rendering or automated testing platforms), apply the same patching timeline and evaluate whether those services need to be taken offline during remediation.

If you find you were exposed

Exploitation of out-of-bounds write vulnerabilities typically occurs before public disclosure, so conduct log-based hunting covering at least the past 90 days for signs of browser crashes, sandbox escapes, or process anomalies on machines that accessed untrusted content. Review web proxy or firewall logs for connections to known malicious sites during the exposure window. If your logging retention is limited, prioritise memory dumps or crash reports from the affected period, as these may contain evidence of exploitation attempts.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-87491 is being exploited. It cannot tell you whether Chromium V8 is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →