importantSYS.SOURCE: The Hacker News• 2026-09-09T14:41:03+05:30
Google Chrome V8 Zero-Day Exploited in the Wild for Sandbox Code Execution
Google patched a critical V8 zero-day (CVE-2026-87491) exploited in the wild for sandboxed code execution. The update addresses seven actively exploited Chrome zero-days this year, along with other critical flaws in WebGL and Cast components.
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.
The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.
"Out-of-bounds write in V8 in Google Chrome prior to
*** END OF TRANSMISSION ***