Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Cybersecurity · September 10, 2026

Cybersecurity·thehackernews.com

Google's latest Chrome update fixes 230 security bugs, including one attackers were already exploiting in the wild before the patch landed. The flaw, tracked as CVE-2026-87491, is an out-of-bounds write in V8, the engine that runs JavaScript and WebAssembly inside the browser, and can let an attacker execute code inside Chrome's sandbox. Anyone running Chrome should let the update install as soon as it's offered, since Google has confirmed real-world abuse of this bug.

// source: thehackernews.com ↗

Back to Blog