Google Chrome V8 Out-of-Bounds Write Zero-Day – Actively Exploited (CVE-2026-87491)

Release Date: 9th September 2026 (Added 10 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to all users of Google Chrome, including Organizations, System/Network administrators, and members of the general public who browse the web on a Windows, macOS, or Linux device. This alert is intended to be understood by both technical and general readers, and requires urgent action given confirmed active exploitation.

What is it?

CVE-2026-87491 is an out-of-bounds write vulnerability in V8, the JavaScript and WebAssembly engine at the core of Google Chrome and every Chromium-based browser, allowing a remote attacker to execute arbitrary code inside Chrome's sandbox simply by getting a victim to open a specially crafted HTML page. This is the seventh actively-exploited Chrome zero-day patched in 2026.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-87491
  2. https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html