Zero‑Day V8 Out‑of‑Bounds Write (CVE‑2026‑87491) Enables Code Execution in Chrome Sandbox
What It Is — An out‑of‑bounds write bug in Google Chrome’s V8 JavaScript/WebAssembly engine that allows an attacker to execute native code inside the browser sandbox.
Exploitability — Actively exploited in the wild; Google reports the vulnerability is being used by unknown threat actors. No public proof‑of‑concept is required to trigger the bug.
Affected Products — Google Chrome (all versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous monitoring of third‑party software versions to prove timely remediation.
- Provides audit‑ready evidence that an organization’s vulnerability‑management controls are operating effectively.
- Highlights the importance of documenting patch‑deployment processes as part of a defensible control‑assurance posture.
Recommended Actions
- Deploy Google’s September 2026 Chrome update immediately on all endpoints.
- Verify the installed version (≥ 115.0.XXXX) via automated inventory tools.
- Enable forced automatic updates to reduce exposure to future zero‑days.
- Incorporate browser‑patch status into your continuous compliance monitoring dashboard.
Source: The Hacker News – Chrome V8 Zero‑Day Exploited in the Wild