HomeIntelligenceBrief
VULNERABILITY BRIEF 🟡 Medium Vulnerability

Zero‑Day V8 Out‑of‑Bounds Write (CVE‑2026‑87491) Enables Code Execution in Chrome Sandbox

Google disclosed CVE‑2026‑87491, an out‑of‑bounds write bug in Chrome’s V8 engine that is currently being exploited in the wild. The flaw allows native code execution inside the browser sandbox, underscoring the need for rapid patching and continuous evidence of vulnerability‑management controls.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 thehackernews.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Zero‑Day V8 Out‑of‑Bounds Write (CVE‑2026‑87491) Enables Code Execution in Chrome Sandbox

What It Is — An out‑of‑bounds write bug in Google Chrome’s V8 JavaScript/WebAssembly engine that allows an attacker to execute native code inside the browser sandbox.

Exploitability — Actively exploited in the wild; Google reports the vulnerability is being used by unknown threat actors. No public proof‑of‑concept is required to trigger the bug.

Affected Products — Google Chrome (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous monitoring of third‑party software versions to prove timely remediation.
  • Provides audit‑ready evidence that an organization’s vulnerability‑management controls are operating effectively.
  • Highlights the importance of documenting patch‑deployment processes as part of a defensible control‑assurance posture.

Recommended Actions

  1. Deploy Google’s September 2026 Chrome update immediately on all endpoints.
  2. Verify the installed version (≥ 115.0.XXXX) via automated inventory tools.
  3. Enable forced automatic updates to reduce exposure to future zero‑days.
  4. Incorporate browser‑patch status into your continuous compliance monitoring dashboard.

Source: The Hacker News – Chrome V8 Zero‑Day Exploited in the Wild

📰 Original Source
https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →