DIRAS TAKE
Urgent — CISA added this defect to the Known Exploited Vulnerabilities catalog on 2026-09-09 with a federal remediation deadline of 2026-09-23, and public exploit code is available, so prioritize applying the vendor fix immediately.
What is CVE-2026-87491?
Remote attackers can execute arbitrary code in Chromium V8 by delivering a crafted HTML page that triggers an out-of-bounds write, enabling code execution inside the renderer sandbox. CVE-2026-87491 affects Chromium V8 153.x prior to 153.0.8010.36; the issue is fixed in 153.0.8010.36. Exploitation requires a user to load a malicious page (user interaction) and only network access to deliver that page. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Google Chromium V8 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 153.x | 153.0.8010.36 – before 153.0.8010.36 | 153.0.8010.36 |
Is CVE-2026-87491 being exploited?
CISA added CVE-2026-87491 to the Known Exploited Vulnerabilities catalog on 2026-09-09; U.S. federal agencies were required to mitigate it by 2026-09-23. Public exploit code for the vulnerability is available.
How to fix CVE-2026-87491
- Upgrade Chromium-based products to the fixed build 153.0.8010.36.
- If immediate upgrade is not possible, follow vendor mitigations and restrict exposure of affected browsers to untrusted sites.
- Monitor browser crash logs and network traffic for signs of exploitation and block known malicious payloads.
- Apply vendor guidance and validate updates across managed endpoints as part of patching workflows.
Frequently asked questions
Is CVE-2026-87491 being actively exploited?
CISA added CVE-2026-87491 to its Known Exploited Vulnerabilities catalog on 2026-09-09 and public exploit code is available, indicating high risk and a federal remediation deadline of 2026-09-23.
Which Chromium V8 versions are affected by CVE-2026-87491?
Chromium V8 153.x builds prior to 153.0.8010.36 are affected; the issue is fixed in 153.0.8010.36.
Is there a patch for CVE-2026-87491?
Yes. The vulnerability is fixed in Chromium V8 build 153.0.8010.36; update affected browsers to that build or later.
Does CVE-2026-87491 require authentication?
No authentication is required; exploitation is achieved by convincing a user to open a crafted HTML page (user interaction is required).
References
- nvd.nist.gov/vuln/detail/CVE-2026-87491
- cve.org/CVERecord?id=CVE-2026-87491
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87491
- chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
- issues.chromium.org/issues/543557673
- All Google CVEs on CVE Radar
- CVEs published in September 2026