• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-87491: remote code execution in Google Chromium V8

Remote attackers can execute arbitrary code in Chromium V8 by delivering a crafted HTML page that triggers an out-of-bounds write, enabling code execution inside the renderer sandbox. CVE-2026-87491 affects Chromium V8 153.x prior to 153.0.8010.36; the issue is fixed in 153.0.8010.36. Exploitation requires a user to load a malicious page (user interaction) and only network access to deliver that page.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.03142
CWE
CWE-787
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added this defect to the Known Exploited Vulnerabilities catalog on 2026-09-09 with a federal remediation deadline of 2026-09-23, and public exploit code is available, so prioritize applying the vendor fix immediately.

What is CVE-2026-87491?

Remote attackers can execute arbitrary code in Chromium V8 by delivering a crafted HTML page that triggers an out-of-bounds write, enabling code execution inside the renderer sandbox. CVE-2026-87491 affects Chromium V8 153.x prior to 153.0.8010.36; the issue is fixed in 153.0.8010.36. Exploitation requires a user to load a malicious page (user interaction) and only network access to deliver that page. The weakness is classified as CWE-787 (Out-of-bounds Write).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Google Chromium V8 are affected?

BRANCHAFFECTEDFIXED
153.x153.0.8010.36 – before 153.0.8010.36153.0.8010.36

Is CVE-2026-87491 being exploited?

CISA added CVE-2026-87491 to the Known Exploited Vulnerabilities catalog on 2026-09-09; U.S. federal agencies were required to mitigate it by 2026-09-23. Public exploit code for the vulnerability is available.

How to fix CVE-2026-87491

  1. Upgrade Chromium-based products to the fixed build 153.0.8010.36.
  2. If immediate upgrade is not possible, follow vendor mitigations and restrict exposure of affected browsers to untrusted sites.
  3. Monitor browser crash logs and network traffic for signs of exploitation and block known malicious payloads.
  4. Apply vendor guidance and validate updates across managed endpoints as part of patching workflows.

Frequently asked questions

Is CVE-2026-87491 being actively exploited?

CISA added CVE-2026-87491 to its Known Exploited Vulnerabilities catalog on 2026-09-09 and public exploit code is available, indicating high risk and a federal remediation deadline of 2026-09-23.

Which Chromium V8 versions are affected by CVE-2026-87491?

Chromium V8 153.x builds prior to 153.0.8010.36 are affected; the issue is fixed in 153.0.8010.36.

Is there a patch for CVE-2026-87491?

Yes. The vulnerability is fixed in Chromium V8 build 153.0.8010.36; update affected browsers to that build or later.

Does CVE-2026-87491 require authentication?

No authentication is required; exploitation is achieved by convincing a user to open a crafted HTML page (user interaction is required).

References