Chrome patches in-the-wild V8 zero-day as part of 230 fixes

TL;DR Summary
Google pushed Chrome updates to fix 230 vulnerabilities, including CVE-2026-87491 — an out-of-bounds write in V8 that has been exploited in the wild to run arbitrary code in the sandbox. The patch, for Windows/macOS versions 153.0.8010.36/37 and Linux 153.0.8010.36, also addresses multiple WebGL and WebPackaging flaws and follows seven actively exploited Chrome zero-days reported this year. Users of Chrome and other Chromium-based browsers should update promptly, noting that some bug details may remain restricted until most users are patched. OpenAI Codex Security is credited for a separate high-severity finding in WebPackaging.
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox The Hacker News
- Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days Proofpoint
- 4 groups caught using the same Chrome and Windows exploit kit Ars Technica
- Google Chrome Multiple Vulnerabilities Hong Kong Computer Emergency Response Team Coordination Centre
- Google warns of new Chrome zero-day bug exploited in attacks BleepingComputer
Reading Insights
Total Reads
1
Unique Readers
7
Time Saved
2 min
vs 3 min read
Condensed
78%
416 → 91 words
Want the full story? Read the original article
Read on The Hacker News