
Chrome patches in-the-wild V8 zero-day as part of 230 fixes
Google pushed Chrome updates to fix 230 vulnerabilities, including CVE-2026-87491 — an out-of-bounds write in V8 that has been exploited in the wild to run arbitrary code in the sandbox. The patch, for Windows/macOS versions 153.0.8010.36/37 and Linux 153.0.8010.36, also addresses multiple WebGL and WebPackaging flaws and follows seven actively exploited Chrome zero-days reported this year. Users of Chrome and other Chromium-based browsers should update promptly, noting that some bug details may remain restricted until most users are patched. OpenAI Codex Security is credited for a separate high-severity finding in WebPackaging.












