CVE-2026-87491: high-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
A flaw in Chrome's V8 JavaScript engine allows attackers to write data outside intended memory boundaries through a malicious webpage, potentially enabling code execution within the browser sandbox.
Out-of-bounds write vulnerability in V8 allows remote code execution within the Chrome sandbox via crafted HTML. Attack vector is network-based (malicious webpage), requiring user interaction to visit the page; impact is arbitrary code execution within sandbox confinement.
In the same product, most dangerous first.