Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Google Chrome V8 Zero-Day Exploited in the Wild: Code Execution Inside Sandbox




Google Chrome V8 Zero-Day Exploited in the Wild: Code Execution Inside Sandbox. A recent security update by Google addressed 230 security vulnerabilities, including a zero-day exploit in V8, allowing a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. The update includes patches for several other zero-day exploits and critical security flaws in various components of the browser. For optimal protection, users are advised to update their Chrome browser to the latest version. This article provides a detailed look at the recent update and its implications for users.

  • Google released a security update on September 9, 2026, patching 230 security vulnerabilities, including a CVE-2026-87491 vulnerability.
  • A remote attacker can execute arbitrary code via a crafted HTML page due to a medium-severity out-of-bounds bug in V8.
  • The vulnerability was discovered by security researcher Jihyeon Jeong of Compsec Lab, Seoul National University, on August 6, 2026.
  • Google acknowledged the existence of an exploit for CVE-2026-87491 but declined to disclose additional information.
  • Google has patched seven actively exploited Chrome zero-days since the start of the year, including CVE-2026-2441.
  • The update also fixes five critical security flaws in WebGL and Cast components.
  • The company attributes many of its security bugs to tools used for detection, including AddressSanitizer and libFuzzer.
  • Users are advised to update their Chrome browser to version 153.0.8010.36/.37 for optimal protection.



  • In a significant security update released by Google on Thursday, September 9, 2026, the tech giant patched 230 security vulnerabilities, including a medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491, which has been actively exploited in the wild. This vulnerability, described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine, allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

    According to a description on the NIST National Vulnerability Database (NVD), the flaw was discovered by security researcher Jihyeon Jeong of Compsec Lab, Seoul National University, on August 6, 2026. Jeong received a $2,500 bug bounty reward for responsible disclosure. Google acknowledged the existence of an exploit for CVE-2026-87491 in the wild but declined to disclose additional specific information related to how the exploit is being weaponized in real-world attacks and by whom.

    This is not the first time Google has addressed a Chrome zero-day vulnerability. Since the start of the year, Google has patched seven actively exploited Chrome zero-days, including CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and CVE-2026-85046. Additionally, the latest update fixes five critical security flaws in WebGL and Cast components.

    Google's efforts to address security vulnerabilities come amid a rising number of zero-day exploits in the wild. The latest update also includes fixes for five critical security flaws in WebGL and Cast components, including CVE-2026-87464 - Use-after-free in WebGL, CVE-2026-87488 - Use-after-free in WebGL, CVE-2026-87438 - Out-of-bounds write in WebGL, CVE-2026-87527 - Buffer overflow in WebGL, and CVE-2026-87628 - Use-after-free in Cast.

    The company attributes many of its security bugs to various tools used for detection, including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL. According to Google, 195 out of the 230 flaws that have been addressed in the update were detected using these tools.

    For optimal protection, users are advised to update their Chrome browser to versions 153.0.8010.36/.37 for Windows and Apple macOS, and 153.0.8010.36 for Linux. To ensure the latest updates are installed, users can navigate to More > Help > About Google Chrome and select Relaunch. Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available.

    The rise of zero-day exploits highlights the need for timely and effective patching of security vulnerabilities. This recent update serves as a reminder to users to stay vigilant and keep their software up to date to prevent falling prey to these types of attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Google-Chrome-V8-Zero-Day-Exploited-in-the-Wild-Code-Execution-Inside-Sandbox-ehn.shtml

  • https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-87491

  • https://www.cvedetails.com/cve/CVE-2026-87491/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-2441

  • https://www.cvedetails.com/cve/CVE-2026-2441/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-3909

  • https://www.cvedetails.com/cve/CVE-2026-3909/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-3910

  • https://www.cvedetails.com/cve/CVE-2026-3910/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-5281

  • https://www.cvedetails.com/cve/CVE-2026-5281/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-11645

  • https://www.cvedetails.com/cve/CVE-2026-11645/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85046

  • https://www.cvedetails.com/cve/CVE-2026-85046/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-87464

  • https://www.cvedetails.com/cve/CVE-2026-87464/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-87488

  • https://www.cvedetails.com/cve/CVE-2026-87488/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-87438

  • https://www.cvedetails.com/cve/CVE-2026-87438/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-87527

  • https://www.cvedetails.com/cve/CVE-2026-87527/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-87628

  • https://www.cvedetails.com/cve/CVE-2026-87628/


  • Published: Wed Sep 9 04:32:21 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us