Junglewise Threat Intelligence

CVE-2026-87489: Google Chrome memory corruption in V8

CVE-2026-87489 · Severity: high · CVSS 8.8 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's V8 JavaScript engine contains a memory corruption vulnerability that could allow attackers to execute arbitrary code within the browser sandbox. An attacker could exploit this by crafting a malicious Chrome extension to trigger the vulnerability, potentially gaining code execution capabilities inside the sandbox environment.

Technical details

A memory corruption vulnerability exists in V8, Google Chrome's JavaScript engine, prior to version 153.0.8010.36. The vulnerability can be triggered via a crafted Chrome extension and allows a remote attacker to potentially achieve arbitrary code execution within the Chrome sandbox. The attack requires social engineering to install the malicious extension. The fix is available in Chrome 153.0.8010.36 and later versions. This vulnerability was assigned a Chromium security severity of Low despite the CVSS score of 8.8, indicating the sandbox mitigates potential real-world impact.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats