Executive brief
Google Chromium's V8 JavaScript engine contains an out-of-bounds memory write vulnerability that allows attackers to execute arbitrary code within the browser sandbox by serving a crafted web page. This affects all major Chromium-based browsers including Chrome, Microsoft Edge, and Opera, potentially compromising user security and data when visiting malicious websites.
Technical details
CVE-2026-87491 is an out-of-bounds write vulnerability in the V8 JavaScript engine that powers Google Chromium and all Chromium-derived browsers. The vulnerability is triggered through a specially crafted HTML page delivered over the network, requiring only that a user visits a malicious website. An attacker can exploit this to achieve arbitrary code execution within the browser's sandbox environment. This vulnerability has been observed being actively exploited in the wild, indicating real-world attack campaigns. Patch availability and version information should be obtained from the vendor's security advisories.
Affected products
- Google Chromium multiple versions
- Google Chrome multiple versions
- Microsoft Edge multiple versions
- Opera Opera Browser multiple versions
Timeline
- 2026-09-09: disclosed
- exploited: Actively exploited in the wild