LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
CVE-2026-87491high

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

zeroday.news ·

Google has reportedly issued an urgent update for its Chrome browser, addressing a critical zero-day vulnerability that has been actively exploited in the wild. The flaw, identified as an out-of-bounds write bug within the V8 JavaScript and WebAssembly engine, allows for code execution within the browser's sandbox environment. This update is part of a broader patch release addressing numerous security issues.

The vulnerability, designated CVE-2026-87491, is described as an out-of-bounds write in V8. This class of flaw typically occurs when a program attempts to write data beyond the allocated memory buffer, potentially overwriting adjacent memory regions. In the context of a JavaScript engine like V8, such an exploit could allow an attacker to manipulate program control flow or inject malicious code, leading to arbitrary code execution.

Specifically, an out-of-bounds write in a JavaScript engine can be leveraged to achieve memory corruption. Attackers often craft malicious web pages that, when visited, trigger this memory corruption. By carefully controlling the overwritten data, an attacker can achieve various objectives, such as bypassing security checks, escalating privileges, or executing arbitrary code within the context of the browser process.

While the vulnerability is described as enabling code execution inside the sandbox, it is important to note the implications. The sandbox is a critical security mechanism designed to isolate browser processes from the rest of the operating system, limiting the damage an exploit can cause. However, successful code execution within the sandbox still represents a significant compromise, as it could be a precursor to a sandbox escape, which would then allow the attacker to execute code on the underlying operating system.

Products in the web browser category, particularly those with complex JavaScript engines, are frequently targeted for these types of memory safety vulnerabilities. The V8 engine, being open-source and widely used in Chrome and other Chromium-based browsers, makes it a high-value target for attackers seeking broad impact. The active exploitation in the wild indicates that attackers have developed reliable methods to trigger and leverage this specific flaw.

Mitigation for this class of vulnerability typically involves prompt application of vendor-supplied patches. Users are strongly advised to update their Chrome browsers immediately to the latest version to protect against active exploitation. Additionally, general security practices such as exercising caution when visiting untrusted websites and using robust endpoint security solutions can help reduce overall risk.

The discovery and active exploitation of this zero-day underscore the continuous threat landscape faced by modern web browsers. Even with sophisticated sandboxing and security features, critical vulnerabilities can emerge and be weaponized quickly. This incident highlights the ongoing cat-and-mouse game between security researchers, software vendors, and malicious actors, emphasizing the critical importance of rapid patching and user vigilance in maintaining digital security.

vulnerabilities in this storyCVE-2026-87491
vulnerabilityzero-daypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.