Google Chrome: CVE-2026-87491 V8 Zero-Day Enables Arbitrary Code Execution
Google has patched CVE-2026-87491, a critical out-of-bounds (OOB) write vulnerability in the V8 JavaScript and WebAssembly engine, following reports of active exploitation in the wild. Threat actors are leveraging this zero-day to achieve arbitrary code execution (ACE) via malicious web content or specifically crafted WebAssembly payloads. Intelligence indicates Chinese-linked APTs are integrating this flaw into multi-stage exploit chains designed to bypass Windows security controls and facilitate full system compromise. Immediate remediation is required by updating Google Chrome to version 153.0.8010.36/37 across Windows, macOS, and Linux to mitigate the risk of remote exploitation and subsequent host-level persistence.
Google Chrome Emergency Patch: CVE-2026-85046 Zero-Day in V8 Engine
Google has issued an emergency security update to address CVE-2026-85046, a critical type confusion vulnerability within the V8 JavaScript and WebAssembly engine. This zero-day flaw has been actively exploited in the wild by at least four China-linked cyber-espionage groups to facilitate remote code execution (RCE). By delivering malicious web-based payloads, attackers can bypass security boundaries to execute arbitrary code on the host system. Given the vulnerability's impact on approximately 3 billion Chrome installations, immediate remediation is essential. Organizations must deploy Chrome version 152.0.7977.82 or later to mitigate the risk of unauthorized system compromise and intelligence theft.
Critical Active Exploitation of Google Chromium V8 Engine Sandbox Escape
Active exploitation of CVE-2026-85046 in the Google Chromium V8 JavaScript engine allows for remote code execution (RCE) and a complete sandbox escape. The vulnerability leverages memory corruption—specifically type confusion or use-after-free flaws—to establish out-of-bounds (OOB) read/write primitives. By bypassing the Chromium multi-process security architecture through manipulated Inter-Process Communication (IPC), attackers can elevate privileges from the restricted renderer process to the host operating system. This critical flaw affects all Chromium-based browsers and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Immediate remediation requires updating to version 149.0.7827.102.103 for Windows/macOS or 149.0.7827.102 for Linux.