Google warns of new Chrome zero-day bug exploited in attacks

by · BleepingComputer

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.

"Google is aware that an exploit for CVE-2026-87491 exists in the wild," the company said in a Tuesday security advisory.

The company began rolling out patched versions to Windows (153.0.8010.36), Mac (153.0.8010.37), and Linux (153.0.8010.36) systems in the Stable Desktop channel two days after Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported it to Google.

Google says the security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates earlier today.

Those who prefer not to update manually can rely on Chrome to automatically check for updates and install them at the next launch.

​This high-severity zero-day vulnerability (CVE-2026-87491) stems from an out-of-bounds write weakness in the Chrome V8 JavaScript and WebAssembly engine, which remote attackers can exploit to execute arbitrary code inside the web browser's sandbox via crafted HTML pages.

Successful exploitation can also let them access data beyond the memory buffer through heap corruption, exposing sensitive information or triggering a crash.

While Google said it was aware of CVE-2026-87491 zero-day exploits used in the wild, the company has yet to share further details about these attacks.

"Access to bug details and links may be kept restricted until a majority of users are updated with a fix," Google said. "We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed."

Since the start of the year, Google addressed five more actively exploited zero-days:

  • An iterator invalidation bug (CVE-2026-2441) in CSSFontFeatureValuesMap (Chrome's implementation of CSS font feature values), which Google addressed in mid-February.
  • Two other Chrome zero-day bugs exploited in attacks in March: an out-of-bounds write weakness in the Skia 2D graphics library (CVE-2026-3909), and an inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine (CVE-2026-3910).
  • A use-after-free weakness in Dawn (CVE-2026-5281), the underlying cross-platform implementation of the WebGPU standard used by the Chromium project, which Google patched in April.
  • And a type confusion flaw in V8 (CVE-2026-85046) fixed earlier this month.

Google fixed eight other zero-days exploited in the wild in 2025, many of them reported by its Threat Analysis Group (TAG), known for tracking zero-day exploits used in spyware attacks.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report