Today is the federal due date for Chromium’s in-the-wild V8 out-of-bounds write. If your Chrome / Edge / Opera fleet is still below the September stable floor, the clock is not a suggestion — it is today’s calendar.
What happened
CVE-2026-87491 is an out-of-bounds write in Google Chromium V8 that lets a remote attacker execute arbitrary code inside the sandbox via a crafted HTML page. Google stated an exploit exists in the wild and fixed it in Chrome 153.0.8010.36 (Linux) and 153.0.8010.36/.37 (Windows/macOS). CISA added it to KEV on September 9, 2026 with a federal due date of September 23, 2026.
Any Chromium-based browser inherits the engine risk — Chrome, Edge, Opera, and the long tail of Electron shells that lag stable.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters
Browser drive-bys are still the shortest path from “user clicked a link” to a foothold worth chaining with a local EoP. Seventh Chrome zero-day of 2026 by public count — the pattern is the point. Due-today KEV means auditors and federal partners will ask for proof of version, not good intentions.
What to do first
- Force-update Chrome/Edge/Opera managed fleets to ≥ 153.0.8010.36/.37 and verify with inventory — not “update available.”
- Block or quarantine endpoints stuck below the fixed build until they check in.
- Audit Electron/Chromium-embedded apps that pin old V8; escalate vendor patches where you cannot self-update.
- Review browser exploit-attempt telemetry and unusual renderer crashes clustered around untrusted sites in the pre-patch window.
Details
- CVE: CVE-2026-87491 (V8 out-of-bounds write; CWE-787)
- Fixed: Chrome 153.0.8010.36 (Linux); 153.0.8010.36/.37 (Windows/macOS)
- KEV: Added 2026-09-09; federal due 2026-09-23 (today); forensic triage No per CISA entry
- Ransomware use (CISA): Unknown
Hunt / verify
- Export browser version inventory; fail closed on anything < 153.0.8010.36.
- Confirm enterprise update policies actually deployed (ring delays can strand high-value users).
- Spot-check Edge and third-party Chromium browsers — Chrome-only dashboards lie.
Sources
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-87491
- https://securityaffairs.com/198757/security/google-fixes-the-seventh-actively-exploited-chrome-zero-day-of-2026.html
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.