Chromium V8 CVE-2026-87491: Out-of-Bounds Write Exploited — KEV Due Today (September 23)

By George Bailey   Published: 09/22/26   Updated: 09/22/26   2 min read

Today is the federal due date for Chromium’s in-the-wild V8 out-of-bounds write. If your Chrome / Edge / Opera fleet is still below the September stable floor, the clock is not a suggestion — it is today’s calendar.

What happened

CVE-2026-87491 is an out-of-bounds write in Google Chromium V8 that lets a remote attacker execute arbitrary code inside the sandbox via a crafted HTML page. Google stated an exploit exists in the wild and fixed it in Chrome 153.0.8010.36 (Linux) and 153.0.8010.36/.37 (Windows/macOS). CISA added it to KEV on September 9, 2026 with a federal due date of September 23, 2026.

Any Chromium-based browser inherits the engine risk — Chrome, Edge, Opera, and the long tail of Electron shells that lag stable.

Why it matters

Browser drive-bys are still the shortest path from “user clicked a link” to a foothold worth chaining with a local EoP. Seventh Chrome zero-day of 2026 by public count — the pattern is the point. Due-today KEV means auditors and federal partners will ask for proof of version, not good intentions.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.