Google warns of new Chrome zero-day bug exploited in attacks

Google has just patched a seventh Chrome zero-day bug this year, with another high-severity vulnerability being actively exploited by attackers. The latest bug, CVE-2026-87491, affects the V8 JavaScript and WebAssembly engine in Google’s Chrome browser, allowing remote attackers to execute arbitrary code inside the web browser’s sandbox via crafted HTML pages.

The security update was made available on Tuesday, just two days after a research intern at Seoul National University’s Compsec Lab reported the bug to Google. The company has begun rolling out patched versions of Chrome for Windows, Mac, and Linux systems in the Stable Desktop channel, but it may take several days or weeks for all users worldwide to receive the update. Those who prefer not to wait can rely on Chrome to automatically check for updates and install them at the next launch.

The CVE-2026-87491 bug is particularly concerning because it stems from an out-of-bounds write weakness in the V8 engine, which allows attackers to access data beyond the memory buffer through heap corruption. This could expose sensitive information or trigger a crash on the affected system. While Google has acknowledged that CVE-2026-87491 zero-day exploits are being used in attacks, it has yet to share further details about these attacks.

This is just the latest in a string of high-profile Chrome zero-day bugs patched by Google this year. Since January 2026, the company has addressed five other actively exploited zero-days, including iterator invalidation and out-of-bounds write weaknesses in various parts of the browser’s codebase. These types of vulnerabilities often allow attackers to execute malicious code on a victim’s device, making them a significant concern for security professionals.

It’s worth noting that Google’s Threat Analysis Group (TAG) has been tracking these zero-day exploits used in spyware attacks and has previously identified 8 other such vulnerabilities exploited in the wild last year. The fact that multiple high-severity bugs have been discovered in Chrome this year highlights the ongoing challenge of keeping software up to date with the latest security patches.

For users, it’s essential to prioritize timely updates and patching of their browsers and operating systems to prevent exploitation by attackers. Google has already begun rolling out the patched version of Chrome, and users can check for updates manually or rely on the browser to automatically download and install them at the next launch.


Source: Bleeping Computer — 2026-09-09