logo

Google warns of new Chrome zero-day bug exploited in attacks

ID: 5b96fea3-61d6-574b-85ea-cdb9bf8e6998

STIX ID: report--5b96fea3-61d6-574b-85ea-cdb9bf8e6998

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-09-09

Date Updated: 2026-09-10

Author: Sergiu Gatlan

...
...

Google released security updates addressing 230 vulnerabilities, including an actively exploited high-severity Chrome zero-day (CVE-2026-87491) — an out-of-bounds write in the V8 JavaScript/WebAssembly engine that can enable arbitrary code execution and heap corruption via crafted web pages; patched Stable Desktop versions for Windows, macOS, and Linux have been rolled out while Google restricts full disclosure until most users are updated. The report also lists several other zero-days patched earlier in the year and notes the updates may take days or weeks to reach all users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.