Chrome Update Fixes 230 Vulnerabilities, Including Actively Exploited Zero-Day Flaw
Google has released an update to Chrome that fixes 230 security vulnerabilities, including one actively exploited in the wild. The bug, tracked as CVE-2026-87491, is a medium-severity flaw affecting V8, Google's open source high-performance JavaScript and WebAssembly engine.
An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome's sandbox. Researcher Jihyeon Jeong from Seoul National University reported the vulnerability on August 6th, 2026, and was rewarded with a $2,500 bounty for responsibly disclosing it.
This is the seventh actively exploited Chrome zero-day of 2026, according to Google. Since the start of the year, Google has addressed several zero-day flaws exploited in attacks in the wild, including CVE-2026-2441 and CVE-2026-85046. The update includes fixes for these vulnerabilities as well.