Google Fixes Seventh Actively Exploited Zero-Day Bug in Chrome
Google has patched another actively exploited Chrome zero-day bug, making it the seventh such vulnerability fixed since the start of the year. The latest bug, CVE-2026-87491, is an out-of-bounds write weakness in the V8 JavaScript and WebAssembly engine that remote attackers can exploit to execute arbitrary code inside the web browser's sandbox.
The company began rolling out patched versions to Windows, Mac, and Linux systems in the Stable Desktop channel two days after a research intern at Seoul National University reported it to Google. The security update could take days or weeks to reach all Chrome users worldwide, but it was available immediately when BleepingComputer checked for updates.
Since the start of the year, Google has addressed five other actively exploited zero-days, including iterator invalidation bugs, out-of-bounds write weaknesses, and use-after-free weaknesses in various components of the browser. The company has yet to share further details about these attacks, saying that access to bug details and links may be kept restricted until a majority of users are updated with a fix.