Google Rapidly Fixes Seventh Zero-Day Vulnerability in Chrome's V8 Engine
Google recently patched its seventh actively exploited zero-day of the year in just two days. The bug, tracked as CVE-2026-87491, is an out-of-bounds write flaw in V8, the JavaScript and WebAssembly engine at the core of every Chrome tab. A malicious or compromised webpage could trigger it to run code inside Chrome's sandbox.
The vulnerability was reported by an external researcher and fixed in Chrome 153.0.8010.36 for Linux and 153.0.8010.36/.37 for Windows and Mac, with the patch shipped just two days after the report.
This is not a one-off incident; four of the seven zero-days this year sit inside V8. Attackers have clearly settled on the engine as their preferred entry point, and they keep finding new corners of it to break.