Skip to content
GoogleCVE-2026-87491

Google Chrome: out-of-bounds write

High8.8CVE-2026-87491 · Published Sep 9, 2026 · updated Sep 21, 2026

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 153.0.8010.36, < 153.0.8010.36153.0.8010.36
Details and references

More Google advisories

All Google
Advisory
Google cel-go: excessive memory allocation
Medium6.9Sep 9
Google Chrome: clickjacking
Medium5.4Sep 9
Google Chrome: remote attacker could bypass system access restrictions
Medium5.4Sep 9
Google Chrome: use after free
Low3.1Sep 9
Google Chrome: information disclosure
Medium4.3Sep 9
Google Chrome: use after free
Critical9.6Sep 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.