“Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page,” reads a description of the flaw on the NIST National Vulnerability Database (NVD).
Security researcher Jihyeon Jeong of Compsec Lab, Seoul National University, has been acknowledged for discovering and reporting the flaw on August 6, 2026. The researcher received a $2,500 bug bounty reward for responsible disclosure.
Google acknowledged it is “aware that an exploit for CVE-2026–87491 exists in the wild,” but has not disclosed any additional specific information related to how it’s being weaponized in real-world attacks and who is behind them.
