Skip to content
Auto-CTI
Back to today
NEW HIGH C3

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

C The Hacker News · · CVE-2026-87491

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

EPSS
0%

Key insight

An actively exploited V8 flaw enables code execution within Chrome's sandbox, which could facilitate escalation to system level.

Description

CVE-2026-87491 is an out-of-bounds write in Google's V8 JavaScript engine that allows attackers to execute arbitrary code within Chrome's sandbox via a crafted HTML page. The vulnerability is already being exploited in the wild and was discovered by Jihyeon Jeong of Seoul National University. Google released a patch in Chrome 153.0.8010.36/.37. Chromium-based browsers including Microsoft Edge, Brave, Opera, and Vivaldi are similarly affected and require corresponding updates. Although rated medium severity, active exploitation and sandbox-bypass potential demand immediate attention.

Risk score

17
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00
consensus penalty
-3.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_SKIPPED TTP mapping skipped (placeholder or aggregation article) −3
Consensus penalty:
−3.0
Total penalty:
−3.0
ESC