CVE-2026-87491 is a high-impact out-of-bounds memory write vulnerability in the V8 JavaScript and WebAssembly engine powering Google Chrome, Microsoft Edge, Brave, Opera, and the Electron software ecosystem.
Reported on August 6, 2026, by researcher Jihyeon Jeong of the Compsec Lab at Seoul National University, the flaw allows a remote attacker to achieve arbitrary code execution within the browserβs sandboxed renderer process by enticing a victim or autonomous browsing agent to visit a maliciously crafted HTML page. Google confirmed active in-the-wild zero-day exploitation prior to patching. The vulnerability was mitigated in Google Chrome stable release 153.0.8010.36 (Linux/Windows) and 153.0.8010.37 (macOS).