Skip to content

CVE-2026-87491: Google Chromium V8 Out-of-Bounds Write Zero-Day to Sandbox RCE

HTS

HERMES THREAT SCORE & OPERATIONAL EXPLOITABILITY

Target: Google Chrome & Chromium V8 Engine (Windows, macOS, Linux, Android)
Confidence: 97%
94 / 100
CRITICAL

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 19 / 20
Threat Activity 20 / 20
Weaponization 19 / 20
Exposure 18 / 20
Prevalence 18 / 20
Impact 18 / 20
Exploit Maturity 20 / 20
Attack Chain Potential 18 / 20
βš–οΈ Divergence & Operational Rationale

While vendor triage classified this vulnerability as Medium severity due to renderer sandbox constraints, Hermes elevates CVE-2026-87491 to 94 (CRITICAL). CISA added this zero-day to the KEV catalog on September 9, 2026, confirming targeted in-the-wild exploitation. Furthermore, autonomous AI agents and developer pipelines increasingly run headless Chromium instances for web browsing, turning client-side memory corruption into an immediate host agent hijacking vector.

HASS

HERMES AGENTIC SECURITY SCORE

Target: Chromium V8 Engine & Headless Agent Browser Automation
Confidence: 94%
86 / 100
HIGH

Measures specific systemic risk arising from autonomy, tool authority, and cascading execution.

Dimension Breakdown
Autonomy 17 / 20
Tool Access 19 / 20
Privilege 13 / 15
Persistence 12 / 15
External Impact 13 / 15
Propagation 12 / 15
βš–οΈ Divergence & Operational Rationale

Autonomous agents equipped with browser tools (e.g., Playwright, Puppeteer, browser-use) navigate external, untrusted web destinations without human validation. Exploitation of CVE-2026-87491 allows malicious webpages to compromise the browser process, hijack the agent's active sessions, and execute arbitrary commands across connected host tools.

πŸ•ΈοΈ Connected Knowledge Graph & Provenance

CVE-2026-87491: Google Chromium V8 Out-of-Bounds Write Zero-Day to Sandbox RCEVULNERABILITY

Connected Nodes: 3
Active Relationships (Outgoing)
→ affectsPRODUCTGoogle Chromium / V8 Engine
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

πŸ” Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Google Chromium / V8 Engine documented in Hermes dossier.”

Supporting Verified Evidence:
→ exploitsAGENTIC ATTACK_PATTERNAAP-007: Autonomous Cascading RCE
92% VERY_HIGH

Cascading multi-stage attack chaining context injection, autonomous loop planning, and un-sandboxed execution sinks to achieve persistent root shell compromise on host machines.

πŸ” Why is this related? (Evidence & Provenance)

“CVE-2026-87491 weaponizes the agentic attack pattern formalized under AAP-007.”

Supporting Verified Evidence:
→ exploitsAGENTIC ATTACK_PATTERNAAP-002: Indirect Context Injection
92% VERY_HIGH

Adversary embeds covert payload instructions into retrieved external data (web pages, repositories, emails) that subvert model planning when parsed by autonomous agents.

πŸ” Why is this related? (Evidence & Provenance)

“CVE-2026-87491 weaponizes the agentic attack pattern formalized under AAP-002.”

Supporting Verified Evidence:

AttributeTechnical SpecificationOperational Impact
CVE IdentifierCVE-2026-87491Universal vulnerability identifier
DiscovererJihyeon Jeong (Compsec Lab, Seoul National University)Bug bounty report ($2,500 reward)
CVSS v3.1 Score8.8 (High)CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
FIRST EPSS Score0.29% (21.44th percentile)Rapidly accelerating following KEV listing
CISA KEV StatusAdded on September 9, 2026Mandatory remediation under BOD 26-04
Vulnerable ComponentGoogle Chromium V8 JavaScript & WebAssembly EngineMemory management / ArrayBuffer backing store
Attack VectorRemote Network (Malicious Webpage / Browser Automation)Requires visiting crafted URL or agent crawl
Downstream ImpactGoogle Chrome, Edge, Brave, Opera, Electron, Node.jsUbiquitous desktop & agent infrastructure

The vulnerability affects all Chromium builds prior to version 153.0.8010.36:

  • Google Chrome (Windows / Linux): Fixed in version 153.0.8010.36 or later;
  • Google Chrome (macOS): Fixed in version 153.0.8010.37 or later;
  • Chromium-based Browsers (Edge, Brave, Opera): Require downstream upstream patches matching Chromium 153 milestone;
  • Electron & Node.js Runtimes: Applications embedding vulnerable V8 versions require rebuilds against updated Chromium releases.

The flaw is classified under CWE-787 (Out-of-bounds Write) inside the memory layout and array buffer indexing logic of the V8 JavaScript engine.

CVE-2026-87491 V8 Out-of-Bounds Write Exploitation Flow:
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 1. Victim Browser / Headless AI Agent β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Navigates to malicious webpage
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 2. Malicious HTML / JavaScript Execution in V8 β”‚
β”‚ β€’ Allocates WebAssembly Memory / TypedArray β”‚
β”‚ β€’ Triggers off-by-one or bound check elimination in JIT β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Out-of-bounds write past allocation boundary
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 3. V8 Isolate Heap Memory Corruption β”‚
β”‚ β€’ Overwrites adjacent ArrayBuffer length or map pointer β”‚
β”‚ β€’ Constructs addrof() & fakeobj() arbitrary R/W primitivesβ”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Arbitrary code execution in renderer
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 4. Renderer Sandbox Compromise & Host Pivoting β”‚
β”‚ β€’ Executes shellcode inside Chrome renderer sandbox β”‚
β”‚ β€’ In agentic workflows: steals API keys & host tool pipesβ”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

In modern V8 architectures, memory allocations for TypedArrays and WebAssembly memory instances are partitioned within the V8 virtual memory cage (V8 Sandbox). During boundary check optimizations in the multi-tier JIT compilation pipeline, the engine performs range analysis to verify that indexed writes remain constrained to the backing store allocated buffer.

In vulnerable builds, a flaw in the index validation routine enables an attacker-controlled calculation to bypass the boundary check. An out-of-bounds write operation transfers controlled byte sequences past the allocated buffer bounds into adjacent heap structures.

  1. Backing Store Corruption: The out-of-bounds write is positioned to overwrite the byte_length and backing_store pointer of an immediately adjacent ArrayBuffer object on the heap.
  2. Arbitrary Memory Primitive: By expanding the adjacent ArrayBuffer size to 0xFFFFFFFF (4 GB) or pointing its backing store to arbitrary memory addresses, the attacker constructs reliable read64() and write64() primitives.
  3. Shellcode Execution: The attacker overwrites JIT-compiled WebAssembly function code or function pointer tables, diverting execution flow to arbitrary shellcode within the renderer process.

Threat actors exploit CVE-2026-87491 through targeted watering hole campaigns and spear-phishing emails delivering links to weaponized web servers. In state-aligned operations, the renderer code execution primitive is chained with a secondary privilege escalation or sandbox escape zero-day (targeting the Windows kernel or Chrome broker process) to execute malware outside the sandbox.

Modern autonomous AI systems frequently employ headless browser toolkits (such as Playwright, Puppeteer, or custom browser agents) to:

  • Conduct autonomous web research;
  • Verify customer support inquiries;
  • Interact with third-party web services and dashboards.

When an autonomous agent navigates to an adversary-controlled page during an automated workflow:

  1. Zero-Click Host Hijacking: The browser tool triggers CVE-2026-87491 without requiring human user interaction.
  2. Context & Credential Harvesting: The attacker accesses the browser session state, harvesting OAuth tokens, session cookies, and local storage.
  3. Cascading Agent Exploitation: Because headless browsers are frequently launched by AI agents with disabled sandbox flags (--no-sandbox or --disable-setuid-sandbox in Docker containers), renderer RCE immediately results in full host container compromise, mirroring the cascading risks documented in AAP-007: Autonomous Cascading RCE.

Investigating systems suspected of encountering CVE-2026-87491 exploitation requires examining browser crash dumps and abnormal child processes:

Terminal window
# 1. Inspect Linux / macOS Chrome crash logs
ls -la ~/.config/google-chrome/Crashpad/reports/
minidump_stackwalk ~/.config/google-chrome/Crashpad/reports/*.dmp
# 2. Check for anomalous child processes spawned by browser processes (Linux)
ps -ef | grep -E "(chrome|chromium|electron)" | grep -v "type="
# 3. Detect --no-sandbox flags in containerized agent configurations
grep -rn "no-sandbox" /etc/docker/ /var/lib/docker/ /home/

Process & Execution Artifacts

  • Chrome renderer crashes logging unhandled memory access exceptions (STATUS_ACCESS_VIOLATION 0xC0000005 on Windows or SIGSEGV on Linux).
  • chrome.exe, msedge.exe, or headless browser instances spawning interactive shells (cmd.exe, powershell.exe, /bin/sh, /bin/bash).

Filesystem & Memory Indicators

  • Suspicious .dmp minidumps generated concurrently with web browsing activity.
  • Unexpected executable or script drops in user temporary directories (%TEMP%, /tmp/).
  • High-volume outbound network connections initiated from browser renderer processes to foreign IPs.

proc_creation_chrome_suspicious_child_process.yml
title: Suspicious Child Process Spawned by Chrome or Chromium Engine
id: 3e8291a4-9214-41d9-8174-bc41f92e1058
status: stable
description: Detects suspicious interactive shells or scripting binaries spawned directly by Google Chrome or Chromium-based processes, indicating renderer sandbox escape or exploit execution.
references:
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
author: Hermes Codex Threat Intelligence
date: 2026-09-09
tags:
- attack.execution
- attack.t1203
- attack.t1059
- cve.2026-87491
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\brave.exe'
- '\opera.exe'
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\rundll32.exe'
condition: selection
falsepositives:
- Rare administrative developer automation tools with explicit shell invoking.
level: critical

  1. Deploy Google Chrome Stable Milestone 153:
    Update Google Chrome across all endpoints:

    • Linux & Windows: Update to version 153.0.8010.36 or later;
    • macOS: Update to version 153.0.8010.37 or later.
  2. Patch Chromium Derivatives & Electron Tooling:
    Ensure Microsoft Edge, Brave, Opera, and developer desktop applications (Cursor, VS Code, Slack) are upgraded to builds incorporating Chromium 153 security fixes.

  3. Harden AI Agent Browser Tool Configurations:
    Review autonomous agent browser launcher configurations:

    • Ban --no-sandbox: Never deploy headless Chrome with --no-sandbox or --disable-web-security flags in automated environments;
    • Container Isolation: Execute agent browser runners within ephemeral, unprivileged Linux namespaces with read-only root filesystems and dropped CAP_SYS_ADMIN capabilities;
    • Egress Filtering: Constrain agent browser traffic through proxy filters restricting access to untrusted, newly registered domains (NRDs).
  4. Audit Agent Interaction Logs:
    Inspect agent execution histories to identify any automated browsing sessions that terminated with unexpected renderer crashes or access violations.