## Overview
CISA added CVE-2026-87491 to its Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026. This addition indicates a federal deadline for remediation. The vulnerability affects the V8 JavaScript engine in Google Chrome and other Chromium-based browsers, including Microsoft Edge and Opera.
## Technical Details
The vulnerability is an out of bounds write issue, which allows a remote attacker to execute arbitrary code within the browser's sandbox. This occurs through a crafted HTML page. The flaw exists in versions of Chromium prior to 153.0.8010.36. Attackers can exploit this vulnerability to bypass security controls and execute malicious scripts.
## Impact
Successful exploitation of CVE-2026-87491 can lead to unauthorized actions within the browser environment. This could result in data theft, system compromise, or further attacks on the user's network. Given the widespread use of Chromium, the impact extends beyond Google Chrome to other browsers that rely on this engine.
## Mitigation
Defenders should immediately update to Google Chrome version 153.0.8010.36 or later. Organizations using Chromium-based browsers should ensure all instances are patched. Regularly monitor for updates and apply security patches promptly to mitigate risks associated with this vulnerability.
CSURFACE Threat Sensor