Google warns of new Chrome zero-day bug exploited in attacks
Key Points:
- Google patched 230 vulnerabilities on Tuesday, including an actively exploited Chrome zero-day bug (CVE-2026-87491), marking the seventh such vulnerability patched this year.
- The zero-day flaw involves an out-of-bounds write weakness in Chrome's V8 JavaScript and WebAssembly engine, allowing remote attackers to execute arbitrary code and potentially access sensitive data.
- Patched Chrome versions for Windows, Mac, and Linux were released shortly after the bug was reported by a security researcher from Seoul National University.
- Google is aware of exploits in the wild but has restricted detailed information to prevent widespread attacks until most users update their browsers.
- Since the start of 2026, Google has addressed six other actively exploited Chrome zero-days affecting various components such as CSS font features, the Skia graphics library, and the WebGPU implementation.