Google released Chrome 153 on 8 September with 230 security fixes and wrote that it is aware of an exploit in the wild for CVE-2026-87491. The next day CISA added the vulnerability to its catalog of actively exploited flaws. Other Chromium browsers are affected too.
- CVE-2026-87491: an out-of-bounds write in V8, the engine that runs JavaScript.
- Google rates it Medium, yet it is the only one of the 230 for which it says an exploit exists in the wild.
- The KEV deadline is 23 September; CISA also names Microsoft Edge and Opera as possibly affected.
Medium. That is how Google rated the severity of CVE-2026-87491 in its own list. The same flaw is the only one of 230 for which the company writes that an exploit exists in the wild.
The two don't contradict each other. The rating measures what the flaw can do on its own. The attack shows what someone is already doing with it.
What inside the sandbox means
CISA writes that the code runs inside the browser's sandbox. That sounds reassuring, and to a point it is. The sandbox is the wall that keeps a web page away from the rest of the machine.
But a page that runs code in the sandbox has covered half the distance. The other half is a second flaw that gets through the wall. That is why such bugs are valuable in combination. Google may keep the bug details restricted until a majority of users have updated to the fix.
The good part is that the work here takes two minutes. Chrome updates itself, but until you restart it the old version keeps running. Open the menu, Help, About Google Chrome, and check whether the number starts with 153.
If your office uses Edge or Opera, check those too. CISA's catalog names them, and their updates arrive on their own schedule.