Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [incident, chrome, zero-day, google, kev, blueMoon] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, defence] ยท au_impact: true

Google patched 230 vulnerabilities on Tuesday 8 September 2026, including another actively exploited Chrome zero-day โ€” CVE-2026-87491, an out-of-bounds write in the V8 JavaScript and WebAssembly engine that remote attackers can exploit via crafted HTML pages to execute arbitrary code inside the browser's sandbox. It is the seventh Chrome zero-day exploited in the wild in 2026; the fix (version 153.0.8010.36) began rolling out to Windows, Mac and Linux Stable Desktop channels two days after Seoul National University researcher Jihyeon Jeong reported it. Critically, CVE-2026-87491 is the same WebAssembly flaw at the heart of the "BlueMoon" Chinese-espionage chain, so the patch closes that browser-side window; CISA added the CVE to its KEV catalogue on 9 September.

Attribute Detail
Date Patched 2026-09-08, KEV 2026-09-09
Type Chrome zero-day (V8 OOB write)
CVE CVE-2026-87491
BlueMoon link Same CVE used in Chinese espionage chain
Source BleepingComputer / Google โ€” Tier 2/1

Source