Google patched 230 vulnerabilities on Tuesday 8 September 2026, including another actively exploited Chrome zero-day โ CVE-2026-87491, an out-of-bounds write in the V8 JavaScript and WebAssembly engine that remote attackers can exploit via crafted HTML pages to execute arbitrary code inside the browser's sandbox. It is the seventh Chrome zero-day exploited in the wild in 2026; the fix (version 153.0.8010.36) began rolling out to Windows, Mac and Linux Stable Desktop channels two days after Seoul National University researcher Jihyeon Jeong reported it. Critically, CVE-2026-87491 is the same WebAssembly flaw at the heart of the "BlueMoon" Chinese-espionage chain, so the patch closes that browser-side window; CISA added the CVE to its KEV catalogue on 9 September.
| Attribute | Detail |
|---|---|
| Date | Patched 2026-09-08, KEV 2026-09-09 |
| Type | Chrome zero-day (V8 OOB write) |
| CVE | CVE-2026-87491 |
| BlueMoon link | Same CVE used in Chinese espionage chain |
| Source | BleepingComputer / Google โ Tier 2/1 |