type: cve ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [cve, chrome, webassembly, sandbox-escape, patch-gap] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology] ยท au_impact: true
CVE-2026-87491 is a WebAssembly defect in Google Chrome used as the second stage of the "BlueMoon" exploit chain: after the V8 type-confusion flaw (CVE-2026-85046) provides arbitrary read/write within the V8 sandbox, this bug is combined with a Windows kernel vulnerability (CVE-2026-85880) to escape Chrome's V8 sandbox entirely and escalate to code execution in the browser process. It is one of three chained zero-days used byte-for-byte identically by multiple Chinese-linked espionage groups, indicating shared supply or brokering of the exploit.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-87491 |
| Type | WebAssembly sandbox escape |
| Exploited | In the wild (Chrome zero-day, AugโSep 2026) |
| Chain | CVE-2026-85046 + CVE-2026-87491 + CVE-2026-85880 |
| Source | Volexity โ Tier 1/4 |