bleeping-computer · Crawled Sep 9, 2026
Google warns of new Chrome zero-day bug exploited in attacks
4 CVEs
Read original article ↗
AI Summary
Google has patched a new Chrome zero-day vulnerability, CVE-2026-87491, which has been actively exploited in the wild. The vulnerability is a high-severity out-of-bounds write issue in the V8 JavaScript and WebAssembly engine, allowing remote attackers to execute arbitrary code within the browser sandbox by luring users to malicious HTML pages. Exploitation can lead to heap corruption, data exposure, or browser crashes. Google has not disclosed further details about the ongoing attacks to avoid exposing technical details before most users are patched.
AI-extracted · verify before operational use
Extracted Entities 4 found
MITRE ATT&CK TTPs 16 techniques
T1055 Process Injection · Defense Evasion T1189 Drive-by Compromise · Initial Access T1203 Exploitation for Client Execution · Execution T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1204.002 Malicious File · Execution T1566 Phishing · Initial Access