Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)

2026-09-09T08:51:41Z1d7fae9b2d2de925e1922d83507f0e5fc6ceebc376c6b104eb72ba5c97f72d55
CVE-2026-87491AI securityAI-assisted cyberattacksChrome zero-dayGoogle ChromeV8WeChat wormactively exploited vulnerabilitycloud networkingdata breachout-of-bounds writephishingsecure data deletionthreat intelligencezero-click exploit

What happened

Help Net Security reports that Google patched 230 Chrome vulnerabilities, including actively exploited CVE-2026-87491, a medium-severity out-of-bounds write in the V8 JavaScript/WebAssembly engine. The update also covers AI security tooling and AI-assisted cyberattacks, a zero-click WeChat worm claim, secure-wiping software fixes, breach-and-attack simulation, cloud infrastructure, and phishing risks following a shipping-partner breach.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
1d7fae9b2d2de925e1922d83507f0e5fc6ceebc376c6b104eb72ba5c97f72d55
Enrichment time
2026-09-09T08:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.