CuraSec

Act active

Chrome V8 Zero-Day Actively Exploited, Code Execution in Sandbox

2026-09-09 15:05 UTC · The Hacker News · read the source ↗ #chrome#zero-day#rce
  • Engineer — Act: Actively exploited in the wild plus a public PoC makes this urgent despite the low EPSS; update Chrome to the latest release across all managed endpoints and browser fleets immediately.
  • SOC/IR — Plan: No IOCs or TTPs are published yet, but active exploitation warrants tuning EDR rules to flag anomalous child processes spawned from Chrome renderer processes as an exploitation indicator.
  • Leader — Skip
  • Signals: CVE-2026-87491 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.