Act
active
Chrome V8 Zero-Day Actively Exploited, Code Execution in Sandbox
- Engineer — Act: Actively exploited in the wild plus a public PoC makes this urgent despite the low EPSS; update Chrome to the latest release across all managed endpoints and browser fleets immediately.
- SOC/IR — Plan: No IOCs or TTPs are published yet, but active exploitation warrants tuning EDR rules to flag anomalous child processes spawned from Chrome renderer processes as an exploitation indicator.
- Leader — Skip
- Signals: CVE-2026-87491 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.