Google released an update patching 230 security vulnerabilities in Chrome, including an actively exploited medium-severity zero-day (CVE-2026-87491) in the V8 JavaScript engine that allows remote code execution inside the sandbox via crafted HTML pages. The U.S. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply patches by September 23, 2026, while users and Chromium-based browser operators are urged to update promptly to mitigate attacks.
https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html

