High CVE-2026-85046, CVE-2026-87491 — Two exploited V8 bugs let a malicious web page run code in Chrome and every Chromium browser on Windows, macOS, Linux, and Android. Fixed Chrome versions and how to update Edge, Brave, and Opera.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Visiting a malicious or compromised web page could run attacker code in your browser. Google fixed two actively exploited V8 JavaScript-engine bugs within a week in September. Make sure Chrome is at 153.0.8010.36 or later, and restart it. Edge, Brave, Opera, and Vivaldi share the engine and need their own updates.
| CVE-2026-85046 | V8 type confusion · fixed in Chrome 152.0.7977.82 · KEV 2026-09-04 |
|---|---|
| CVE-2026-87491 | V8 out-of-bounds write · fixed in Chrome 153.0.8010.36 · KEV 2026-09-09 |
| Trigger | Just loading a crafted HTML page; no download or click needed |
| Impact | Code execution inside the browser sandbox |
| Platforms | Every OS Chrome runs on: Windows, macOS, Linux, ChromeOS, Android |
| Also affects | Chromium-based browsers: Microsoft Edge, Brave, Opera, Vivaldi, Arc |
V8 is the engine that runs JavaScript in Chrome and every other Chromium-based browser. In early September Google shipped two emergency fixes for V8 bugs it said were being exploited:
Either one lets a web page run code inside the browser’s sandbox. Attackers usually pair a V8 bug like this with a second “sandbox escape” bug to take over the whole computer, and these chains are often delivered through compromised legitimate sites or malicious ads.
chrome://settings/help. You need 153.0.8010.36 or later.edge://settings/helpbrave://settings/help · Opera: opera://updategoogle-chrome --version or chromium --versionChrome downloads updates on its own but only applies them when you restart the browser. People who never close Chrome can sit on a vulnerable version for weeks. Open the settings/help page above; it will download the update and show a Relaunch button. Click it.
Linux:
# Debian/Ubuntu with Google's repo
sudo apt update && sudo apt install --only-upgrade google-chrome-stable
# Fedora
sudo dnf upgrade google-chrome-stable
# Flatpak
flatpak update
Businesses: use Chrome or Edge group policy (RelaunchNotification and RelaunchNotificationPeriod) to force a relaunch within a day or two of an update, so a forgotten browser window doesn’t stay vulnerable for weeks.
These weren’t Chrome’s first exploited V8 bugs of the summer. In June, Google fixed CVE-2026-11645, an out-of-bounds read/write in V8 (Chromium severity High) that also allowed code execution inside the sandbox from a crafted page, fixed in Chrome 149.0.7827.103 and added to CISA’s exploited list on 2026-06-09. Any Chrome at 153.0.8010.36 or later includes that fix too.
These two bugs are in V8, which Firefox (SpiderMonkey) and Safari (JavaScriptCore) don’t use, so they’re not affected by these CVEs. Keep them updated anyway. Every browser engine gets zero-days.
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.