Google Patches Actively Exploited Chrome Zero-Day: Update Now
Google has issued an urgent update for its Chrome browser, patching 230 security vulnerabilities including one that attackers are already exploiting. The flaw, tracked as CVE-2026-87491, is an out-of-bounds write bug in V8, Chrome's JavaScript and WebAssembly engine. It could allow an attacker to run arbitrary code inside Chrome's sandbox simply by getting a victim to visit a crafted webpage.
Google confirmed it is aware an exploit exists in the wild but has withheld technical details until most users have updated, a standard precaution to prevent wider abuse. This marks the seventh actively exploited Chrome zero-day patched so far this year. The update also fixes five critical flaws in Chrome's WebGL and Cast components, and Google noted it reported the vast majority of the 230 issues itself, with one flaw credited to OpenAI Codex Security.
Businesses relying on Chrome, whether for staff browsing, cloud apps, or customer-facing tools, should treat this as a priority patch. Since exploitation is already occurring, delaying the update increases the window of exposure to attacks that require no more than visiting a malicious webpage.