The Bug Google Calls Medium

On September 8, Google promoted Chrome 153 to the stable channel for Windows, Mac and Linux and quietly closed CVE-2026-87491, an out-of-bounds write in V8, the engine that runs every script on every page a Chrome user opens. In the same release notes, Google's own security team wrote the sentence that actually matters: "Google is aware that an exploit for CVE-2026-87491 exists in the wild." A specially crafted web page is enough to trigger it, and a successful hit lets an attacker run arbitrary code inside the browser sandbox.

Look at the severity column next to the CVE, though, and Chromium's own bug tracker rates it Medium. Not Critical, not even High. The researcher who found and reported it, Jihyeon Jeong of Compsec Lab at Seoul National University, was paid a $2,500 bounty, a mid-tier reward that matches the mid-tier label. Nothing about the fix itself signals urgency. Everything about how it was being used does.

Why CISA Disagrees With The Label

The US Cybersecurity and Infrastructure Security Agency does not rate bugs by how bad they could theoretically be. It runs one list, the Known Exploited Vulnerabilities catalog, and the only thing that gets a CVE onto it is evidence that someone is already using it against real targets. CVE-2026-87491 is on that list now, filed under Google, Chromium V8, with a remediation due date of September 23, 2026, fifteen days after the patch shipped.

That fifteen-day clock is a US federal civil executive branch requirement, not an EU one, so it binds no Servola reader directly. What it does is something more useful than a legal mandate: it is a second, independent signal, built entirely from exploitation evidence rather than a vendor's own scoring, and it landed on a bug that Chromium's own tracker still calls Medium. When the two disagree this sharply, the KEV listing is the one that reflects what is actually happening on the internet right now.

Four Zero-Days, One Engine

CVE-2026-87491 is not an isolated incident. It is the seventh Chrome zero-day Google has confirmed under active exploitation in 2026, and it landed just four days after the sixth, CVE-2026-85046, another V8 flaw patched on September 3. Four of this year's seven confirmed zero-days sit specifically inside V8, the JavaScript and WebAssembly engine that Chrome, Edge, Opera, Brave and every other Chromium-based browser share.

That concentration is not a coincidence of what happened to get reported this year. V8 is one of the most heavily fuzzed, most heavily rewarded pieces of code in the browser, which means attackers who do find something in it get a component that runs on effectively every desktop and phone on the planet, not a niche feature a fraction of users have enabled. Four hits in one engine inside nine months reads less like bad luck and more like attackers have settled on where the highest-value work is.

What This Means For An EU Security Team

Most vulnerability management programs still triage by vendor severity first and exploitation status second, if they check it at all. This bug is the argument against that order. A team that patches Critical and High immediately and lets Medium sit in the next maintenance window would have left CVE-2026-87491 open for weeks while it was already being used, because the label told them it could wait.

The fix itself costs nothing beyond the standard patch cycle: Chrome auto-updates to 153.0.8010.36 or later on most managed and unmanaged machines within days, and confirming the version number under Chrome's About page settles it. The more durable change is procedural. NIS2's expectation of state-of-the-art vulnerability handling is easier to meet by pulling the CISA KEV feed directly into a patch-priority queue than by trusting a vendor's own severity tier to catch every actively exploited bug before it does damage, because this one shows that tier does not.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.