CVE
CVE-2026-87491
- First Reported
- Sep 9, 2026
- Latest Reported
- Sep 21, 2026
Reported Context (3)
- the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT) UTA0565 Used Fake Websites to Deliver Chrome and Windows Zero-Day Exploits
- The exploit first gains arbitrary read/write within the V8 sandbox through the Type confusion vulnerability (CVE-2026-85046), then combines a separate WebAssembly defect to escape the V8 sandbox (CVE-2026-87491). Volexity Details Chinese Actors’ Chrome–Windows Exploit Chain Used in Two Espionage Campaigns
- vulnerability in Chromium’s V8 JavaScript engine (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel Local Privilege Escalation (LPE) zero-day present in older Windows builds Multiple State-Aligned Threat Actors Rapidly Adopt BlueMoon Chrome and Windows Exploit Chain
CVE (2)
Malware (6)
People (2)
Threat Actors (7)
MITRE ATT&CK (30)
Vendors (3)
Products (11)
Tools (2)
Industries (10)
Countries (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.