In plain language
What this advisory means
A security flaw called CVE-2026-87491 was discovered in the Chromium browser engine, specifically in its V8 JavaScript engine. This flaw can cause a program to write data outside its allowed memory boundaries, which may lead to crashes or allow attackers to run harmful code. Microsoft Edge, which is built on Chromium, has integrated the fix from Chromium to address this issue. An exploit for this vulnerability is known to exist in the wild, so users should update their browsers to the latest version to stay protected.
Technical explanation
How the issue affects the environment
CVE-2026-87491 is an out-of-bounds write vulnerability in the V8 JavaScript engine of Chromium. This type of flaw allows a component to write data beyond the bounds of allocated memory, which can corrupt memory, lead to application crashes, or enable remote code execution. Since Microsoft Edge (Chromium-based) incorporates the Chromium engine, it inherits this vulnerability. The issue is addressed by updating Chromium to a fixed version, which Microsoft has integrated into Edge version 152.0.4191.66 or later. Google has confirmed active exploitation of this vulnerability in the wild.
Operational impact
Why teams should care
This vulnerability poses a significant security risk since it can be exploited to execute arbitrary code on users' systems through a compromised browser. This could lead to unauthorized access, data breaches, or disruptions. Organizations using Microsoft Edge must update to a secure version promptly to mitigate the threat. Failure to update may expose the enterprise to attacks that exploit this flaw.
Immediate action
Update Microsoft Edge (Chromium-based) to version 152.0.4191.66 or later, which includes the integrated fix from Chromium for CVE-2026-87491.
Affected and fixed releases
Temporary risk reduction
No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.
Evidence and validation checklist
- Microsoft Security Response Center advisory confirming integration of Chromium fix in Microsoft Edge 152.0.4191.66.
- Google's statement acknowledging active exploitation of this vulnerability.
- Documentation indicating Edge version 152.0.4191.66 is no longer vulnerable.
- Release notes linking Microsoft Edge updates to fixed Chromium versions.
Authoritative reference
Microsoft Security Response Center
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
