Two Chrome Zero-Days in a Few Days: When Vulnerabilities Become a Pattern

Two Chrome Zero-Days in a Few Days: When Vulnerabilities Become a Pattern

Two Chrome Zero-Days in a Few Days: When Vulnerabilities Become a Pattern

Two actively exploited zero-day vulnerabilities. The same core Chrome component. Just five days between the security updates.

On September 3, Google released a Chrome security update addressing CVE-2026-85046, a high-severity type confusion vulnerability in V8, Chrome’s JavaScript and WebAssembly engine. Google confirmed that an exploit for the vulnerability existed in the wild.

Five days later, another V8 vulnerability entered the spotlight.

On September 8, Google promoted Chrome 153 to the stable channel, addressing 230 security vulnerabilities. Among them was CVE-2026-87491, an out-of-bounds write vulnerability in V8 discovered by Jihyeon Jeong of Compsec Lab at Seoul National University. Google subsequently confirmed active exploitation of the vulnerability.

This was the seventh actively exploited Chrome zero-day addressed in 2026.

Individually, these are two security incidents requiring remediation. Together, their timing and location raise a broader question for security teams: When should vulnerabilities stop being viewed as isolated events and start being considered part of a pattern worth watching?

Two Zero-Days, One Core Component

V8 plays an important role inside Chrome. It is the engine responsible for executing JavaScript and WebAssembly, technologies that power much of the interactive content users encounter online.

That also makes vulnerabilities within V8 particularly relevant from a security perspective. Memory corruption vulnerabilities in a browser engine such as V8 can have serious security implications, particularly when attackers are already exploiting the vulnerability in the wild.

Importantly, this does not mean that exploitation automatically provides an attacker with full control of an endpoint. Chrome uses sandboxing to restrict what renderer processes can access. Further vulnerabilities may therefore be required to escape the sandbox and gain broader access to the underlying system.

Nevertheless, achieving code execution through content delivered by a website can provide an important foothold in an attack chain.

The appearance of two actively exploited V8 vulnerabilities within five days does not prove that they are connected. Google has not publicly attributed them to the same threat actor or campaign. But from a defensive perspective, seeing multiple actively exploited vulnerabilities affecting the same technology in such a short period is still information worth paying attention to.

Severity Does Not Tell the Whole Story

There is another detail about CVE-2026-87491 that makes this case particularly interesting.

Google classified it as Medium severity.

Yet it is being actively exploited.

That highlights an important distinction in vulnerability management. A severity rating helps organizations understand the technical characteristics and potential impact of a vulnerability, but it should not be the only factor determining operational priority.

A critical vulnerability for which there is no known exploitation may represent a very different immediate risk from a medium-severity vulnerability that attackers are already using.

Exploitation status, affected technology, software prevalence and the organization’s actual exposure all add context.

The lesson is not to ignore severity ratings. It is to avoid treating them as the entire picture.

Vulnerability Management Needs Context

For IT and security teams managing hundreds or thousands of endpoints, vulnerabilities can quickly become a stream of CVE numbers, scores and security updates.

The challenge is therefore increasingly about identifying which vulnerabilities require attention now.

This is where accurate vulnerability intelligence and endpoint visibility become important.

SecTeer VulnDetect identifies applications and their exact versions across endpoints and matches this information against SecTeer’s vulnerability and patch management data. Applications can be classified as OK, Insecure, End-of-Life or 0-Day, helping teams understand not simply that a vulnerability exists, but whether their environment is actually affected.

VulnDetect also provides dedicated 0-Day alerting, giving organizations visibility when installed applications are affected by zero-day vulnerabilities.

For organizations managing applications through Microsoft Intune, SecTeer PatchPro extends this process into the existing Intune environment, allowing supported third-party applications and new versions to be published and managed through Intune.

Look Beyond the Individual CVE

The two recent Chrome vulnerabilities are important individually. Their proximity makes them even more interesting together.

They do not prove a coordinated campaign against V8, and security teams should be careful about drawing conclusions that the available evidence does not support.

What they do demonstrate is why vulnerabilities should not always be evaluated in isolation.

Severity tells you something. Active exploitation tells you something else. Multiple zero-days appearing in the same technology within days adds further context.

Effective vulnerability management means bringing those signals together and understanding what they mean for the software actually running across your endpoints.

Want better visibility into zero-day vulnerabilities affecting your environment? See how SecTeer VulnDetect can help your team identify vulnerable applications, prioritize real exposure and respond with the context needed to make faster security decisions.

Comments are closed.