September 22, 2026

CVE-2026-87491 - Remote Code Execution Vulnerability

high-severity security vulnerability

Lookout Coverage and Recommendation for Admins

Lookout will release security coverage for CVE-2026-87491 and CVE-2026-85046 on September 23, 2026. This release was prioritized due to active in-the-wild exploitation, high CVSS severity, and the broad deployment of Chromium browsers across enterprise endpoints. Upon deployment, the platform will automatically trigger alerts and remediation workflows aligned with each organization’s configured risk thresholds and escalation policies.

To ensure mobile endpoints are protected, Lookout administrators should take the following actions in the Lookout console:

  • Enable Application Vulnerability Policies: Configure vulnerability detection policies to identify all devices running unpatched versions of Google Chrome (below 153.0.8010.36) and Microsoft Edge (below 152.0.4191.65). Set policy severity to High and enforce conditional access policies to block access to corporate data until updates are applied.
  • Remediate Application Versions: Ensure Google Chrome and Microsoft Edge browser applications are updated to patched builds across mobile and desktop endpoints via the Google Play Store, Apple App Store, or enterprise EMM/MDM portal.
  • Enable Lookout Phishing & Content Protection (PCP): Activate PCP across all enrolled endpoints to inspect and block malicious web links, phishing campaigns, and vector URLs designed to trigger browser exploit chains.

Overview 

Google has disclosed multiple zero-day security vulnerabilities affecting Chromium-based browsers: CVE-2026-87491 and CVE-2026-85046.

  • CVE-2026-87491: An out-of-bounds write vulnerability in the V8 JavaScript and WebAssembly engine.
  • CVE-2026-85046: A high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine.

These high-severity flaws stem from memory safety violations—specifically out-of-bounds writes and type confusion logic in the V8 engine—which allow for unauthenticated remote code execution inside the browser sandbox. An attacker can exploit these vulnerabilities by persuading a user to visit a malicious website or load a specially crafted HTML page. While the execution is initially confined to the browser's sandbox, these vulnerabilities serve as critical components in exploit chains used to compromise devices and exfiltrate sensitive enterprise data.

CVE-2026-87491 has been patched in Google Chrome starting with version 153.0.8010.36 and Microsoft Edge version 152.0.4191.65 . CVE-2026-85046 has been patched in Google Chrome starting with version 152.0.7977.82 and Microsoft Edge version 152.0.4191.65. Microsoft Edge builds incorporating these upstream Chromium V8 fixes should also be applied immediately across enterprise endpoints. Devices running versions below these thresholds are vulnerable and require immediate updates.

Enterprise organizations are strongly advised to enforce immediate remediation across all mobile and desktop endpoints to reduce risk.

Lookout Analysis

This exploit poses a maximum risk to Confidentiality, Integrity, and Availability. Successful exploitation enables attackers to execute arbitrary code to access sensitive enterprise data—including authentication tokens, session cookies, and user PII—while facilitating unauthorized actions within the context of the vulnerable application.

The exploitation of MultiApp-MultiCVE-2026-87491-85046 follows these stages of the kill chain::

  1. Luring: User is induced to visit a malicious link or site.
  2. Triggering: Browser renders crafted content, invoking the underlying V8 JavaScript engine.
  3. Memory Corruption: The application fails to restrict operations or improperly handles object types, leading to out-of-bounds writes or type confusion on the JavaScript heap.
  4. Accessing: Attacker gains code execution and accesses application memory, exposing tokens and credentials.
  5. Post-Exploitation: Attacker leverages code execution to escape the browser sandbox, pivot across host processes, or exfiltrate sensitive enterprise data.

Authors

Abstract fan-shaped digital art with green and yellow gradient bars radiating from the center.

Lookout

Endpoint Security
Icon of a white document with lines on a dark circular background.
Entry Type
Threat Guidances
Icon of a broken smartphone with a crack on the screen.
Threat Type
Vulnerability
Platform(s) Affected
All Platforms
Computer screen showing a code editor with Python code implementing a dictionary filter function.
Platform(s) Affected
Threat Guidances
Vulnerability
All Platforms
A woman using her phone and laptop on a train ride.Abstract white wavy lines creating a smooth flowing pattern on a light background.

Lookout Mobile Endpoint Security

Stop Cyberattacks Before They Start With Industry-Leading Threat Intelligence.

Advanced mobile Endpoint Detection & Response powered by data from 185M+ apps and 200M+ devices on iOS, Android, ChromeOS.

HeaderHeaderHeaderHeader
CellCellCellCell
CellCellCellCell
CellCellCellCell
CellCellCellCell