Tools AI-Found Vulnerability Register aifv-0047
Register entry
Chrome V8 out-of-bounds write exploited in the wild, found by a human researcher and paid $2,500 (the control row)
- CVE
- CVE-2026-87491
- Project
- Google Chrome
- Component
- V8
- Finder
- Jihyeon Jeong (human researcher)
- Autonomy
- human
- Evidence tier
- CNA credits the finder in its own advisory
- Assigner
- Chrome
- Severity
- Medium (Chromium severity)
- Bounty
- Paid, $2,500 (Chrome VRP)
- Confidence
- CONFIRMED
What happened
Fixed in Chrome 153.0.8010.36 on 8 September 2026 and exploited in the wild by a third party. The row sits in the register as a control: headlines conflated it with an AI-derived exploit chain built on 3 September, and the release note credits a person, with a $2,500 reward.
Credit as recorded: [$2,500][ 543557673 ] Medium CVE-2026-87491: Out of bounds write in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-06. Date basis: release note.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
- Chrome Releases, Stable Channel Update, 8 September 2026chromereleases.googleblog.com/2026/09/stable-channel-update-…
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026